Skip to main content
Verified Passive AuditScanned: Sep 9, 2026100% Non-Intrusive

www.siggol.com

Full technical assessment across email security, infrastructure encryption, search & AI discovery, and conversion pathways. Written with exact steps for non-technical leadership and developers.

Overall Score
81/100
Rating
Grade B
Book 48-Hour Diagnostic Sprint
Critical Issues
4

Requires immediate remediation

Quick Wins
14

Under 1 hour to resolve

AI & AEO Ready
81%

Perplexity & ChatGPT visibility

Opportunities
14

Revenue & security upsides

DataForSEO TelemetryLive SERP Verification

Google Search Footprint & Competitor Value

Est. Google Ads Replacement Value$29/mo
Total Indexed Keywords
62

Ranking in Top 100 on Google

Est. Monthly Organic Visits
~35

High-intent non-paid traffic

Google Knowledge Panel
Verified

Official brand entity card

Top Sample Ranking Keywords & SERP Features
c32 formVol: 90/mo
#7
top 10 logistics companies in kenyaVol: 70/mo
#9AI
transport and logistics companies in kenyaVol: 70/mo
#9
clearing and forwarding companies in mombasaVol: 140/mo
#10AI
clearing and forwarding companies in mombasa kenyaVol: 140/mo
#11

System Category Breakdown

Email Security & Deliverability63/100 (C)
1 issue2 opportunity
SSL/TLS & Encryption98/100 (A)
0 issues1 opportunity
Website & Cloud Security86/100 (B)
2 issues1 opportunity
Privacy & Kenya DPA 201960/100 (C)
2 issues0 opportunity
Speed, Assets & Carbon Footprint86/100 (B)
1 issue2 opportunity
Search Engine Visibility50/100 (D)
4 issues3 opportunity
AI Engine Optimization (AEO)81/100 (B)
0 issues3 opportunity
AI Workflow & Agent Readiness100/100 (A)
0 issues2 opportunity

Detailed Findings & Recommendations (24)

criticalEmail Security & Deliverability

No DMARC record — you have no protection against invoice fraud by email

OBSERVED EVIDENCE:We looked up _dmarc.siggol.com and found no DMARC policy.
Commercial Impact

DMARC is what actually instructs receiving mail servers to reject forged email claiming to be from your domain, and it is what sends you reports when someone tries. Without it, an attacker can email your customers or your own finance team as you — the classic version being a genuine-looking invoice with the bank details swapped. You also get no visibility that it is happening.

Recommended Fix

Publish a DMARC record at _dmarc.siggol.com starting at "p=none" with a reporting address so you can see who is sending as you, then tighten to "p=quarantine" and finally "p=reject" once legitimate senders are aligned. This is a staged rollout over a few weeks, not a switch to flip.

HarLyn Service Line:Cyber Defense & Compliance
Technical Reference
highSearch Engine VisibilityQuick Win (< 1hr)

Your site is not configured for mobile screens

OBSERVED EVIDENCE:We found no viewport meta tag.
Commercial Impact

Without a viewport tag, mobile browsers render the page at desktop width and shrink it, leaving text unreadable until the visitor pinches to zoom. Google indexes the mobile version of your site first, so this suppresses your ranking everywhere — and the majority of Kenyan web traffic is mobile.

Recommended Fix

Add <meta name="viewport" content="width=device-width, initial-scale=1"> and confirm the layout responds to narrow screens.

HarLyn Service Line:High-Speed Web Systems
highPrivacy & Kenya DPA 2019

You collect personal information but publish no privacy policy

OBSERVED EVIDENCE:Your homepage has a form that collects visitor details, but we found no link to a privacy policy.
Commercial Impact

Kenya's Data Protection Act 2019 requires that you tell people what data you collect, why, how long you keep it and who you share it with — before you collect it. The same applies under GDPR for any European visitors. Beyond the legal exposure, the absence of a policy is a visible trust problem for anyone deciding whether to hand over their details.

Recommended Fix

Publish a privacy policy covering the personal data you actually collect, your lawful basis, retention periods, third parties you share with, and how someone exercises their rights. Link it from the footer and from every form.

HarLyn Service Line:Cyber Defense & Compliance
Technical Reference
highPrivacy & Kenya DPA 2019

You track visitors before asking their permission

OBSERVED EVIDENCE:We found 1 tracking tool loading immediately on page load — Google Analytics / Tag Manager — with no consent mechanism.
Commercial Impact

These tools set identifiers and send visitor behaviour to third parties from the first moment of the visit. Kenya's Data Protection Act requires consent for this, and GDPR requires it before the tracker loads, not after. Enforcement in this area has been rising, and the fines are calculated against turnover.

