For compliance and risk teams
We will not tell you that you are compliant. We will give you the record.
A timestamped, reproducible evidence trail against WCAG 2.2 AA — with the scope, the method and the limitations stated in every document, so it holds up when somebody reads it carefully.
- Scope and method in every report
- VPAT / ACR for procurement
- Totals reconcile or we tell you
18records on file
- Quarterly compliance report issuedPDF
- 14 developer-side findings closed, verified by re-scanClosed
- Manual audit — screen reader, keyboard, AT usersHuman
Open items stay visible. A record that only shows closed findings is not evidence of diligence — it is evidence of editing.
Illustrative example — not real audit data.
01 — Evidence
What a defensible record actually looks like.
Not a badge and a date. A sequence of dated actions, each one reproducible from the underlying data.
- Day one
Baseline, with scope stated
Pages scanned, sampling method if the scan is not exhaustive, standard tested against, and the date. The starting position is written down before anything is fixed, because "we improved" means nothing without a measured beginning.
- Continuously
Scheduled re-scans, including the bad news
Score-over-time with every scan timestamped. New issues introduced by a release appear in the record too. We do not suppress new findings to make a trend line look better.
- Per finding
Closure verified, not asserted
A finding moves to closed when a re-scan confirms it, and the record keeps both the date it was raised and the date it was verified. Anyone reviewing later can see how long each item stayed open.
- Periodically
Human testing, with evidence attached
Manual audits cover what automation cannot judge: screen reader testing with NVDA, JAWS and VoiceOver, keyboard-only navigation, visual and contrast analysis, and testing by people who use assistive technology daily. The report carries visual evidence and severity ratings, not a summary opinion.
- On request
Export, filtered the way a reviewer needs it
Reports filter by issue severity, date range and WCAG category. When internal audit asks for everything Critical raised in Q2 and not yet closed, that is a filter, not a project.
02 — Documents
Four documents, four different readers.
Each one exists because a specific person asks for it. None of them is a compliance claim.
- DOC 01
Accessibility statement
Reader: the public, and any regulator who looks. Published in your own footer. It describes your current state, your known limitations and how someone reports a barrier to you. A statement that claims full conformance while the site has open Critical findings is worse than no statement — it is a documented inconsistency.
- DOC 02
Compliance report
Reader: internal audit, your board, your counsel. A PDF showing what was found, what was fixed, when, and what remains — with an executive summary that explains what the score means rather than presenting a bare number. Available quarterly on the Infrastructure tier, monthly on Scale.
- DOC 03
VPAT 2.5 / ACR
Reader: procurement, on the other side of a bid. The Accessibility Conformance Report that government and enterprise buyers ask for, mapped to Section 508 and EN 301 549. Note the distinction that matters in procurement: a VPAT documents a product's accessibility. It is not a certificate for your website.
- DOC 04
Certificate
Reader: anyone your team hands it to. Dated, and linked to a live transparency profile that shows which areas are accessible and where work is ongoing. We do not issue static compliance badges. If a colleague expects a permanent seal, this is the document that will disappoint them, and it is the one that will survive scrutiny.
03 — Refusals
What we refuse to put in writing.
You have read vendor claims before. Here are ours in advance, so you can check whether the documents match them.
“Your site is compliant”
No document we produce will say this. Conformance is a property of the site, assessed against every applicable success criterion including the ones only a human can judge. What our documents state is what was tested, when, by what method, and what was found.
“This protects you legally”
No widget, report or certificate provides legal immunity. Courts under the ADA look at whether the site is actually usable. Documentation supports a defence of documented, continuing effort; it does not replace one, and it does not transfer your exposure to us.
A score without its meaning
Every report explains what the number measures, what a typical starting score looks like, and that automated scoring covers only the machine-testable portion of WCAG. A bare “22.7/100” on a board slide is alarming and uninformative in equal measure.
A clean report that hides open items
Monitoring reports state honestly what the widget helps with and what needs a developer. New issues are not suppressed to protect a trend line. A record that only improves is a record nobody senior will believe.
Why this is the section we lead with for your team: compliance functions are usually the ones left holding a vendor's overstatement. The value of a supplier who will not overstate is not modesty — it is that everything else they hand you can be relied on without re-verification.
04 — Integrity
The checks we run before a report reaches you.
If your team has ever had to explain why two numbers in the same document disagree, this list is for you.
