- Does this make my clinic GDPR or Cyber Essentials compliant?
- No. Vantyris doesn't certify you against any framework. Every verified report has a Cyber Essentials A1-A5 section (the UK government's baseline scheme) showing which controls each finding touches, which is a good starting point for a conversation with your regulator or your insurer. Certification needs an assessor. Vantyris shows what an external scan can speak to and what needs internal evidence.
- Will the scan slow my booking system down?
- No. It reads what your site already shows the public: DNS records, response headers, certificates and a short list of common paths, with time-limited requests. It doesn't try to log in, doesn't probe for hidden services, and doesn't brute-force or fuzz anything.
- Can I show this to my professional indemnity insurer?
- Yes, three ways. Email them the PDF (the compliance-pack layout is sized for this). Send a time-limited share link they open in a browser, watermarked with their name if you like. Or give them the address of your public trust page. If your policy asks for evidence of an external scan in the past 12 months, any of the three gives you something dated to send.
- What about cookie-consent sweeps? Does Vantyris check for that?
- Yes. The Privacy category checks for trackers loading before consent, reject parity on the cookie banner (the EDPB rule that rejecting must be as easy as accepting), Google Consent Mode v2 when Google trackers are present, and a visible privacy-policy link. Regulators run sweeps on exactly these patterns (the UK ICO's 2023 sweep covered the top 100 UK sites) and follow up with smaller organisations when someone complains.
- What if a regulator asks about a specific control?
- Open the verified report, go to the Cyber Essentials section and find that control's row. It lists every finding that touches the control, with its severity. It also says whether the area is covered, has gaps, or sits outside what an external scan can see. Endpoint posture and staff training, for example, need internal evidence.
- What if I don't have a 'developer'?
- Most fixes happen in your web host's control panel. The report words each action plainly enough to forward to the host's support team, and includes a copy-paste snippet for the common fixes: DMARC, HSTS, blocking /readme.html, locking down the WordPress REST API user list. You can also assign a finding to your host's support address from inside the report. Vantyris keeps the audit trail of when it went out and who responded.