For enterprise digital estates

Your problem is not one broken site. It is not knowing which ones.

A counted inventory, one comparable measure across every property, and an owner attached to every finding. Governance first — because at your scale nothing gets fixed until somebody can see it and somebody is accountable for it.

Estate by business unit340 properties
  • Retail EMEA84 properties81Stable
  • Consumer Finance52 properties58Watch
  • Careers & HR19 properties44Act now
  • Campaign microsites63 properties · no named owner76Unscanned

The fourth row is the one that matters. In most estates the largest single risk is the set of properties nobody has counted — campaign sites, regional landing pages, acquired brands still on their own stack.

Illustrative example — not real estate data.

01 — Inventory

You cannot govern what nobody has counted.

Every large estate we have looked at has properties that are not on any list — and those are where the exposure concentrates.

  • The orphaned properties

    Campaign microsites built by an agency three years ago. Regional pages a country team spun up. Brands you acquired that are still on their own stack. They rarely appear in a governance programme and they are usually the least accessible things you own.

  • One measure, or no comparison

    If three business units use three tools with three scoring methods, you cannot rank risk across them and you cannot hold anyone to a target. A single scoring method across the estate is worth more than a marginally better method used inconsistently.

  • A name against every finding

    Findings without an owner do not get fixed, they get reported again next quarter. Properties map to business units, business units map to people, and the record shows how long each item stayed open and with whom.

// Coverage, not just score

Properties inventoried 340 / 34084

Scanned in the last 30 days 277 / 34052

With a named owner 212 / 340121

Critical findings closed within SLA 38 / 9183

Illustrative layout. Coverage metrics tell a governance owner more than an average score, because an average across 340 properties hides both the best and the worst.

02 — Access

Who sees what, and who answers for it.

Available today, and one significant gap stated plainly rather than left for your security review to find.

  • Multi-account structure

    Each brand, region or business unit is a separate account under one organisation, so a country team sees its own properties and the group function sees all of them.

    Available
  • Role-based access control

    Separate what a developer, a compliance reviewer, an agency partner and a finance approver can each see and do. Reviewers get read access to evidence without touching configuration.

    Available
  • SSO, SAML and SCIM provisioning

    Not available yet, and this is the honest blocker on the page. We know most enterprise IT security functions will not approve a SaaS purchase without single sign-on, so we are not going to let you discover this in a questionnaire three weeks into an evaluation. Until it ships, access is managed through role-based accounts under a multi-account structure. Ask for the current target date at the first conversation — we will give you engineering's answer, not a comfortable one, and we will tell you if it moves.

    SOON

03 — Execution

Visibility is the easy half. Here is the other one.

Findings do not fix themselves, and a dashboard that only counts them becomes an expensive way to feel informed.

Work your teams can pick up

Every developer-side finding exports as a ticket with the selector, the criterion, priority and legal risk, plus framework-specific guidance for HTML, React, Vue and Angular.

Expert remediation on demand

Where a team has no capacity, our specialists do the work. Quarterly audits and remediation sprints run against the properties you prioritise, not against whatever scored lowest.

PDF remediation, unlimited

Annual reports, product sheets, forms, policy documents. Large organisations forget that their document library is in scope, and it is often the largest single block of inaccessible content they own.

Full white-label rebrand

For groups that present a single internal platform to their business units, the environment can carry your identity rather than ours.

Custom API and webhooks

Push results into your own risk register, data warehouse or internal dashboard. A CLI is available for pipeline gating where teams want the check before merge.

Human audit, at intervals

Screen reader, keyboard-only, and testing by people who use assistive technology daily — on the properties where an automated score is not a sufficient answer.

04 — Commitments

What we will sign, and what we will not.

Your procurement team will test both lists. Better that they read them here than discover them in redlines.

  • We will

    Service levels in the contract

    Response times, uptime and scan frequency are contractual terms, not aspirations on a webpage. Your account has a named manager and a shared channel rather than a ticket queue.

  • We will

    Report the inconvenient findings

    New issues introduced by your own releases appear in the record. If two numbers in a report disagree, we tell you rather than quietly choosing one. A trend line that only improves is one your internal audit will not believe.

  • We will not

    Certify your estate as compliant

    No vendor can make 340 properties conformant from the outside, and any who says otherwise is describing a document, not a state of the world. We make the problem visible, comparable and assignable. Conformance is produced by your teams changing code, and we will say that in front of your board.

  • We will not

    Assume your legal exposure

    No widget, report or certificate provides legal immunity, and a service level on our uptime is not a warranty on your compliance. Risk transfer is what insurance is for; that is a conversation with a broker, not a clause in a software agreement.

