the check bibliography

What Audera checks

Every page Audera scans runs through the checks below. Each entry explains what the check looks for, why it matters on a pharmaceutical website, and what causes it to raise a finding.

Availability & links

Is the page up, and do its links work?

Content management systems leave a small number of addresses open by default: a list of every account that has published, an archive page per author, and a content feed. On a site aimed at healthcare professionals those addresses hand out staff names and republish page content outside the gate. Audera requests each of them once per scan and reports only what actually answered. When the site refuses the requests, that is reported as not verified rather than as clean.

When a page is captured but its content cannot be parsed into the structured elements the other checks read, those checks silently skip rather than fail. This check makes that state visible: a finding is raised when analysis failed entirely, and a review item when only part of the page could be analysed. The checks that depend on the part that failed are recorded as not checked rather than run against an empty default, so a skipped check is never mistaken for a pass. It resolves automatically on the next scan that analyses cleanly.

The most fundamental check: requests the page and confirms that what came back is the page being monitored. A page that returns an error, answers with a not found template, redirects somewhere else or does not respond at all is invisible to patients and healthcare professionals, and every other check is moot for it. A success status whose content is the real page passes, and so does a redirect that lands on the same page under a tidier URL. A page that was reachable before and has just stopped answering is first raised as a review ("confirming on next scan") rather than condemned outright, because a single transient blip should not be a hard failure; a second consecutive observation escalates it to a fail in place, on the same finding. The exceptions escalate on sight: a rejected security certificate and a server error are never transient, and neither is a page that has missed three of its last seven scans. A domain that does not resolve is held the longest, for three observations, because a registrar change looks exactly like a dead domain on the scan that catches it.

Checked once per scan of a live site rather than per page, and once per origin rather than once per environment, because one robots.txt serves every site on a host. Audera fetches the file at the root of the site and reads it the way a crawler does: a crawler obeys only the most specific group that names it, so a rule blocking every crawler while separately allowing Google and Bing does not hide the site from search. A finding is raised when the file is missing or unreachable, when a content management system answers the robots.txt address with a web page instead of a robots file, or when a rule keeps a search engine out of the whole site. The finding is attached to the homepage of the site.

Raised once per scan rather than per page: when an overwhelming majority of a site's pages come back unreachable in the same scan, the cause is almost never each page being individually down. It is a WAF, bot-management product or rate-limiter blocking automated access to the whole site. Rather than flooding the findings list with one "page unreachable" finding per page, Audera collapses the situation into a single actionable finding on the homepage that points at allowlisting our scanner. The individual page findings stay on record as evidence, but their alerts are held under this one so the picture stays clear. It resolves automatically on the next scan that reaches the site again. A second, quieter form of the same finding is raised for review when no single scan is bad enough to collapse but several of the recent scans each lost a meaningful share of the pages, which is what an intermittent challenge looks like from the outside.

Opens a direct secure connection to the site each time it is scanned and inspects the certificate the server offers. An expired certificate, one that does not cover the address, or one browsers do not trust puts a full page security warning in front of every visitor. A certificate approaching expiry is reported so it can be renewed before that happens. Audera checks the certificate the server presents; it does not check whether a certificate has been revoked since it was issued.

Tracking & SEO

Search visibility and analytics tagging.

Records which analytics and tag manager tools a page loads, and compares them with the approved baseline version of the page. A missing or changed tag may affect measurement. Separately, Audera flags external resources it has not classified. These may support normal page functionality; their presence does not establish tracking, cookie use, or a change from the approved baseline. Review their purpose before deciding whether consent is relevant. Audera reads the page HTML and, where the capture supports it, the requests the page actually made. Tags loaded inside an iframe, or injected only after a visitor accepts a cookie notice, may not be visible.

Reads the canonical tag and any hreflang entries on the page. A canonical pointing at another domain, at a staging server or at a page that does not respond tells search engines to index something other than this page, which is how a live page silently disappears from search. hreflang entries are checked for valid language codes, for a self reference and for targets that respond. Audera reads the tags in the page HTML; canonical tags sent in an HTTP Link header and hreflang declared in a sitemap are not read.

