GUUT Technologies
A United Kingdom cybersecurity provider whose own website had to argue security competence rather than assert it.

The constraint
A company that sells penetration testing and risk management cannot have a website that fails the checks it sells. Every header, every third party script and every form is read by its own prospects as evidence.
What most people would have built
A theme from a marketplace with a dozen plugins. Fast to launch, and every plugin is an unaudited dependency on a site whose whole argument is that the company audits things.
Service pages that argue, not assert
Each service is explained as a process rather than a promise. Penetration testing, risk management, network design, each with what happens, in what order, and what the client receives at the end.

A process the reader can hold them to
Discovery and analysis, strategic planning, implementation, continuous monitoring. Four steps, published, so a prospect knows what the engagement looks like before the first call.

A chat widget that works when nobody is there
Off the shelf chat tools either need a human online or hand the conversation to a bot. The custom widget captures the enquiry with context and delivers it as a lead when the team is offline, so a prospect at midnight still gets a reply in the morning.
Hardening and speed
Security headers, a locked down admin, plugin count kept to what is auditable, and a CDN in front so the site is fast from anywhere a prospect might be reading it.
What broke
The first performance pass was undone by a single analytics tag loaded synchronously. Every third party script now loads deferred, and there is a list of them, because on a security site an unlisted script is a finding.
What it taught us
For a security firm the site is the first audit. Anything sloppy in the front end is read as sloppiness in the product. This engagement led to a second one, a business analytics dashboard for the same client.