Recommended Fix

Add a consent mechanism that genuinely blocks these scripts until the visitor agrees, rather than a banner that only informs. The distinction matters legally — a notice that tracking has already started is not consent.

HarLyn Service Line:Cyber Defense & Compliance
mediumSpeed, Assets & Carbon FootprintQuick Win (< 1hr)

Your images have no declared size, so the page jumps around as it loads

OBSERVED EVIDENCE:5 of 5 images have no width and height attributes.
Commercial Impact

The browser cannot reserve space for an image it has not measured, so content shifts down the moment each image arrives. Visitors tap the wrong thing, and Google penalises this directly through the Cumulative Layout Shift metric.

Recommended Fix

Add explicit width and height attributes (or a CSS aspect-ratio) to every image. The browser then reserves the correct space before the image loads.

HarLyn Service Line:High-Speed Web Systems
mediumSearch Engine VisibilityQuick Win (< 1hr)

Your homepage has no main heading

OBSERVED EVIDENCE:We found no <h1> element on the page.
Commercial Impact

The main heading tells both search engines and screen readers what the page is about. Its absence weakens your ranking for your core terms and makes the page harder to navigate for anyone using assistive technology.

Recommended Fix

Add exactly one <h1> per page stating the primary offer in plain language.

HarLyn Service Line:High-Speed Web Systems
mediumSearch Engine VisibilityQuick Win (< 1hr)

No canonical URL — Google may treat several copies of your site as competitors

OBSERVED EVIDENCE:We found no canonical link tag on the homepage.
Commercial Impact

Most sites are reachable at several addresses — with and without www, with and without a trailing slash, http and https. Without a canonical tag telling Google which is the real one, your ranking strength is split between duplicates instead of concentrated on one page.

Recommended Fix

Add a canonical link tag to every page pointing at its single preferred address.

HarLyn Service Line:High-Speed Web Systems
mediumWebsite & Cloud Security

No Content Security Policy — the browser will run any script injected into your pages

OBSERVED EVIDENCE:Your site sends no Content-Security-Policy header.
Commercial Impact

A Content Security Policy tells the browser which scripts it is allowed to run. Without one, if an attacker manages to inject code into a page — through a comment field, a compromised plugin, or a third-party script that gets hijacked — the browser executes it without question. This is the mechanism behind most card-skimming attacks on small e-commerce sites.

Recommended Fix

Add a Content-Security-Policy header listing the domains permitted to serve scripts, styles and frames. Roll it out in report-only mode first so you can see what would break before enforcing it.

HarLyn Service Line:Cyber Defense & Compliance
Technical Reference
lowWebsite & Cloud SecurityQuick Win (< 1hr)

Links that open in a new tab give the destination control over yours

OBSERVED EVIDENCE:12 links open in a new tab without rel="noopener".
Commercial Impact

The page you link to can quietly replace the tab your visitor came from with a copy of your site — a convincing way to harvest logins. It also slows down the browser.

Recommended Fix

Add rel="noopener noreferrer" to every link using target="_blank".

HarLyn Service Line:High-Speed Web Systems
lowSearch Engine VisibilityQuick Win (< 1hr)

Your page title is cut off in search results

OBSERVED EVIDENCE:Your title is 86 characters: "Siggol Logistics | Freight Forwarders Kenya | Logistics Services | Kenya customs Agent"
Commercial Impact

Google truncates titles at roughly 60 characters. Anything past that is replaced with an ellipsis, so the end of your message never reaches the searcher.

Recommended Fix

Shorten to under 60 characters, front-loading the words people actually search for.

HarLyn Service Line:High-Speed Web Systems
highAI Engine Optimization (AEO)

No structured data — AI assistants cannot reliably describe your business

OBSERVED EVIDENCE:We found no JSON-LD structured data on your homepage.
Commercial Impact

Structured data is the machine-readable summary of who you are, what you sell, where you are and when you are open. Google uses it for rich results, and ChatGPT, Perplexity and Google AI Overviews lean on it heavily when deciding which business to name in an answer. Without it, an AI assistant asked to recommend a supplier in your category has to guess from your prose — and it will more often name a competitor whose details it can read cleanly.

Recommended Fix

Add Organization and LocalBusiness schema with your name, address, phone, hours and service area, plus Product or Service schema on the relevant pages and FAQPage schema on any question-and-answer content.

HarLyn Service Line:High-Speed Web Systems
Technical Reference
mediumAI Engine Optimization (AEO)Quick Win (< 1hr)

No llms.txt — you have no summary written for AI assistants

OBSERVED EVIDENCE:We found no /llms.txt file on your site.
Commercial Impact

llms.txt is an emerging convention: a plain-text file giving AI assistants a clean, authoritative summary of what your business does and which pages matter, instead of leaving them to infer it from navigation menus and marketing copy. Adoption is early, which is exactly why publishing one now is cheap and puts you ahead of competitors who will get to it in a year.

