The Countloyal café audit reader

Countloyal's free café audit checks what a customer finds about a café online. When someone asks for an audit of a café at countloyal.com/audit, this reader visits that café's public website once to check things like its opening hours, phone number and menu links. It runs only when someone asks for an audit, so it does not crawl the web.

How to recognise it

It sends this User-Agent:

CountloyalAuditResearch/1.0 (+https://countloyal.com/audit)

Every request is signed with Web Bot Auth (HTTP Message Signatures, RFC 9421, Ed25519). Requests carry Signature-Agent: "https://countloyal.com" and a signature you can check against our public key directory at https://countloyal.com/.well-known/http-message-signatures-directory.

What it reads

For each audit it asks for your robots.txt, then the page it was given (usually your homepage), then at most two pages that page links to for bookings, orders or menus. It follows a small number of redirects and reads only pages anyone can see without logging in. It does not submit forms, run scripts or fetch images.

It keeps no copy of your pages. It takes the few facts the audit needs and shows them to the person who asked for the audit. Nothing it reads is used to train AI models or republished.

How to block it

It obeys robots.txt. To keep it off your whole site, add:

User-agent: CountloyalAuditResearch
Disallow: /

It also follows the rules in your User-agent: * group when you have not named it. If you would rather talk to us, email hello@countloyal.com.