Kestrel SOC 2 readiness (demo)
Demonstration data
1 · Overview
Executive summary
- Target query
- “soc 2 readiness consultant” user-provided
- Audit timestamp
- 2026-09-18 10:00 UTC
- Search discovery
- Found at position 3 in checked results
- Fetch extraction
- Content extracted
- Browser verification
- Verified in a rendered page
- Actionable findings
- 7
- Most important issue
- Page carries a noindex robots directive
- Recommended first action
- Remove noindex from the meta tag or X-Robots-Tag header if the page should be discoverable.
Findings by severity
Technical checks
These results describe sampled retrieval evidence from 1 search request(s) and 1 fetch request(s) at one point in time. They are not guaranteed universal AI rankings.
2 · Discovery
Search visibility analysis
Found at position 3 of 5 checked results
Query “soc 2 readiness consultant” (user-provided). Sample: 5 result(s), page 1.
Match method: exact. Matching URL: https://kestrelcompliance.example/soc-2-readiness
- 1
SOC 2 readiness consulting | Auditline
https://auditline.example/soc-2-readiness
SOC 2 readiness consultants for startups. Gap assessment, policies and evidence collection in 8 weeks.
- 2
SOC 2 readiness assessment services — Vantage Assure
https://vantageassure.example/soc-2
Our SOC 2 readiness assessment finds control gaps before your auditor does. Fixed-fee consultants.
- 3
SOC 2 Readiness | Kestrel Compliance Your page
https://kestrelcompliance.example/soc-2-readiness
Kestrel guides growing companies through SOC 2. Our team has 15 years of experience in security and compliance.
- 4
How to choose a SOC 2 consultant
https://secburo.example/blog/choose-soc-2-consultant
Questions to ask a SOC 2 readiness consultant: audit firm relationships, fixed fees, timelines.
- 5
SOC 2 readiness consultants for SaaS
https://trustbridge.example/soc-2
TrustBridge SOC 2 readiness consultants: gap assessment, policy templates and auditor introductions.
Result title: “SOC 2 Readiness | Kestrel Compliance”. Final-URL comparison uses the Fetch result when available (target: https://kestrelcompliance.example/soc-2-readiness).
Competing pages: auditline.example, vantageassure.example, secburo.example, trustbridge.example. Evidence: ev_search_1
Sample size and limitations
- DEMO DATA: not a live request.
- One page of results; order is not a guaranteed Google ranking.
3 · Extraction
Fetch extraction analysis
- Requested URL
- https://kestrelcompliance.example/soc-2-readiness
- Final URL after redirects
- https://kestrelcompliance.example/soc-2-readiness
- HTTP status
- Not provided by Fetch
- Extracted title
- SOC 2 Readiness | Kestrel Compliance
- Meta description
- Kestrel guides growing companies through SOC 2 with practical, plain-English advice from experienced security professionals.
- Language / latency
- en · 640 ms
- Canonical (metadata)
- https://staging.kestrelcompliance.example/soc-2-readiness
- Retrieval
- Live fetch requested; may be served from cache by TinyFish
- Extracted size
- 1,342 characters
Heading hierarchy
- H1 Compliance, simplified
- H2 Why Kestrel
- H2 How we work
- H2 Frequently asked questions
- H3 Do you offer a SOC 2 readiness assessment?
- H3 How long does SOC 2 take?
Key facts extracted
- email hello@kestrelcompliance.example
Entities (AI-interpreted, quote verified)
- SOC 2 readiness assessment service
Links and structured data
- Internal links: 3
- External links: 1
- Structured data: 1 JSON-LD block(s): no @type
Sample internal links
- https://kestrelcompliance.example/
- https://kestrelcompliance.example/contact
- https://kestrelcompliance.example/about
Content that appears absent from the extraction
Browser verification found no rendered headings that were missing from the Fetch text.
