Qaynaq STUDIO ’26 / BAKU
Journal AI

Inside the $0.50 free audit

How the site is fetched, what the AI actually sees, what the human edits, and why I personally read the first twenty reports.

Qaynaq’s lead magnet is free. Building something that’s free isn’t actually easy — you still owe the partner real work. Here are the technical steps, the cost structure, and the decision points, in the open.

The pipeline has two halves

Half 1 — mechanical findings

The moment a partner submits the form:

  1. Playwright (stealth) fetches the site — residential IP, real User-Agent, normal navigation pattern, so Cloudflare doesn’t filter the request.
  2. Lighthouse and axe-core pull the mechanical metrics — performance, SEO headers, contrast, keyboard navigation, ARIA errors.
  3. HTML, header, and robots.txt analysis — CSP, HSTS, meta tags, structured data, sitemap.
  4. Outdated dependency scan — script src attributes get parsed for old Bootstrap, jQuery, double-mounted GTM, the usual suspects.

This half doesn’t touch AI. Every finding has a precise source.

Half 2 — synthesis

Now we hand three contexts to the Claude API:

  1. The structured output of Half 1, as JSON.
  2. Quoted HTML fragments from the site (only the relevant chunks).
  3. The partner’s business category — e-commerce, corporate, agency, etc.

The LLM returns structured JSON, not prose. This matters: the PDF template fills field by field from that JSON. A hallucination can’t poison the whole report because every finding without a source is dropped.

Models in use:

StepModelWhy
ExtractionHaiku 4.5Fast, cheap, simple format
SynthesisSonnet 4.6Strong prose, sound judgment
Risk scoringSonnet 4.6Lower hallucination on the rating axis

Prompt cache is on. A repeat audit on the same site is roughly 30% cheaper.

Cost per report

Average marginal cost:

  • Playwright fetch + Lighthouse: ~$0.05 (CPU time)
  • Claude API: ~$0.40
  • PDF rendering: ~$0.02
  • Email send (Resend): ~$0.001
  • Storage (Supabase): ~$0.005

Total: ~$0.48 per report.

Even with a 2% conversion to a paid engagement, the lead magnet pays for itself many times over.

”Can’t AI just do the whole thing?”

Answer: no. And we don’t hide the limit.

What AI does well here:

  • Mechanical surfaces — header staleness, performance bottlenecks, SEO structure issues.
  • Synthesis — collapsing dozens of data points into a readable report.
  • Format normalisation — making different sources line up.

What AI doesn’t do well:

  • UX judgment in context — “why isn’t this CTA working” needs business context the model doesn’t have.
  • Brand quality — “this typography is wrong” is human judgment.
  • Market positioning — “what should you do differently from your competitor” is strategy.

This is why I read the first twenty reports myself. I edit the AI output, drop in human-written notes on the “attention” sections, and tighten the language. After the first twenty, the patterns repeat and I move to spot-checks.

The PDF structure

  1. Summary — three highest-impact findings, one sentence each.
  2. Triage (Phase 1) — what to fix in a week.
  3. Foundation (Phase 2) — four to six weeks of structural work.
  4. Strategic (Phase 3) — longer-horizon rebuilds.
  5. What this audit doesn’t cover — explicit, listed.

That last section earns the report. “What this audit doesn’t cover” does two jobs: it sets legal boundaries, and it sets up the conversation about a paid engagement.

Risks I run

Risk 1: AI hallucination. Mitigation: every finding cites a source (line / header / file). No source, no entry in the PDF.

Risk 2: Cloudflare blocks the stealth fetch. Mitigation: residential IP pool plus reasonable rate limits. If a site is fully blocked, the report says so explicitly — partial reports are labelled as partial.

Risk 3: This reads like cold outreach. Mitigation: opt-in only. I never email someone who didn’t fill the form. The partner submits their own URL; the report goes to their own inbox.

Why I’m publishing this

Most studios that sell “AI audits” hide how the pipeline works. We do the opposite: the process is in the open so partners can judge how reliable the report is for themselves.

This isn’t “we use AI.” It’s how we use AI.