# AI readiness of hsbc.com

> Site report: 1 measured page. Overall grade: Fair.

Score 69/100, grade Fair. Measured 2026-09-18T23:24:12.74+00:00, engine axrush-engine@6.0.1.

## Checks

### Content · 78/100

#### Content Negotiation · 0/100

- **FAIL** Homepage does not serve Markdown via content negotiation
  Got text/html (HTTP 200) for "Accept: text/markdown"
  Serve a Markdown representation of your pages when agents request "Accept: text/markdown". Agents like Claude Code and Cursor ask for it, and Markdown cuts token usage by roughly 80% against HTML. Cloudflare ("Markdown for Agents") and Vercel can enable this without code changes.
  https://axrush.com/guides/content-negotiation#not-supported
- **WARN** No <link rel="alternate" type="text/markdown"> fallback found on the homepage
  If you cannot enable content negotiation, advertise a Markdown version with <link rel="alternate" type="text/markdown" href="/index.md"> so agents can discover it.
  https://axrush.com/guides/content-negotiation#no-alternate

#### Structured Data · 85/100

- **PASS** 1 JSON-LD block(s) found
- **PASS** @context references schema.org
- **PASS** @graph array present (multi-entity structured data)
- **WARN** Only 1 key type found: WebSite
  Consider adding: Person, Organization, WebPage, ProfilePage
  Add more entity types to your @graph. AI agents use these to understand site structure. Common types: Person, Organization, WebSite, WebPage.
  https://axrush.com/guides/structured-data#few-types
- **WARN** No BreadcrumbList found
  Add a BreadcrumbList entity to help AI agents understand your site navigation hierarchy.
  https://axrush.com/guides/structured-data#no-breadcrumb
- **WARN** No author declared in structured data
  An assistant deciding whether to cite a page weighs where it came from. Add author as a Person or Organization, not a bare string.
  https://axrush.com/guides/structured-data#no-author
- **WARN** No sameAs links
  sameAs is what turns a name into an entity. Link your Organization or Person to Wikidata, LinkedIn, GitHub or Crunchbase so a model can connect this page to what it already knows.
  https://axrush.com/guides/structured-data#no-same-as
- **PASS** Content last dated 2026-09-10 (8 days ago)
- **PASS** Structured-data headings appear in the visible text

#### HTML Rendering · 100/100

- **PASS** Server-rendered content detected (1655 words, 10619 chars of visible text)
- **PASS** Text-to-markup ratio is healthy (7.7% of structural markup)
- **PASS** Semantic landmarks present (main, section, header, footer, nav)
- **PASS** Single <h1> heading: "HSBC Group corporate website | HSBC Holdings plc"
- **PASS** 15/15 <img> tags have alt attributes

#### SEO Basics · 100/100

- **PASS** <title> length 48 chars: "HSBC Group corporate website | HSBC Holdings plc"
- **PASS** Meta description length 147 chars
- **PASS** Canonical URL: https://www.hsbc.com/
- **PASS** <html lang="en">
- **PASS** UTF-8 charset declared
- **PASS** Viewport meta present: "width=device-width, initial-scale=1.0"

#### Agent Operability · 65/100

- **PASS** 253/254 interactive elements have an accessible name
- **WARN** 2/4 form controls have no label
  <input type="text">
  An unlabelled box is one the agent has to guess the meaning of, which is how an email address ends up in a search field. Use <label for>, wrap the control in a label, or add aria-label.
  https://axrush.com/guides/agent-operability#unlabelled-controls
- **WARN** 1 link(s) lead nowhere without JavaScript
  0 with no href, 1 with a javascript: href
  A link with no destination cannot be followed by a fetch-only agent and cannot be opened in a new tab by a browsing one. Give it a real href, or make it a <button> if it is an action rather than a destination.
  https://axrush.com/guides/agent-operability#dead-links
- **WARN** 16/16 images, frames or videos have no declared dimensions
  Undeclared dimensions shift the layout as media loads. An agent working from a screenshot clicks where the button was a moment ago. Set width and height, or aspect-ratio.
  https://axrush.com/guides/agent-operability#unsized-media
- **PASS** Method note: this reads markup, not a rendered accessibility tree
  Labels attached by script and roles computed at runtime are invisible here, so treat low proportions as a prompt to check the real tree rather than as a count. Every finding is also a plain accessibility defect.

