DIRECTIVE (EU) 2019/882 · IN FORCE SINCE 28 JUNE 2025 EU-HOSTED · GDPR-CLEAN
EAA Compliance

CHANGELOG

What changed, and why.

Every release that touches your evidence, your documents or the API. Entries that change API behaviour are tagged, and breaking changes only ever arrive in a new major version. Work done before the platform opened to customers is marked pre-release.

SUBSCRIBE BY WEBHOOK FROM YOUR PORTAL · 17 ENTRIES

18 AUG 2026Platform
Added

Our own accessibility statement, and the legal set

We publish an accessibility statement for eaacompliance.org produced the same way our customers' are — including the problems we have not fixed yet. Alongside it: privacy notice, terms, data processing agreement and imprint.

  • The statement names three real defects on our own site rather than claiming a clean sheet.
  • Analytics are aggregate page counts with no cookies and no identifiers, so there is no consent banner to dismiss.
We hold ourselves to what we sell.It would be indefensible to publish a statement about our own site that we would not accept from a customer.
18 AUG 2026Platform
Added

Status page and this changelog

Self-hosted status with ninety days of component history, and a public record of every change that touches your evidence, your documents or the API.

When an outage touches your evidence, it goes in your ledger.A delayed scan is not a clean scan. A gap you can explain is worth more than a gap someone discovers during an audit.
18 AUG 2026Platform
Added

Client workspaces, pooled capacity and white-label documents

Agencies run each client as a separate evidence file — own domains, matrix, sign-offs and ledger — while capacity comes from one shared pool.

  • Opening a client workspace writes an entry in that client’s ledger, every time.
  • Settings: authorize colleagues by Google account, manage API keys and webhook endpoints yourself.
Provenance is never white-labelled.Every export keeps its scan id, engine and date. A document a regulator cannot trace is worth nothing to the client you are billing for it.
17 AUG 2026API
Added

Public API v1 and signed webhooks

Pull coverage, findings, the ledger and generated documents into your own systems, and stop polling: six events are delivered with an HMAC signature and retried for hours.

  • A scan requested over the API is capacity-metered like any other, returning 409 rather than pretending.
The API cannot declare compliance.No endpoint resolves a finding, signs off a criterion or sets a compliance status. Those are earned by evidence.
16 AUG 2026Security
Changed

Google sign-in only

Removed the email link rail entirely. One way in means one surface to secure and nothing to phish; sessions stay first-party cookies with no password anywhere in the system.

14 AUG 2026Billing
Added

Capacity billing, and what happens when you run out

Plans are metered by pages per month across all your domains, with the effective rate per thousand pages shown in the portal. At capacity, scheduled scans step down to the lowest frequency your plan allows.

  • They never stop, and the change is recorded in your ledger.
  • A failed payment never locks your evidence — exports, ledger and matrix stay available.
12 AUG 2026Pre-release
Added Pre-release

Accessibility statement and regulator response pack

Two documents generated from the same evidence file, so they can never disagree. The statement’s compliance status is computed from the matrix rather than selected from a dropdown.

  • The response pack carries a 30-day ledger excerpt: monitoring proven, not claimed.
"Fully compliant" is earned.There is no setting anywhere in the product that lets a customer declare it.
5 AUG 2026Pre-release
Added Pre-release

Journey recorder for authenticated flows

Checkout, account and quote flows are recorded in your own tester’s browser. axe runs inside their session and results are stripped in the page before anything uploads — rule ids and selectors only.

  • One installer, one audit sprint. Nothing runs in the background.
Credentials never leave the browser.Form values, cookies and page HTML are stripped before upload. That constraint is why an IT department will actually allow this.
29 JUL 2026Pre-release
Added Pre-release

The coverage matrix: all fifty criteria, by the right method

Machine states are computed from scans; human criteria close through named sign-offs with method and date; a justified not-applicable is evidence too. Resolving a finding turns its cell green on the next scan automatically.

  • Living conformance report export, dated at the moment you take it.
15 JUL 2026Pre-release
Added Pre-release

Root-cause deduplication and the public failure reference

Hundreds of instances collapse into the handful of template fixes that clear them, ranked by severity against legal weight. Every detectable rule gets a permanent public page explaining the failure and the fix.

  • Marking a finding fixed moves it to verifying; only a scan resolves it.
1 JUL 2026Pre-release
Added Pre-release

Domain verification with a 72-hour grace window

Ownership is proven with a DNS TXT record and re-checked on a rolling schedule, because a verification gap would taint the evidence chain. If the record disappears, scanning continues for 72 hours while we tell you.

  • Warning, lapse and restoration are all ledger entries.
  • Certificate-transparency discovery proposes subdomains; you decide.
17 JUN 2026Pre-release
Fixed Pre-release

Duplicate findings across paginated templates

Product listings generated thousands of findings for what was one template defect. The fix became the triage engine: group by normalised selector pattern, not by page.

2 JUN 2026Pre-release
Added Pre-release

Enforcement tracker across the EU27 plus Norway

A living register of how each country actually enforces: the national instrument, the market surveillance authority, transposition status and the real enforcement route — private demand letters in Germany, injunctions in France, regulator sweeps in the Netherlands.

  • Country files with a per-regime response timeline.
  • Curated event feed rather than scraped noise.
19 MAY 2026Pre-release
Added Pre-release

Append-only ledger

Every verification, scan and decision writes an immutable entry. Nothing in the system updates or deletes one; a correction is a new entry that references the old.

6 MAY 2026Pre-release
Changed Pre-release

The 31/19 split, written down

Went through all fifty WCAG 2.1 A/AA criteria by hand and recorded which are genuinely machine-testable and which need human judgement. Thirty-one and nineteen — and that ratio became the honesty backbone of the product.

This is why we never say "fully automated".Vendors claiming full automation are describing about a third of the standard. We would rather show the other two-thirds and how they get covered.
22 APR 2026Pre-release
Added Pre-release

Crawler prototype: real browser, real rendering

A headless Chromium worker that renders pages the way a user does, rather than parsing HTML. Early runs against volunteer sites confirmed the obvious: server-rendered checks miss most of what breaks.

  • Same-host crawl with a politeness delay and a page budget.
  • axe-core injected per page against WCAG 2.1 A and AA.
14 APR 2026Pre-release
Added Pre-release

Project opened: continuous evidence, not one-off audits

First commit on a platform built around a single premise — an accessibility audit is a photograph, and the European Accessibility Act asks for a film. Everything that follows is in service of a continuously maintained evidence file.

OLDER ENTRIES ARE KEPT INDEFINITELY — A CHANGELOG YOU CAN PRUNE IS NOT A RECORD