A leaked page is one that was never meant to carry a live link: CMS author archives, tag and date archives, attachment pages, or half-built templates. Audera stops content-checking a leaked page (there is nothing to fix on it) and instead probes it each scan, keeping this finding open while the page still returns 200 and resolving it automatically once it is taken down or redirected.

Live only
Critical

Detects a robots noindex directive, in a meta tag or in the X-Robots-Tag response header, on a live production page. Noindex is routinely used to keep staging and preview sites out of search engines, and when it leaks into a production deployment the page disappears from search results, often unnoticed until traffic collapses. Because some live pages are noindexed on purpose, a noindex is raised for review rather than failed outright: confirm it is intentional, or disable this check for the page. A page type that is normally excluded from search, such as a sitemap page, a login wall or a bibliography, is recorded at low severity instead, and so is gated healthcare professional content on a site that declares a gate. Staging and development environments are handled by the staging indexable check.

Watches the Google Search Console verification meta tag and compares it with the approved baseline version of the page. A finding is raised when a token that was present at baseline disappears, or when a token that was not there appears. Losing the verification tag can silently revoke access to Search Console data for the domain, and a new token often indicates an unexpected deployment or template change. Only the HTML meta form is visible to Audera: a domain verified through DNS, an uploaded HTML file, Google Analytics or Google Tag Manager carries no tag on the page, and this check says so rather than reporting a problem.

Staging only
High

On a staging or development environment, checks that the page is kept out of search engines. A non-production page Google can crawl leaks pre-launch content, competes with production for the same keywords, and can expose embargoed or unapproved claims. Audera makes one anonymous request for the page, with no stored credentials, which is what a search engine sends. A refusal is protection and a noindex directive is protection; credentials stored in Audera are not, because a server can lose its password wall while the credentials stay on file, and that is the misconfiguration this check exists to catch. When the anonymous request does not complete, nothing is claimed either way. Live environments are handled by the noindex leak check instead.

Content & legal drift

Changes against the approved baseline.

Surfaces when the visible copy of a live page has materially changed since the approved baseline while its job code has not. In most approval workflows a material copy change requires re-approval, and re-approval produces a new code, so changed copy under an unchanged code suggests the page was edited outside that process. The job code is what clears this check: a date of preparation that moved on its own is a stamp refresh rather than evidence of re-approval, and it is recorded beside the finding rather than suppressing it. The comparison is over every code the page carries, not the first one found, so a bumped second code counts. A page that carries no job code on either side is recorded as not applicable, because there is nothing to check a change against. The check runs on live environments only.

Watches every live page for any change to what a reader can see on it, compared with the capture accepted as the baseline. Every word, every image source and every link target is hashed on each scan, and when the hash no longer matches the baseline the difference is graded: a change over the threshold, a change to the main heading, a dose, a frequency, a negation or a reordered instruction are all material, and a value that changes on its own, such as a counter or a relative timestamp, is not. A material change is a finding and a smaller one is raised for review, and either stays open until the new state is accepted as the baseline.

Pharma compliance

Mandatory regulatory content on the page.

When the linked EMA source or manual fallback says the product is under additional monitoring, Audera expects the promotional site to be behind a healthcare-professional gate. This site-level check raises a review finding on the anchor page when additional monitoring is expected but the site is configured as public.

Watches whether the linked medicine is on the European Medicines Agency list of medicines under additional monitoring, the list that decides whether promotional material must carry the black triangle. The list is revised monthly and Audera re-reads it weekly, so a medicine added to it is picked up within a week of the revision being published. A medicine the list does not name is checked against its EPAR page instead, because a name missing from the list is not the same as a medicine the list says is not monitored. The MHRA maintains the separate list that applies in Great Britain and Audera does not read it, so a Great Britain site is told which list its finding came from. The change originates outside the agency control, so it is surfaced between site deployments as well as during them.