### Access · 93/100

#### TLS / HTTPS · 100/100

- **PASS** Site is served over HTTPS
- **PASS** HTTP requests redirect to HTTPS
- **PASS** HSTS max-age=31536000
- **PASS** HSTS includes subdomains
- **PASS** HSTS preload-eligible

#### Agent Access · 95/100

- **WARN** ClaudeBot probe failed: Network error: Request timed out
  Request timed out
  The request did not complete, so access for this crawler is unknown. Re-run the audit; if it persists, check origin health for this user agent.
  https://axrush.com/guides/agent-access#probe-failed
- **WARN** OAI-SearchBot probe failed: Network error: Request timed out
  Request timed out
  The request did not complete, so access for this crawler is unknown. Re-run the audit; if it persists, check origin health for this user agent.
  https://axrush.com/guides/agent-access#probe-failed
- **WARN** 2 crawler probe(s) could not be settled from outside
  ClaudeBot, OAI-SearchBot
  ax-audit sends this user agent from its own network without a Web Bot Auth signature, so an edge that verifies crawlers by IP range or signature will reject the probe while admitting the real crawler. Confirm against your WAF logs before changing any rule.
  https://axrush.com/guides/agent-access#inconclusive-probe

#### HTTP Hygiene · 70/100

- **WARN** A missing page redirects (301) instead of returning 404
  Location: http://www.hsbc.com/ax-audit-probe-r2s6h68m
  A redirect on a nonexistent path hides the error. Return 404 or 410 so a client can tell the difference.
  https://axrush.com/guides/http-hygiene#soft-404-redirect
- **WARN** Homepage takes 2 redirects to answer
  301 → http://www.hsbc.com/
301 → https://www.hsbc.com/
  Every hop is a round trip the agent pays for, and some clients cap redirects well below a browser. Collapse the chain: point the first URL straight at the final one.
  https://axrush.com/guides/http-hygiene#redirect-chain
- **PASS** HEAD requests are supported
- **PASS** Content-Type: text/html with charset

#### Crawl Efficiency · 100/100

- **PASS** Response compressed with gzip
  Brotli (br) typically compresses text 10–20% smaller. Consider enabling it.
- **PASS** Cache validator present (ETag)
- **PASS** Conditional request returns 304 Not Modified
- **PASS** Homepage size is reasonable (152.8 KB decompressed)
- **WARN** Roughly 2,655 tokens of content in 39,095 tokens of response (93% markup)
  Estimated at four characters per token.
  An agent pays to receive the markup and then discards it. Serving Markdown on Accept negotiation is the direct fix.
  https://axrush.com/guides/crawl-efficiency#markup-overhead
- **PASS** Homepage responded in 420ms

#### AI Directives · 100/100

- **PASS** Homepage is indexable
- **PASS** No directive restricts how AI assistants may use this page

### Discovery · 42/100

#### LLMs.txt · 0/100

- **FAIL** /llms.txt not found
  HTTP 404
  Create a /llms.txt file at your site root following the llmstxt.org specification. It should be a Markdown file starting with "# Your Site Name" and include a description, sections, and links.
  https://axrush.com/guides/llms-txt#not-found

#### Robots.txt · 55/100

- **PASS** /robots.txt exists
- **FAIL** No core AI crawlers explicitly configured
  Expected: GPTBot, ClaudeBot, Meta-ExternalAgent, Google-Extended, Applebot-Extended, Amazonbot, Bytespider, CCBot, OAI-SearchBot, Claude-SearchBot, PerplexityBot, ChatGPT-User
  Add User-agent entries for core AI crawlers in your robots.txt. For each crawler, add: User-agent: <name> followed by Allow: / on the next line.
  https://axrush.com/guides/robots-txt#no-core-crawlers
- **WARN** No Sitemap directive found
  Add a Sitemap directive to your robots.txt: Sitemap: https://your-site.com/sitemap.xml
  https://axrush.com/guides/robots-txt#missing-sitemap
- **WARN** No Content-Signal directive found (optional)
  Declare how crawlers may use your content after access with the Content Signals Policy, e.g.: Content-Signal: search=yes, ai-train=no. Known signals: search, ai-input, ai-train, plus the optional use=immediate|reference|full. Generate yours at contentsignals.org.
  https://axrush.com/guides/robots-txt#missing-content-signals
- **WARN** 0/57 known AI crawlers have explicit rules
  Add explicit User-agent entries for more AI crawlers to maximize discoverability.
  https://axrush.com/guides/robots-txt#low-coverage