Recommended Fix

Publish a short /llms.txt describing the business, the services, the service area and links to the pages you most want cited.

HarLyn Service Line:AI Search & AEO Integration
Technical Reference
mediumAI Engine Optimization (AEO)Quick Win (< 1hr)

Google AI Overviews are actively appearing on 2 of your ranking keywords

OBSERVED EVIDENCE:Keywords triggering AI Overviews include: "top 10 logistics companies in kenya" (Rank #9), "clearing and forwarding companies in mombasa" (Rank #10).
Commercial Impact

When Google triggers an AI Overview at the top of the search page, traditional organic clicks drop by up to 35% unless your site is explicitly cited inside the AI synthesis. Being cited in the AI answer preserves top-of-funnel lead flow.

Recommended Fix

Add authoritative schema markup, explicit definitions, and structured answer blocks directly below H2 headers on your target pages so Google Gemini and AI Overviews source their summary directly from you.

HarLyn Service Line:AI Search & AEO Integration
lowEmail Security & DeliverabilityQuick Win (< 1hr)

No MTA-STS policy — inbound email can be intercepted via TLS downgrade

OBSERVED EVIDENCE:We looked up _mta-sts.siggol.com and found no MTA-STS record.
Commercial Impact

Standard SMTP encryption (STARTTLS) is opportunistic, meaning an active attacker on the network can strip the encryption handshake and read incoming emails in plaintext. MTA-STS (RFC 8461) forces sending mail servers to use TLS 1.2+ encryption, closing the man-in-the-middle downgrade loophole.

Recommended Fix

Publish an MTA-STS DNS record at _mta-sts and host the standard policy text at https://mta-sts.<domain>/.well-known/mta-sts.txt.

HarLyn Service Line:Cyber Defense & Compliance
Technical Reference
lowSSL/TLS & EncryptionQuick Win (< 1hr)

No CAA record — any Certificate Authority is permitted to issue certificates for you

OBSERVED EVIDENCE:We looked up DNS CAA records for siggol.com and found none.
Commercial Impact

A CAA (Certificate Authority Authorization) DNS record explicitly specifies which Certificate Authorities (like Let's Encrypt, DigiCert, or Google Trust Services) are allowed to issue certificates for your domain. Without it, if any CA anywhere in the world is compromised or misconfigured, it could issue an unauthorized certificate for your domain without your knowledge.

Recommended Fix

Publish a CAA DNS record for siggol.com naming your approved certificate provider(s) (e.g. '0 issue "letsencrypt.org"').

HarLyn Service Line:Cyber Defense & Compliance
Technical Reference
lowSearch Engine VisibilityQuick Win (< 1hr)

No robots.txt file

OBSERVED EVIDENCE:We found no robots.txt at http://www.siggol.com/robots.txt.
Commercial Impact

robots.txt is where you tell search engines what to crawl and where your sitemap lives. Its absence is not fatal, but it means you are giving crawlers no guidance at all.

Recommended Fix

Add a robots.txt that allows crawling and points to your sitemap.

HarLyn Service Line:High-Speed Web Systems
lowSearch Engine VisibilityQuick Win (< 1hr)

Your links look broken when shared on WhatsApp or LinkedIn

OBSERVED EVIDENCE:Open Graph tags are incomplete: og:title missing, og:image missing.
Commercial Impact

When someone shares your link on WhatsApp, LinkedIn or Facebook, these tags decide whether it appears as a rich preview with an image and headline, or as a bare grey URL. In a market where WhatsApp is the main sharing channel, this directly affects how many people click a link a customer forwards.

Recommended Fix

Add og:title, og:description and og:image (1200x630px) to every page, plus the Twitter card equivalents.

HarLyn Service Line:High-Speed Web Systems
lowSpeed, Assets & Carbon Footprint

Your pages are not cached, so every visit is rebuilt from scratch

OBSERVED EVIDENCE:No Cache-Control header is present.
Commercial Impact

Caching lets repeat visitors and the CDN reuse work already done. Without it your server does the full job for every single request, which costs you both speed and hosting capacity on your busiest days.

Recommended Fix

Set appropriate Cache-Control headers — long-lived for assets with versioned filenames, short with revalidation for HTML.

HarLyn Service Line:High-Speed Web Systems
lowSpeed, Assets & Carbon Footprint

Your images use older, heavier formats

OBSERVED EVIDENCE:5 images are served as JPEG or PNG rather than a modern format such as WebP or AVIF.
Commercial Impact

Modern image formats are typically 25-50% smaller at the same visual quality. On an image-heavy page this is often the single largest saving available.

