Calibre Squad

Work  ·  Financial services  ·  Perth

A compliance problem wearing a website’s clothes.

Pura Finance Group asked us to make some changes to their website. Within an hour it was clear the changes were not the point.


The brief

The site had been inherited, not chosen.

The business had commissioned a website from a previous developer and been handed the keys without the knowledge that comes with them. What they had was a purchased page-builder template that had never been fully de-templated — the demo content was still in place, underneath a coat of paint.

That is a common enough story. What made this one urgent is that Pura Finance Group is a credit representative operating under an Australian Credit Licence. Several of the things sitting on that site were not cosmetic problems. They were representations a licensee has to be able to stand behind.

So the first job was not design. It was working out what had to come off the site that day.

The audit

What was actually on the site.

01

Australian Credit Licence XXXXX

A placeholder sat where the licence number belongs, in the footer of every page. For a credit representative that is a disclosure failure, not a typo.

02

Performance claims that could not be substantiated

99% approval. 8,900 happy customers. $90K in daily payments. A 99.9% success rate guarantee. All template filler, all live on a regulated business.

03

Three testimonials that were never real

Different names, the same job title, stock avatars. Demo content shipped with the template and never replaced.

04

Another company’s name in the service copy

The template vendor’s brand appeared twice on the homepage, describing the services as though it were them.

05

Lorem ipsum on three homepage cards

Placeholder Latin sitting where each service description should have been.

06

A contact form that delivered nothing

It reported success on every submission. The messages were accepted and silently discarded. Enquiries had been going missing since launch.

07

No Credit Guide, complaints process or privacy policy

Three documents a credit representative is expected to make available. None were published.

08

No H1 headings and no meta descriptions, anywhere

Across every page checked. Search engines had almost nothing to work with.

09

Not one clickable phone number or email address

On a business where most traffic arrives on a phone, the number could not be tapped to dial.

Why it mattered

Fabricated numbers on a credit licensee’s website are not a copywriting problem.

Approval rates and customer counts are representations. Invented testimonials are misleading conduct. A placeholder where a licence number belongs is a disclosure failure. None of it had been put there deliberately — it arrived with the template — but it was published, and it was live.

The work

Exposure first. Everything else after.

Day one

Take the exposure down

Deletions only, no design work. The fabricated statistics, the three invented testimonials, the other company’s name, the lorem ipsum, a line offering student lending they do not provide. Nothing here needed a decision — it needed removing, and it was gone the same afternoon.

Week one

Correct the disclosure, fix what was broken

We traced the licensing chain properly — the licensee, the Australian Credit Licence, both credit representative numbers, AFCA and FBAA memberships — and verified every figure against the AFCA register and the client’s own documents before publishing any of it. Then the contact form, which turned out to be a longer story.

Weeks two to four

Rebuild, rather than patch

The template was fighting every change. We rebuilt the site by hand — eleven pages, no page builder, no plugin stack — with the copy written around what the business actually does: asset and equipment finance for sole traders, companies, trusts and partnerships.

The interesting bit

The form said it worked. It did not.

Every submission returned a success message. Nothing ever arrived. The obvious suspects — spam folder, wrong address, a misconfigured plugin — all came back clean.

The delivery log told the real story: zero records. The messages were not failing to deliver, they were never entering a queue that delivers. The domain’s mail runs on Microsoft 365, but the web host was accepting mail for it locally and dropping it into a mailbox that did not exist.

At that point the right call is to stop debugging someone else’s mail server. We moved the enquiry pipeline onto an email API we could observe, on a dedicated sending subdomain so the client’s Microsoft 365 configuration was never touched. Every enquiry is now written to disk before the send is attempted, so a delivery failure can never again cost them a lead silently.

11Pages rebuilt by hand
8Legacy URLs redirected
3Compliance documents published
0Placeholders remaining
Where it landed

What the business has now.

Eleven hand-built pages with a single H1 and a unique description each — previously there were none of either. Licensing disclosure that is correct and verified. A Credit Guide page, a complaints and dispute resolution page naming AFCA, and a privacy policy written for the site rather than borrowed from one.

Every address from the old site — eight of them — redirects permanently to its replacement, so no bookmark and no search result was lost on the day of the switch. The changeover took under an hour, with the previous site left intact and reversible for a fortnight afterwards.

And the enquiry form delivers, which it had not been doing for as long as anyone could establish.

See the site we built ↗

The through-line

The brief said “make some changes to the website”. The job was a compliance audit that happened to end in a rebuild.

Most engagements are like this. The brief describes the symptom.

Start a conversation ↗