#### Sitemap · 0/100

- **FAIL** No sitemap found
  Tried robots.txt Sitemap: directive and /sitemap.xml
  Publish an XML sitemap at /sitemap.xml and reference it from robots.txt with: Sitemap: https://your-site.com/sitemap.xml
  https://axrush.com/guides/sitemap#not-found

#### Meta Tags · 49/100

- **WARN** No AI meta tags (ai:*) found
  Add AI meta tags to your HTML <head>: <meta name="ai:summary" content="Brief description">, <meta name="ai:content_type" content="website">, <meta name="ai:author" content="Your Name">.
  https://axrush.com/guides/meta-tags#no-ai-meta
- **WARN** No rel="alternate" link to llms.txt in HTML
  Add to your <head>: <link rel="alternate" type="text/plain" href="/llms.txt" title="LLM-optimized content">
  https://axrush.com/guides/meta-tags#no-llms-alternate
- **WARN** No rel="alternate" link to the Agent Card in HTML
  Add to your <head>: <link rel="alternate" type="application/json" href="/.well-known/agent-card.json" title="Agent Card">
  https://axrush.com/guides/meta-tags#no-agent-alternate
- **WARN** No rel="me" identity links found
  Add rel="me" links to verify your identity across platforms: <link rel="me" href="https://github.com/yourname">, <link rel="me" href="https://twitter.com/yourname">.
  https://axrush.com/guides/meta-tags#no-rel-me
- **PASS** OpenGraph required tags present (og:title, og:description, og:url, og:type)
- **WARN** Twitter Card required tags missing: twitter:title, twitter:description
  Add these meta tags: <meta name="twitter:title" content="...">, <meta name="twitter:description" content="...">.
  https://axrush.com/guides/meta-tags#twitter-required-missing

#### HTTP Headers · 85/100

- **PASS** 6/7 security headers present
- **WARN** No Link header for AI discovery (llms.txt, Agent Card)
  Add a Link response header pointing to your AI discovery files: Link: </llms.txt>; rel="alternate"; type="text/plain", </.well-known/agent-card.json>; rel="alternate"; type="application/json"
  https://axrush.com/guides/http-headers#no-link-header
- **WARN** No machine-readable discovery relations beyond llms.txt and the Agent Card
  describedby: llms.txt v2 uses this relation to point a page at the llms.txt that covers it.
api-catalog: RFC 9727: the catalog of APIs this publisher offers.
service-desc: RFC 8631: a machine-readable API description.
service-doc: RFC 8631: human documentation for the API.
ai-catalog: Draft: the AI catalog listing agent cards and MCP server cards.
c2pa-manifest: C2PA 2.4: content provenance for media on the page.
license: RSL and other machine-readable licensing terms.
  Advertise what you publish with Link relations so agents stop guessing paths. Add the ones that apply, for example: Link: </llms.txt>; rel="describedby", </.well-known/api-catalog>; rel="api-catalog". Informational in 3.x: this does not affect your score.
  https://axrush.com/guides/http-headers#discovery-relations

### Protocols

#### Agent Card (A2A) · N/A

- **PASS** No agent-facing surface: an Agent Card does not apply to this site
  No API, MCP server or existing card was found. An Agent Card advertises capabilities another agent can invoke; a site that offers none has nothing to put in it. Run with --profile agent to audit as though it did.

#### OpenAPI Spec · N/A

- **PASS** No API surface: API discovery does not apply to this site
  No description, catalog, service-desc relation or developer area was found. Run with --profile api to audit as though the site offered one.