Looks for the adverse event reporting statement on the page, the standard wording that tells readers how to report side effects, for example via the MHRA Yellow Card scheme or the drug safety contact of the marketing authorisation holder. Pharmaceutical promotional material is generally required to carry this statement wherever a product is promoted, and regulators treat its absence seriously. A finding is raised when no adverse event reporting wording is detected in the page content. When the page instead links to adverse event reporting information (for example via a persistent header link) without stating it inline, the finding is raised for review rather than as a failure. The scan recognises the UK Yellow Card scheme, the FDA MedWatch programme and the national wordings seeded for Spanish, French, German, Italian, Dutch, Portuguese, Polish, Swedish and Danish; a statement in a language with no seeded wording is not recognised. It reads the text a reader can see, so a statement carried only in an image, inside an iframe or behind a closed modal is not read, and a name on its own, such as a footer link labelled Pharmacovigilance, is reported as a reference to reporting rather than as the statement.

Verifies that the black triangle (the symbol marking a medicine under additional regulatory monitoring) is used consistently. A finding is raised for review in either direction: the site is configured as promoting an additionally monitored product but no black triangle signal is detected at all, or a black triangle is detected when the site is not flagged for additional monitoring. A soft consistency finding is also raised when a text-rendered triangle is applied inconsistently across many mentions of the medicine name. Because the symbol can be rendered as text, inside a logo image, or alongside an "additional monitoring" statement, this check is best effort and always asks for human confirmation rather than asserting a definite failure.

Checks that a date of preparation, or date of revision, is present on the page. Industry codes such as the ABPI Code require promotional material to state when it was created or last revised, so reviewers and inspectors can tell whether the material is current. A finding is raised when no date of preparation can be detected on the page, and a review is raised when a date is present but cannot be tied to an approval stamp. The age of the date is not judged, only its presence.

Runs when an Important Safety Information section is present on a US market page, and measures how much safety text it actually contains. A section far shorter than a real one may have been truncated, collapsed, or only partially rendered in the captured page, a real failure mode where the heading survives and the content does not. Every live US ISI measured for this check ran between four thousand and forty four thousand characters, so the threshold is set well below the shortest of them. Because legitimately short sections exist, and because a section built in a shadow-DOM template cannot be measured from the page at all, the finding is raised for review rather than as a definite failure.

Looks for an Important Safety Information section on the page. The ISI carries the safety warnings, contraindications and other risk information that must accompany product promotion, and its absence from a US product page is one of the most serious findings Audera raises. An ISI is a US construct: it is how the FDA fair-balance requirement for promotional labelling is met, and no other market asks for one, so the check applies to US market pages and is not applicable elsewhere. A finding is raised when the page serves the US market and no ISI section is detected. When the market cannot be determined the item is raised for review at low severity instead, and it does not count against a free-check score.

Validates candidate job codes found on the page against the expected format configured for the site, or inherited from the client. Each company uses a defined job code structure, and a code that does not match it usually means a typo, a code from the wrong market, or placeholder text that survived to production. The check only runs when a format is configured and code-like strings are detected on the page; the finding lists every candidate that fails to match.

Checks whether a job code (approval reference) claims a market other than the one the site belongs to. UK material is certified under the ABPI code by a UK signatory; Irish material is certified under the IPHA code by an Irish signatory, with different adverse-event reporting and a different SmPC. A UK page carrying an Irish job code, or the reverse, suggests the asset moved between markets without being re-certified for its new home. The code is evidence, not proof, so a needs-review finding is raised for a human to confirm; the check stays silent whenever the site market or the code market cannot be confirmed.

Checks that a job code (the unique approval reference, sometimes called a Veeva code, Zinc code or job bag number) is present on the page. The job code ties the live page back to its certified version in the approval system; without one there is no evidence the content was approved. A finding is raised when no job code can be detected on the page.

Checks whether a page shows more than one job code inside its own content. A site footer code beside a page stamp is the normal arrangement and is not flagged: the two codes cover different material and both are correct. Two codes in the page content are the case worth confirming, because one of them can belong to material that was replaced. A low-severity finding is raised then, naming each code with where on the page it sits.

Cross-checks the superscript citation markers in the page body against the numbered entries in the references section. A finding is raised for review when superscript numbers point to no reference entry, meaning a claim has no supporting citation, or when reference entries exist that no superscript points to, which is often a sign that copy was deleted without updating the bibliography. Clinical claims on pharma sites must be traceable to their cited sources, so both directions are flagged. When the scan cannot read a references section at all, it says so rather than naming entries it never read. The text cross-check and its AI second reading run on every plan; Pro and Agency plans additionally review crops of the page figures, where a marker can be baked into a chart or an infographic.