Recommended Fix

Convert images to WebP or AVIF with a fallback, or move to an image CDN that does the conversion automatically per visitor.

HarLyn Service Line:High-Speed Web Systems
lowSearch Engine Visibility

Google ranks your domain for 62 search queries in Kenya

OBSERVED EVIDENCE:DataForSEO live telemetry measures ~35 monthly organic visitors from Google (Kenya), with an estimated Google Ads replacement value of $29/mo.
Commercial Impact

Organic search traffic is high-intent compounding revenue. Knowing which keywords drive inbound interest allows you to protect your highest-converting search positions against aggressive competitors.

Recommended Fix

Strengthen internal linking to your top-ranking pages and publish dedicated landing pages for second-page keywords (positions 11-20) to push them into the top 3.

HarLyn Service Line:High-Speed Web Systems
infoEmail Security & DeliverabilityQuick Win (< 1hr)

No TLS-RPT reporting configured for mail transport security

OBSERVED EVIDENCE:We looked up _smtp._tls.siggol.com and found no TLS-RPT record.
Commercial Impact

TLS-RPT (RFC 8460) works alongside MTA-STS to send you daily diagnostic reports on inbound email delivery failures and TLS decryption attempts.

Recommended Fix

Publish a TXT record at _smtp._tls.siggol.com with "v=TLSRPTv1; rua=mailto:tls-reports@siggol.com".

HarLyn Service Line:Cyber Defense & Compliance
Technical Reference
infoWebsite & Cloud SecurityQuick Win (< 1hr)

No security.txt — researchers have no way to report a problem to you

OBSERVED EVIDENCE:We found no file at /.well-known/security.txt.
Commercial Impact

When someone discovers a vulnerability in your site, security.txt tells them where to report it. Without one, findings tend to go unreported or get posted publicly instead of coming to you first.

Recommended Fix

Publish a short /.well-known/security.txt listing a contact address and a preferred language.

HarLyn Service Line:Cyber Defense & Compliance
Technical Reference
infoAI Workflow & Agent Readiness

You already have a chat widget — but it likely still needs a human to answer

OBSERVED EVIDENCE:We detected a third-party live chat widget on your site.
Commercial Impact

A live chat widget only works during office hours, and outside them it collects messages that go stale overnight. An assistant grounded in your own product and pricing information handles the routine questions immediately at any hour and hands over to your team only when the conversation is worth their time.

Recommended Fix

Keep the widget and add a grounded assistant behind it, with clear escalation to a human. Visitors keep the interface they recognise; you stop losing the after-hours enquiries.

HarLyn Service Line:AI Search & AEO Integration
infoAI Workflow & Agent Readiness

Your quote process is a manual queue that could answer instantly

OBSERVED EVIDENCE:Your site invites visitors to request a quote or pricing.
Commercial Impact

Between the moment someone requests a quote and the moment they receive it, they are contacting your competitors. Research on lead response consistently finds that the supplier who responds first wins a disproportionate share of the business. If quotes go out the next working day because someone has to build each one by hand, you are losing deals you already paid to attract.

Recommended Fix

Automate quote generation from your existing pricing rules — an instant indicative figure to the customer plus a structured brief to your sales team, with the complex cases still routed to a human. This is workflow automation rather than a website change.

HarLyn Service Line:Workflow Automation
HarLyn Engagement Roadmap

How HarLyn Resolves These Findings

Every issue and opportunity above maps directly to one of our four core offerings. Our 48-hour diagnostic sprint delivers the exact technical remediation blueprint, zero-trust implementation, and AI discovery foundation.

1. Cyber Defense & Compliance

Email Authentication & Zero-Trust Hardening

Full DMARC p=reject rollout, SPF & DKIM alignment, MTA-STS mail encryption, and compliance auditing under Kenya Data Protection Act 2019.

2. High-Speed Web Systems

SSR Architecture & Edge Performance

Eliminating client-rendering bottlenecks, instant page transitions, CDN caching, security header enforcement, and carbon footprint reduction.

3. AI Search & AEO Integration

Entity Schema & LLM Discovery

Structured JSON-LD schema (Organization, LocalBusiness, FAQ), /llms.txt deployment, and unlocking crawl access for ChatGPT, Claude, and Perplexity.

4. AI Automation & Workflows

Self-Healing Lead & Inbound Pipelines

Instant quote automation, Telegram/WhatsApp alert routing, and autonomous client acquisition pipelines built with n8n and TypeScript.

Ready to resolve these items?
Fixed fee · 48-hour turnaround · Handled directly by Harrison & Nazline
Claim 48-Hour Assessment (KES 35,000 / $280)