#### MCP (Model Context Protocol) · N/A

- **PASS** No MCP server: MCP discovery does not apply to this site
  A server card describes an MCP server so agents can find it. A site that runs none has nothing to advertise. Run with --profile mcp to audit as though it did.

#### AI Catalog · 0/100 (reports, does not score)

- **WARN** No agent resource catalog found
  Checked robots.txt Agentmap: directive, Link header rel="ai-catalog", <link rel="ai-catalog">, well-known path and /.well-known/ai-catalog.json, /.well-known/ard.json. Both specifications are drafts.
  A catalog is one document listing everything an agent can call here (agent cards, MCP servers, APIs, skills), so a client stops probing four conventions to find out. Worth publishing once you have more than one of those. Informational: both ai-catalog.json and ard.json are still drafts, so this never affects your score.
  https://axrush.com/guides/ai-catalog#not-found

#### Agent Skills · N/A

- **PASS** No developer-facing surface: skills do not apply to this site
  No documentation links, llms.txt, or API description found. Skills describe procedures an agent follows; a site with no procedures to teach has nothing to publish.

#### Commerce Discovery · N/A

- **PASS** No commerce surface: agentic-commerce discovery does not apply to this site
  No Product or Offer structured data, cart links, or product price tags found.

#### Auth Discovery · N/A

- **PASS** Nothing on this site requires authorization: auth discovery does not apply
  No API description, API catalog, MCP server card or commerce profile found.

#### WebMCP · 100/100 (reports, does not score)

- **WARN** 2 form(s) on the page, none declared as agent tools
  WebMCP is a W3C Community Group draft in a Chrome origin trial. It is not a standard and adoption is minimal, so this is a forward-looking note, not a defect.
  A declared form is called by an agent rather than driven pixel by pixel. Add toolname and tooldescription to the forms worth automating (search, filter, subscribe) and toolparamdescription to each field.
  https://axrush.com/guides/webmcp#no-annotations

### Policy · 33/100

#### Security.txt · 45/100

- **PASS** /.well-known/security.txt exists
- **FAIL** Required field "Contact" missing (RFC 9116)
  Add "Contact:" to your security.txt. Use a mailto: or https: URI, e.g., Contact: mailto:security@example.com
  https://axrush.com/guides/security-txt#missing-field
- **FAIL** Required field "Expires" missing (RFC 9116)
  Add "Expires:" to your security.txt. Use an ISO 8601 date, e.g., Expires: 2026-12-31T23:59:59.000Z
  https://axrush.com/guides/security-txt#missing-field
- **WARN** No optional fields (Canonical, Preferred-Languages, Policy, etc.)
  Consider adding Canonical: (canonical URL), Preferred-Languages: (e.g., en), and Policy: (link to your security policy).
  https://axrush.com/guides/security-txt#missing-optional

#### RSL License · 0/100

- **FAIL** No RSL license discovery found
  Checked robots.txt License directive, Link header, and <link rel="license" type="application/rsl+xml">
  Declare machine-readable licensing terms for your content with Really Simple Licensing. Add to robots.txt: License: https://your-site.com/license.xml, then publish the RSL document. See https://rslstandard.org.
  https://axrush.com/guides/rsl#not-found

#### Usage Policy · 40/100

- **WARN** No machine-readable usage policy declared
  Checked robots.txt Content-Signal and Content-Usage, the Content-Usage and content-signal response headers, an RSL licence, TDMRep, and the noai meta directive.
  State your terms where they can be read without a lawyer. The lowest-effort option is a Content-Signal line in robots.txt: Content-Signal: search=yes, ai-input=yes, ai-train=no. Absence is neutral, not permission, but it also gives you nothing to point at.
  https://axrush.com/guides/usage-policy#no-policy

## Turn this report into ongoing improvements

Give your team full reports, prioritized fixes and monitoring, so improvements last beyond the next release.

- [Get started with AX Rush](https://axrush.com/signup)
- [See plans](https://axrush.com/pricing)

## Connect the AX Rush MCP to your site

Scan your site and read its reports from Codex, Claude or Cursor. No account needed.

- [See how to connect](https://axrush.com/developers/mcp)

- [Read this report via the API or the MCP server](https://axrush.com/developers)

---

Markdown representation of https://axrush.com/report/hsbc.com