Main content excerpt (plain text)
# Compliance, simplified Kestrel Compliance was founded in 2011 by two security engineers who were tired of audit season. Today our team has 15 years of combined experience helping growing companies earn trust. ## Why Kestrel We believe compliance should be practical. We work with your team, not around it, and we explain every control in plain English. ## How we work We start with a conversation, then agree a plan that fits your calendar and your budget. ## Frequently asked questions ### Do you offer a SOC 2 readiness assessment? Yes. Our SOC 2 readiness assessment compares your controls with the Trust Services Criteria and ranks the gaps by effort. ### How long does SOC 2 take? Most clients are audit-ready in 8 to 12 weeks. Contact hello@kestrelcompliance.example to book a call. Kestrel works with startups and mid-sized SaaS companies across North America and Europe. Kestrel works with startups and mid-sized SaaS companies across North America and Europe. Kestrel works with startups and mid-sized SaaS companies across North America and Europe. Kestrel works with startups and mid-sized SaaS companies across North America and Europe. Kestrel works with startups and mid-sized SaaS companies across North America and Europe. Kestrel works with startups and mid-sized SaaS companies across North America and Europe.
Shown as inert text. Fetched content is untrusted and is never rendered as HTML.
Evidence: ev_fetch_1 · ev_browser_1
4 · Search vs. page
Visibility gap analysis
What the search result communicates
SOC 2 Readiness | Kestrel Compliance
Kestrel guides growing companies through SOC 2. Our team has 15 years of experience in security and compliance.
AI-interpretedA generic overview: Kestrel guides growing companies through SOC 2, with 15 years of experience.
What the fetched page actually explains
SOC 2 Readiness | Kestrel Compliance
Kestrel guides growing companies through SOC 2 with practical, plain-English advice from experienced security professionals.
AI-interpretedA company-history opening, then a FAQ that finally mentions the SOC 2 readiness assessment and an 8 to 12 week timeline.
Does the page’s purpose match the query?
Partly AI-interpreted
The page offers what the query asks for, but the H1 and opening copy describe the company, not the service. The assessment and timeline appear only in the FAQ.
Useful details the snippet omits
- Readiness assessment compares controls with the Trust Services Criteria
- Audit-ready in 8 to 12 weeks
Evidence: ev_search_1ev_fetch_1
Query term coverage
Are the query’s key terms stated where tools look first? Computed from the extracted page, not guessed.
| Term | Title | H1 | Description | Body | Search snippet |
|---|---|---|---|---|---|
| soc | present | absent | present | present | present |
| readiness | present | absent | absent | present | present |
| consultant | absent | absent | absent | absent | absent |
Terms competing results emphasise that the page does not state
auditor ×2fixed ×2
Terms appearing in at least two other results. Hypotheses from a small sample, not requirements.
Evidence: ev_search_1ev_fetch_1
5 · Deterministic
Technical SEO checks
Observed rows report something a tool returned. Inferred rows are conclusions drawn from absence and may need confirmation. “Not checked” means no evidence was collected, never that it passed.
| Check | Status | Observation | Basis | Evidence |
|---|---|---|---|---|
| Title | Pass | "SOC 2 Readiness | Kestrel Compliance" (36 characters) | observed | ev_fetch_1 |
| Meta description | Pass | 124 charactersKestrel guides growing companies through SOC 2 with practical, plain-English advice from experienced security professionals. | observed | ev_fetch_1 |
| H1 and heading structure | Pass | H1: "Compliance, simplified" · 6 headings | observed | ev_fetch_1 |
| Canonical URL | Warning | Canonical points to https://staging.kestrelcompliance.example/soc-2-readiness, which differs from the fetched URL. | observed | ev_fetch_1 |
| Robots meta directives | Fail | robots meta contains "noindex, follow". | observed | ev_fetch_1ev_browser_1 |
| Extracted content volume | Pass | 207 words extracted. | observed | ev_fetch_1 |
| Internal links | Pass | 3 internal and 1 external links extracted. | observed | ev_fetch_1 |
| Open Graph tags | Warning | og keys: title | observed | ev_fetch_1 |
| Structured data (JSON-LD) | Fail | 1 block(s): no @type · 1 failed to parse | observed | ev_browser_1 |
| robots.txt | Warning | Disallow rules apply to: GPTBot, ClaudeBot.Directives are declared preferences; compliance depends on each crawler. | observed | ev_robots_1 |
| Sitemap discoverability | Warning | Sitemap found (31 URLs) but this URL is not listed. | observed | ev_sitemap_1 |
| Broken links | Not checked | Links were not individually requested. Sniffsite does not test links in this version. | observed | — |
6 · Prioritized
Findings and recommendations
F-001 Page carries a noindex robots directiveSeverity: HighConfidence: ●●● high confidence
Deterministic checkConfirmed by evidenceindexingWhat the evidence shows
robots meta contains "noindex, follow".
