How Ovenir measures
Six tools, one scale. Each one reads what a site says about itself to whoever knows how to listen: a machine, a screen reader, a stranger, a phone. Nothing is installed on your site, no trace is left, and whatever couldn't be measured counts neither for nor against you.
Three rules, for all six
- We only grade what we saw. A check that couldn't run, for lack of a form to examine or an image to weigh, leaves the calculation: the total is made on the remaining points.
- Every finding comes with its fix. The "fixes for your site" block under each result is written for the person who will do the work: the DNS to paste, the header to add, the element named in the page.
- Every measurement is dated and signed. A domain's record book keeps each measurement with its date and a fingerprint; the badge carries it, and anyone can verify it here.
Grades, from A+ to E
The score runs from 0 to 100. The letter reads the same way across all six tools.
| Grade | Score | What it means |
|---|---|---|
| A+ | 90 and up | Nothing is missing of what an automated check can see. |
| A | 80 and up | A few points to fix; none of them closes the door. |
| B | 70 and up | It holds, with visible flaws. |
| C | 55 and up | Whole areas are missing; the fixes are known. |
| D | 40 and up | The gaps pile up on the essentials. |
| E | 0 and up | The essentials are not in place. |
AI visibility Measure →
We read up to four pages of your site the way ChatGPT, Claude and Perplexity crawlers do: are they allowed in, do they find your name, address and phone number, and is that information written in a way a machine can copy without errors.
What it doesn’t see. It doesn’t ask the AIs themselves: that’s what the free sample does, by asking ChatGPT three real questions and sending you its answers.
Email deliverability Measure →
We read your domain’s public declarations in DNS: who may send in your name (SPF), message signatures (DKIM), the policy when someone impersonates you (DMARC), transport encryption, and blocklist presence.
What it doesn’t see. It reads no messages and doesn’t judge your sending server’s reputation: it says what you’ve declared, not what you send.
Security hygiene Measure →
We look at what your server answers to anyone who asks: certificate and encryption, instructions given to browsers, cookies, information leaking in headers.
What it doesn’t see. No probe, no penetration test: it doesn’t look for vulnerabilities, it reads the hygiene visible from outside.
Accessibility Measure →
We run up to seven pages of your site through automated checks: images without alternatives, unlabeled fields, headings, landmarks, language, code. Each check maps to the standard it serves.
What it doesn’t see. Automated checks see roughly a third of the criteria. Reading order, keyboard use and the meaning of texts need a human eye.
Compliance Measure →
We load the page in a real browser, count trackers before any choice, refuse, and count again. Then we read the legal notices and privacy policy for what the law requires.
What it doesn’t see. It’s not legal advice: it reports what a robot sees, as a first inspection would, and doesn’t read your contracts.
Site speed Measure →
We load the page on a simulated mobile, slow 4G and throttled CPU, from France, three times, and keep the median. The score rests on structure: weight, images, requests, compression, cache, protocol, blocking scripts, fonts, third-party share.
What it doesn’t see. Stopwatches depend on place and device: they’re shown as reference points, with their method, and don’t enter the score. Only your server’s response time does.
What none of the six does
No tool connects to your site as anything but a visitor. None modifies anything. None gives legal advice: compliance and accessibility report what a first inspection would see, not what a court would decide. And none promises a ranking: they say what's missing; the rest is up to you.