Tracks the linked medicine's EMA EPAR Product information last-updated date. When the source date advances, this informational review finding is raised so the site's prescribing and safety content can be checked against the new product information. The finding remains reviewable, but carries only the configured info-severity health weight.

Disease awareness and corporate sites are usually unbranded, so the promotional checks start switched off for them. This check guards that assumption. It raises a review when a product name configured on one of the client's product sites appears in this site's visible text, and when a link points at a product site's domain, including a link that carries the destination in its query string as an exit interstitial does. It reports once for the whole site rather than once per page. Mentions inside images, embedded documents and content loaded after the capture are not seen.

When a UK product page promotes a medicine under additional monitoring, Audera requires the adverse-event reporting statement to link to the MHRA Yellow Card scheme. The generic adverse-event check still owns pages with no AE wording at all; this check only raises when AE wording exists but the Yellow Card link is missing. The scheme URL written out as plain text satisfies the duty, which is how a footer copied from the SmPC reads, and an anchor whose label says Yellow Card while its destination goes elsewhere does not.

Audience gating & cookies

HCP gating and cookie consent.

Checks the site for the self certification step that keeps promotional material intended for healthcare professionals away from the general public. Gate presence is assessed on the home page and on any page that shows gate wording. When the scan crosses a gate this scan the check passes. When a gate is expected and the scan finds no step it recognises the check raises a review rather than a failure, because gates built with JavaScript, checkbox declarations and login walls are not always recognisable from the page markup. When the scan captured the gate instead of the page behind it, the content checks for that page are skipped and a separate holding review says so.

Brand & visual

Logos, trademarks and visual brand drift.

Medium

Keeps a copy of every brand mark located on the page and compares it on each scan. A mark that is replaced, removed or broken after the page was approved is a real compliance problem: a rebrand shipped without review, a partner logo swapped in, or a lock up that lost its registered trademark symbol. Image files and CSS background images are re-fetched and compared byte for byte; inline SVG marks are compared from the page itself. When the bytes differ, an AI review compares the two images before the change is reported, so a file that was simply re-saved is reported as a re-save rather than as a changed mark. Marks drawn as text, or loaded from a stylesheet Audera cannot read, are not tracked.

Reports when a tracked logo file stops loading. The file is re-requested on each scan; two consecutive failures with the same error are reported, so a single slow response or a moment of maintenance does not raise a finding.

Medium

Reports when a brand mark that was previously located on a page stops appearing on it. A logo is only reported as removed after it has been absent from two consecutive scans that read the page cleanly, and it is tracked by the file it loads rather than by the name it was given, so renaming a mark never reports it as removed.

Looks for a brand term that carries a trademark mark (®, ™ or ℠) somewhere on the page but appears without it on its first use in the main content. Trademark guidance asks for the mark on the first and most prominent use of a brand name; later bare repetitions are acceptable, which is why only the first use is judged. Navigation, headers, footers, cookie banners and gate copy are not counted as a first use, because they come from the shared template rather than from the page. The check reads the page text and does not read marks rendered inside imagery, so a brand whose mark sits only in the logo is raised for review rather than failed.

Finds registered trademark and trademark symbols in the page text and checks that each one is rendered as a superscript. Brand guidelines, and most approved artwork, specify superscripted marks, so a full-size symbol usually means the page markup has drifted from the approved layout. A single finding for review lists every occurrence in the page copy that is not superscripted, and a separate one lists the marks that come from the site template. The check reads the page text. It does not read marks rendered inside imagery such as a logo, a banner or a figure. A site whose house style does not raise its marks can turn the check off on its settings.

Site setup

Settings and page classification that decide which checks run.

Every compliance check needs to know what a page is. A privacy policy is checked for a last updated date; a product page is checked for prescribing information, safety information and an adverse event statement. Audera detects the type from the page address, its heading and its content, and a detected type that would switch checks off is never acted on until someone confirms it. This check lists the pages whose type is still a guess.

No checks match your search

Try a different word. Checks are searchable by their title and explanation.