Evidence excerpt
robots meta contains "noindex, follow".from ev_fetch_1
Why it may matter
A noindex directive asks search engines to leave the page out of their results.
Recommended fix
Remove noindex from the meta tag or X-Robots-Tag header if the page should be discoverable.
Suggested replacement copy or code
<meta name="robots" content="index, follow">
Expected outcome (no guarantee)
The page becomes eligible for indexing once recrawled. Ranking is not guaranteed.
How to verify
Fetch the page again and read the robots metadata.
Evidence: ev_fetch_1ev_browser_1 · Section: Technical checks
F-002 robots.txt contains Disallow rules for AI crawlers (GPTBot, ClaudeBot)Severity: MediumConfidence: ●●● high confidence
Deterministic checkObservedaccessWhat the evidence shows
robots.txt has user-agent-specific groups that disallow this path for the crawlers listed. Other crawlers may be unaffected.
No verbatim excerpt is attached to this finding.
Why it may matter
If you want these assistants to be able to retrieve the page, these rules work against that. If it is deliberate, no action is needed.
Recommended fix
Confirm the rules are intentional; remove them for the crawlers you want to allow.
Expected outcome (no guarantee)
Named crawlers that honour robots.txt would be permitted to fetch the page.
How to verify
Re-fetch /robots.txt.
Evidence: ev_robots_1 · Section: Technical checks
F-003 Structured data failed to parseSeverity: MediumConfidence: ●●● high confidence
Deterministic checkObservedstructured-dataWhat the evidence shows
1 block(s): no @type · 1 failed to parse
Evidence excerpt
1 block(s): no @type · 1 failed to parsefrom ev_browser_1
Why it may matter
Invalid JSON-LD is ignored by consumers that read it.
Recommended fix
Fix the JSON syntax and validate with a structured-data testing tool.
Expected outcome (no guarantee)
Structured data becomes machine-readable.
How to verify
Re-run with browser verification.
Evidence: ev_browser_1 · Section: Technical checks
F-004 Canonical URL points to a different addressSeverity: MediumConfidence: ●●○ medium confidence
Deterministic checkObservedindexingWhat the evidence shows
Canonical points to https://staging.kestrelcompliance.example/soc-2-readiness, which differs from the fetched URL.
Evidence excerpt
Canonical points to https://staging.kestrelcompliance.example/soc-2-readiness, which differs from the fetched URL.from ev_fetch_1
Why it may matter
Search engines may consolidate this page into the canonical target.
Recommended fix
Confirm the canonical is intentional; otherwise point it at this URL.
Expected outcome (no guarantee)
Consistent consolidation signals.
How to verify
Re-run the audit.
Evidence: ev_fetch_1 · Section: Technical checks
F-005 The service is described in the FAQ, not in the headline or opening copySeverity: MediumConfidence: ●●○ medium confidence
AI-interpretedObservedmessagingWhat the evidence shows
The H1 reads 'Compliance, simplified' and the first paragraph is company history. The words readiness assessment and the 8 to 12 week timeline appear only under the FAQ.
Evidence excerpt
Most clients are audit-ready in 8 to 12 weeksfrom ev_fetch_1
Why it may matter
The search snippet for this page was assembled from the generic opening. Competing results lead with the concrete offer and its timeline.
Recommended fix
Lead with what you deliver, for whom, and how long it takes; move the company history lower.
