Aamu Compliance

Your partner for secure, compliant business online

A website is the most public part of a company, and the demands on it keep growing: accessibility, security, findability and statutory duties. We measure all four, explain the findings plainly and help you fix them.

Example results

company.fi

Accessibility34/100
Security baseline51/100
Search visibility58/100
Legal & privacy65/100

Four angles, one check. Every finding can be verified directly on your own site.

Four angles

Compliance is not one thing but four

The same public pages your customers use also show how well your company carries its obligations. We check them from four directions, each with a direct effect on the business.

Accessibility

Can every customer do business with you?

The European Accessibility Act has applied since June 2025 to, among others, online shops, travel and transport services and e-books. In Finland the supervisor is Traficom. An accessible site also serves ageing customers and mobile users.

96 %of the company sites we studied publish no accessibility statement

Security

Is the baseline in place — including email?

Most security problems are not break-ins but missing basics: security headers, cookie protection, certificates and email spoofing protection (SPF, DMARC). Without them, anyone can send scam emails to your customers in your company's name.

52 %of sites lack a DMARC policy, the control that blocks scam emails sent in your name

Search visibility

Are you found when a customer searches?

Technical obstacles — missing descriptions, sitemaps and mobile settings — drop a site out of search results regardless of how good the content is. The same applies to AI search, which reads the same structures.

47 %of sites have no meta description, the text a search result is built from

Legal & privacy

Are statutory duties visibly met?

Cookie consent, privacy notice, business ID and contact details on the site, terms of sale in the shop. Small things that an authority, a customer and a partner check first — and where fines and reputational risk begin.

51 %of sites start tracking services before the visitor has consented

Research

How do Finnish company websites fare?

We do not guess, we measure. We surveyed hundreds of public websites of Finnish consumer-facing companies with the same automated review we run for our clients. Below: the share of sites with at least one critical or serious finding in each angle.

Accessibilitysomething to fix on 100 %
94 %
Securitysomething to fix on 100 %
88 %
Search visibilitysomething to fix on 89 % — rarely severe
7 %
Legal & privacysomething to fix on 99 %
54 %
100 %of sites had at least one finding — we found no clean site
71 %of sites use text whose contrast is too weak to read
79 %of sites lack a Content-Security-Policy, the key defence against malicious scripts
60 %of sites do not show a business ID, although Finnish law requires it of any company trading online

The results did not change as the sample grew several times over — this is not chance but the general state of Finnish SME websites. The gaps are rarely large; they are small and repetitive, and most often nobody has simply looked.

Data: public websites of Finnish consumer-facing companies, company data from the PRH/YTJ open data (CC BY 4.0), automated review 2026. Percentages rounded. Automated testing covers roughly half of the accessibility criteria, and legal findings are indicators, not legal determinations.

Services

Three tiers — from reports to fixes

Every tier contains real work. The reports tell you everything a machine can see; the audit tells you what it cannot. The report price is credited against the audit.

Tier 1

Four reports

€29 per report · all four €99 + VAT

Accessibility, security, search visibility and legal — every automatically verifiable finding with a fix, in Finnish and English. Bought through a personal link. Read more about the reports.

Tier 2

Expert audit

from €1,900 + VAT

The half a machine cannot see, in the area you choose: for accessibility, a keyboard and screen-reader walkthrough criterion by criterion plus a finished accessibility statement; for privacy, a cookie inventory and a rewritten notice; for security, a configuration review with your hosting partner. Always with a prioritised remediation plan and effort estimates.

Tier 3

Remediation

By quotation

Implementation of the fixes, retesting and a conformance re-check. Delivered together with our partner network; the audit fee is credited against the remediation project.

Automated checks detect roughly half of the accessibility criteria and only the publicly visible security and privacy signals. That is why tier 1 is a baseline, not a certificate of conformance — and why tier 2 is genuine additional work, not the same information sold twice.

Why now

The requirements already apply — and they are checked on your website

The European Accessibility Act has applied to consumer-facing online services since 28 June 2025, supervised in Finland by Traficom. Enforcement of the GDPR and cookie rules has tightened across the EU, and tracking that bypasses consent is the single most common cause of a reprimand.

A security baseline is increasingly a contract and insurance condition that partners and customers verify themselves. Findability is decided more and more by technical basics that AI search reads too. All four are visible on your public pages — to anyone who knows how to look.

How we work

Measured by machine, interpreted by people

Automation finds recurring gaps fast and comprehensively. A person tells you which of them actually hurt the business and in what order to fix them. Neither can replace the other.

  1. ReviewWe analyse the public pages exactly as an ordinary browser would: accessibility, technical baseline, search visibility and cookie behaviour before consent.
  2. VerificationWe go through the findings by hand before sending anything. We never send a report whose claims we have not verified ourselves.
  3. ReportsYou get the findings with fixes and a clear picture of what automated testing does not cover — separately for each of the four angles.
  4. RemediationIf you want help, we estimate the effort and deliver the fixes with our partners.

Our pledge

How we work — and what we never do

Always

  • We analyse only publicly available pages
  • Findings can be verified on your own site
  • We say clearly what is an observation and what is an interpretation
  • We show what a report contains before you buy — grades and an example finding are free

Never

  • Break in, log in or test for vulnerabilities
  • Load your site or scan ports
  • Threaten with sanctions or present findings as violations
  • Sell findings onwards or publish your report

"Compliance is not a cost line. It is a promise that every customer can trust your company — and do business with it."

— Aamu Compliance

Contact

Request a report link for your site

Send us your domain and we will run the review and send a personal link where you can see the grades from all four angles and buy the reports (€29 + VAT per report, all four €99 + VAT; sold to businesses). Requesting the link is free and carries no obligation.

info@aamucompliance.fi →

Aamu Compliance

Email: info@aamucompliance.fi
Privacy matters: tietosuoja@aamucompliance.fi
Requests about the bot: bot@aamucompliance.fi

Aamu Advisory Oy · Business ID 3435542-4 · Tampere, Finland

Suomeksi

Aamu Compliance on kumppanisi turvalliseen ja vaatimustenmukaiseen liiketoimintaan verkossa: saavutettavuus, tietoturva, hakukonenäkyvyys ja juridiikka yhdessä tarkistuksessa. Suomenkielinen sivusto →