- Page count in the summary equals the page count in the appendix
- Total issue count equals the sum of the severity buckets, with no uncategorised remainder
- Every WCAG criterion cited is verified to exist in WCAG 2.2 — by lookup, not from memory
- The score is reproducible from the underlying data
- No page appears in the appendix that falls outside the stated scope
- Dates are consistent across the cover, the summary and the appendix
The limitation printed in every report
Automated testing reliably detects 30–50% of WCAG 2.2 AA success criteria. The remainder requires human judgement, and this report is not a conformance claim. Those two sentences appear in the scope and method section of every report we produce, under our brand or a partner's. If you are comparing vendors, look for where their equivalent sentence is — and how large the print is.
05 — When something arrives
A demand letter lands. What is already in the file?
The work that matters at that point was all done before it arrived.
In the file already
- A dated baseline, so the timeline of effort starts before the complaint, not after it
- Findings with severity, legal-risk rating, owner and closure date
- A published accessibility statement with a working channel for reporting barriers
- Human audit evidence, which is the part automation cannot supply
What we can and cannot do next
- Can: assemble the technical record your counsel asks for, prioritise the specific barriers named in the complaint, and put an expert on remediation.
- Can: provide a dedicated case manager and a response toolkit on the Scale tier, so your team is not assembling this from scratch under time pressure.
- Cannot: advise you on the claim, represent you, or assume your liability. A response toolkit is preparation material, not counsel, and we will say so in the toolkit itself.
05b — Data handling
Where the record lives.
You are going to send us a security questionnaire. These are the answers we can give before you do.
No visitor tracking
The widget sets no tracking cookies. A visitor's accessibility preferences stay in their own browser's local storage and are never sent to us or to advertisers. There is no visitor profile to breach because we do not build one.
GDPR and CCPA ready
The widget is built to operate without personal data collection from your visitors, which is what makes the data-protection position straightforward rather than something you have to engineer around.
Delivery and payment
The script is served encrypted from a CDN edge and updates itself, so you are not carrying an unpatched version. Card details are handled by a PCI-compliant gateway and are never stored by us.
Exit and deletion
If you leave, dashboard access continues to the end of the paid period, then you have 30 days to export reports and settings, after which data is deleted per our privacy policy. Written into the billing terms, not left to goodwill.
06 — FAQ
Questions, answered honestly.
Do you offer a legal warranty, indemnity or guarantee?
No. Some vendors in this category offer something described as a legal pledge or warranty. Read those terms closely with your counsel — they are typically narrow, conditional, and capped. Our position is simpler: risk transfer is what insurance is for, and that is a conversation with a broker, not a feature of a SaaS subscription. What we sell is testing, remediation and evidence.
Our board wants a single number. What do we show them?
Show the score, but never alone — every report pairs it with what it measures and what it excludes. Two figures usually serve a board better: open Critical findings, and median time to close. The first is exposure, the second is whether your process works. A score can improve while nothing structural changes; time-to-close cannot.
Can we publish an accessibility statement before everything is fixed?
Yes, and in most cases you should. A statement is meant to describe your current state, your known limitations and how to reach you about a barrier — not to announce a finished project. The version that creates risk is the one claiming full conformance while Critical findings are open, because it is a documented inconsistency in your own words.
Procurement asked for a VPAT. Does that cover our website?
Not automatically, and this trips up a lot of teams. A VPAT documents the accessibility of a specific product or service against Section 508 and EN 301 549. If procurement is asking about the software you sell, that is the VPAT you need. If they are asking about your public website, a compliance report against WCAG 2.2 AA is usually the right artefact. We produce both, and we will tell you which one the request is actually about if you forward it to us.
How do we handle third-party content we do not control?
Embedded widgets, payment iframes, chat tools and syndicated media are a real and common gap. Our reports identify them and attribute them, so the record shows the barrier was found and where responsibility sits. What that means for your obligations depends on your jurisdiction and your contracts — that part is a question for counsel. Practically: raise it with the supplier in writing and keep the correspondence with the rest of the record.
How long do you retain the audit history?
While your account is active, the audit history remains available in full. On cancellation you keep dashboard access to the end of the paid period, then 30 days to export reports and settings, after which data is deleted in line with our privacy policy. If your retention policy requires a longer period or a specific format, raise it before you sign — it is easier to agree in the contract than to reconstruct afterwards.
Start the record today, not after the letter.
A dated baseline costs nothing and takes minutes. Everything defensible that follows is measured from it.
<a href="/reports" style="color: #ffffff; text-decoration: underline; text-underline-offset: 3px;"> Or look through the documents first </a> For teams who would rather hold an accurate record than a reassuring one.