Suggested replacement copy or code
<h1>SOC 2 readiness consulting for growing SaaS companies</h1> <p>A fixed-scope readiness assessment, a prioritised gap list and an 8–12 week path to audit-ready.</p>
Expected outcome (no guarantee)
The offer is stated where extractors and snippet generators look first. Rankings are not guaranteed.
How to verify
Re-run the audit and compare the extracted H1 and first paragraph with the search snippet.
Evidence: ev_fetch_1ev_search_1 · Section: Visibility gap analysis
F-006 URL is not listed in the sitemapSeverity: LowConfidence: ●●○ medium confidence
Deterministic checkObserveddiscoveryWhat the evidence shows
Sitemap found (31 URLs) but this URL is not listed.
Evidence excerpt
Sitemap found (31 URLs) but this URL is not listed.from ev_sitemap_1
Why it may matter
Sitemaps help crawlers find pages that are weakly linked.
Recommended fix
Add the URL to the sitemap.
Expected outcome (no guarantee)
Crawlers have an explicit path to the page.
How to verify
Re-fetch the sitemap.
Evidence: ev_sitemap_1 · Section: Technical checks
F-007 Competing results emphasise terms this page never statesSeverity: LowConfidence: ●○○ low confidence
Deterministic checkPotential issuecompetitor-comparisonWhat the evidence shows
At least two competing results mention: auditor (2), fixed (2). None appear in the extracted page.
No verbatim excerpt is attached to this finding.
Why it may matter
These may be expectations searchers associate with the query. They are hypotheses from a small sample, not requirements.
Recommended fix
Review whether any of these terms describe your offering truthfully and add them where relevant.
Expected outcome (no guarantee)
Better coverage of the vocabulary used for this query.
How to verify
Check against the competing pages in the Search evidence.
Evidence: ev_search_1ev_fetch_1 · Section: Visibility gap analysis
7 · Sources
Evidence inspector
Every finding and check cites these records. Records store normalized, sanitized data only: no keys, headers or credentials.
ev_search_1 Search: soc 2 readiness consultantsearch
- Produced by
- GET api.search.tinyfish.ai (demo data)
- Captured
- 2026-09-18 10:00 UTC · retrieved live
- Requested
- Query “soc 2 readiness consultant”
- Content hash
- demo800000000000…
- Used by
- F-005, F-007
- Verification state
- Observed in a search response
Sanitized request and response metadata
{
"request": {
"query": "soc 2 readiness consultant",
"location": "US",
"language": "en"
},
"metadata": {
"demo": true
}
}Known limitations
- DEMO DATA: not a live request.
- One page of results; order is not a guaranteed Google ranking.
Normalized data (JSON)
{
"query": "soc 2 readiness consultant",
"page": 0,
"totalResults": 5,
"results": [
{
"position": 1,
"title": "SOC 2 readiness consulting | Auditline",
"url": "https://auditline.example/soc-2-readiness",
"snippet": "SOC 2 readiness consultants for startups. Gap assessment, policies and evidence collection in 8 weeks.",
"siteName": "auditline.example"
},
{
"position": 2,
"title": "SOC 2 readiness assessment services — Vantage Assure",
"url": "https://vantageassure.example/soc-2",
"snippet": "Our SOC 2 readiness assessment finds control gaps before your auditor does. Fixed-fee consultants.",
"siteName": "vantageassure.example"
},
{
"position": 3,
"title": "SOC 2 Readiness | Kestrel Compliance",
"url": "https://kestrelcompliance.example/soc-2-readiness",
"snippet": "Kestrel guides growing companies through SOC 2. Our team has 15 years of experience in security and compliance.",
"siteName": "kestrelcompliance.example"
},
{
"position": 4,
"title": "How to choose a SOC 2 consultant",
"url": "https://secburo.example/blog/choose-soc-2-consultant",
"snippet": "Questions to ask a SOC 2 readiness consultant: audit firm relationships, fixed fees, timelines.",
"siteName": "secburo.example"
},
{
"position": 5,
"title": "SOC 2 readiness consultants for SaaS",
"url": "https://trustbridge.example/soc-2",
"snippet": "TrustBridge SOC 2 readiness consultants: gap assessment, policy templates and auditor introductions.",
"siteName": "trustbridge.example"
}
],
"match": {
"position": 3,
"method": "exact",
"url": "https://kestrelcompliance.example/soc-2-readiness"
}
}ev_fetch_1 Fetch: target pagefetch
- Produced by
- POST api.fetch.tinyfish.ai (demo data)
- Captured
- 2026-09-18 10:00 UTC · live fetch requested (cache possible)
- Requested
- https://kestrelcompliance.example/soc-2-readiness
- Content hash
- demo900000000000…
- Used by
- F-001, F-004, F-005, F-007, title, meta_description, h1, canonical, robots_meta, content_volume, internal_links, open_graph
- Verification state
- Directly observed from the source
Sanitized request and response metadata
{
"request": {
"urls": [
"https://kestrelcompliance.example/soc-2-readiness"
],
"format": "markdown",
"links": true,
"page_metadata": true,
"ttl": 0
},
"metadata": {
"demo": true
}
}Known limitations
- DEMO DATA: not a live request.