Why we put the second list on the page: at enterprise scale the expensive failure is not choosing the wrong tool. It is a programme built on a promise that quietly turns out to be narrower than everyone assumed, discovered eighteen months in, by which point the governance structure, the reporting to the board and the internal targets all rest on it.

05 — Service

The numbers that go in the contract.

Infrastructure tier terms. Commercial terms are volume-based and annual — there is no list price and we will not invent one.

  • 1 hour

    Response SLA

  • 99.5%

    Uptime SLA on our service

  • Real-time

    Scan frequency

  • Named

    Account manager and shared channel

Read the uptime figure correctly

99.5% describes the availability of our platform. It says nothing about the accessibility of your properties, and it is not a compliance metric. We separate the two here because they get conflated in vendor comparisons more often than any other pair of numbers in this category.

05b — Security posture

What we can evidence, and what we cannot yet.

You will send a security questionnaire. These are the answers before you do — including the uncomfortable one.

No visitor data collected

The widget sets no tracking cookies. Visitor accessibility preferences stay in their own browser and never reach us. There is no visitor dataset to breach, which removes a whole category of question from your assessment.

GDPR and CCPA ready

Built to operate without collecting personal data from your visitors, which is what keeps the data-protection position simple rather than something your DPO has to engineer around.

Delivery and payment

The script is served encrypted from a CDN edge and updates itself, so no property in your estate is left running an unpatched version. Card details go through a PCI-compliant gateway and are never stored by us.

Formal certifications

We publish our certification status rather than implying one. Ask us directly for the current position on SOC 2, ISO 27001, hosting region, encryption at rest, our sub-processor list and a DPA, and you will get a written answer the same week — including where the answer is "not yet". We would rather fail your assessment on a fact than pass it on an implication.

On scale, stated as architecture rather than as a customer count: accounts nest under one organisation, so the operating model does not change between ten properties and five hundred — the same role structure, the same scoring method, the same reporting. We are a young company and we are not going to imply a customer list we do not have. What we will do is put our solution engineering team on your estate and show you the method before you commit to it.

06 — FAQ

Questions, answered honestly.

Do you support SSO / SAML / SCIM?

Not yet. It is on the roadmap and it is marked as such everywhere on this site, including in pricing. We would rather lose an evaluation at the first meeting than pass a security review on an implication and have the gap surface at contract stage. If it is a signature requirement, raise it immediately and ask for dates.

We have properties nobody owns. Where do we start?

With counting, not with fixing. An inventory that names every property and assigns an owner is worth more in the first quarter than remediation work on the three sites you already know about. Unowned properties are where exposure concentrates precisely because nobody is watching them. Our solution engineering team does this exercise with you; it is usually the least technical and most politically difficult part of the programme.

Can you replace our existing accessibility vendor across the group?

Migration from any provider is supported, and priority migration is included with an annual plan. One expectation to set now: switching vendor does not improve underlying code, and your scores may not rise. If a previous dashboard showed materially higher numbers, the likely explanation is a different scoring method or a narrower test set rather than a regression. We will put that in writing before you present the first comparison internally.

How do you price at this scale?

Volume-based, annual, and quoted against your actual estate — number of properties, traffic, scan frequency, and how much remediation you want us to perform rather than assign. There is no list price for this tier and we will not put an indicative figure on a webpage, because a number quoted without knowing your inventory is a number that gets renegotiated. Ask for a quote and you will get a real one.

What does a first year usually look like?

Inventory and baseline first, then owners assigned, then remediation sequenced by legal risk rather than by ease. Human audits run against the properties where an automated score is not a sufficient answer — usually transactional journeys. Expect the estate-wide average to move slowly and the count of open Critical findings to move fast; the second is the metric worth reporting upward, because an average can improve while nothing structural changes.

Who is accountable if a property fails after we have paid you?

We are accountable for the service levels in the contract: that scans run, that findings are reported accurately and completely, that the evidence trail is intact, and that work we performed was done to standard. We are not accountable for the conformance of properties your teams control and change. That line is worth agreeing explicitly during contracting rather than discovering it during an incident, and we will draw it in the same place in a negotiation as we do on this page.

Start with the count. Everything else depends on it.

Our solution engineering team will work through your estate with you and tell you what is actually there — including the parts nobody has been looking at.

How many web properties are in scope?

A solution engineer is assigned to every enterprise conversation, whatever you pick. The last option is a common and entirely reasonable answer — establishing the count is usually the first piece of work.

For organisations that would rather know the real number than report a comfortable one.