- Fetch returns extracted Markdown, not raw HTML: HTTP status and JSON-LD are not available from this evidence.
Normalized data (JSON)
{
"requestedUrl": "https://kestrelcompliance.example/soc-2-readiness",
"finalUrl": "https://kestrelcompliance.example/soc-2-readiness",
"title": "SOC 2 Readiness | Kestrel Compliance",
"description": "Kestrel guides growing companies through SOC 2 with practical, plain-English advice from experienced security professionals.",
"language": "en",
"author": null,
"publishedDate": null,
"textLength": 1342,
"textTruncated": false,
"pageMetadata": {
"canonical": "https://staging.kestrelcompliance.example/soc-2-readiness",
"robots": "noindex, follow",
"og": {
"title": "Kestrel"
}
},
"links": [
"https://kestrelcompliance.example/",
"https://kestrelcompliance.example/contact",
"https://kestrelcompliance.example/about",
"https://www.linkedin.com/company/kestrel-example"
],
"latencyMs": 640,
"text": "# Compliance, simplified\n\nKestrel Compliance was founded in 2011 by two security engineers who were tired of audit season. Today our team has 15 years of combined experience helping growing companies earn trust.\n\n## Why Kestrel\n\nWe believe compliance should be practical. We work with your team, not around it, and we explain every control in plain English.\n\n## How we work\n\nWe start with a conversation, then agree a plan that fits your calendar and your budget.\n\n## Frequently asked questions\n\n### Do you offer a SOC 2 readiness assessment?\n\nYes. Our SOC 2 readiness assessment compares your controls with the Trust Services Criteria and ranks the gaps by effort.\n\n### How long does SOC 2 take?\n\nMo… [642 more characters]"
}ev_browser_1 Browser: rendered pagebrowser
- Produced by
- POST api.browser.tinyfish.ai + CDP (demo data)
- Captured
- 2026-09-18 10:00 UTC · retrieved live
- Requested
- https://kestrelcompliance.example/soc-2-readiness
- Content hash
- demo240000000000…
- Used by
- F-001, F-003, robots_meta, structured_data
- Verification state
- Observed in a rendered page
Sanitized request and response metadata
{
"request": {
"url": "https://kestrelcompliance.example/soc-2-readiness",
"objective": "Verification requested: compare the rendered page with the Fetch extraction."
},
"metadata": {
"demo": true
}
}Known limitations
- DEMO DATA: not a live session.
Normalized data (JSON)
{
"requestedUrl": "https://kestrelcompliance.example/soc-2-readiness",
"finalUrl": "https://kestrelcompliance.example/soc-2-readiness",
"title": "SOC 2 Readiness | Kestrel Compliance",
"headings": [
{
"level": 1,
"text": "Compliance, simplified"
},
{
"level": 2,
"text": "Why Kestrel"
},
{
"level": 2,
"text": "How we work"
}
],
"visibleTextLength": 2900,
"visibleTextSample": "Compliance, simplified. Kestrel Compliance was founded in 2011 by two security engineers.",
"jsonLd": [
{
"valid": false,
"types": [],
"sample": "{\"@context\":\"https://schema.org\",\"@type\":\"Service\",\"name\":\"SOC 2 readiness\","
}
],
"canonical": null,
"robotsMeta": "noindex, follow",
"linkCount": 40,
"missingFromFetch": [],
"objective": "Verification requested: compare the rendered page with the Fetch extraction."
}ev_robots_1 robots.txtrobots
- Produced by
- GET {origin}/robots.txt (demo data)
- Captured
- 2026-09-18 10:00 UTC · retrieved live
- Requested
- https://kestrelcompliance.example/robots.txt
- Content hash
- demo280000000000…
- Used by
- F-002, robots_txt
- Verification state
- Directly observed from the source
Sanitized request and response metadata
{
"request": {
"url": "https://kestrelcompliance.example/robots.txt"
},
"metadata": {
"demo": true
}
}Known limitations
- DEMO DATA: not a live request.
Normalized data (JSON)
{
"url": "https://kestrelcompliance.example/robots.txt",
"status": 200,
"bodySample": "",
"genericDisallowsPath": false,
"aiBotDisallows": [
"GPTBot",
"ClaudeBot"
],
"sitemaps": [
"https://kestrelcompliance.example/sitemap.xml"
]
}ev_sitemap_1 Sitemapsitemap
- Produced by
- GET sitemap (demo data)
- Captured
- 2026-09-18 10:00 UTC · retrieved live
- Requested
- https://kestrelcompliance.example/sitemap.xml
- Content hash
- demo290000000000…
- Used by
- F-006, sitemap
- Verification state
- Directly observed from the source
Sanitized request and response metadata
{
"request": {
"url": "https://kestrelcompliance.example/sitemap.xml"
},
"metadata": {
"demo": true
}
}Known limitations
- DEMO DATA: not a live request.
Normalized data (JSON)
{
"url": "https://kestrelcompliance.example/sitemap.xml",
"status": 200,
"isIndex": false,
"listsTarget": false,
"urlCount": 31
}Activity log and stage results
- Completed
Validating the target URL
Completed· 2.0 s
Completed (demo).
- Completed
Preparing the search query
Completed· 2.1 s
Completed (demo).
- Completed
Searching for the target page
Completed· 2.3 s
Completed (demo).
- Completed
Inspecting relevant search results
Completed· 2.5 s
Completed (demo).
- Completed
Fetching the live page
Completed· 2.6 s
Completed (demo).
- Completed
Extracting the page's main content
Completed· 2.8 s
Completed (demo).
- Completed
Comparing discovered information with extracted content
Completed· 2.9 s
Completed (demo).
- Completed
Checking SEO and technical signals
Completed· 3.0 s
Completed (demo).
- Completed
Verifying disputed findings in the browser
Completed· 3.2 s
Completed (demo).
- Completed
Generating prioritized recommendations
Completed· 3.4 s
Completed (demo).
- Completed
Saving the final report
Completed· 3.5 s
Completed (demo).
8 · How to read this
Limitations and methodology
- Search is one request to TinyFish Search per query (one page of results). Position means order in that response, not a Google, Bing or universal AI ranking. A page missing from the sample is “Not found in checked results”, which does not mean “not indexed”.
- Fetch returns extracted Markdown plus metadata and links. HTTP status, response headers, JSON-LD and exact markup are not returned, so Sniffsite never infers them from text. TinyFish may serve a cached copy even when a live fetch is requested.
- Browser runs only with a concrete verification objective or when you enable it. It is one session from TinyFish’s network and may differ from what other visitors see.
- robots.txt and sitemap are read directly by Sniffsite from the public site. Directives are declared preferences; compliance depends on each crawler.
- Deterministic checks are computed only from observed data. AI-interpreted findings are produced by a language model from the collected evidence, validated against a schema, and any excerpt that is not verbatim in the cited evidence is discarded.
- Broken links are not tested. A successful Fetch does not prove a page is indexable or readable by every AI tool.
- Semantic analysis: used. API calls made: search 1, fetch 1, browser 1, Gemini 1.