DIRECTIVE (EU) 2019/882 · IN FORCE SINCE 28 JUNE 2025 EU-HOSTED · GDPR-CLEAN
EAA Compliance

The platform

Everything the evidence file contains.

Three evidence sources fill one coverage matrix, every event lands on one append-only ledger, and the exports are the documents regulators and procurement actually ask for. This page is the full inventory — what each plan includes is on the pricing page.

3 evidence sources — crawler, journeys, human audits 50 / 50 WCAG 2.1 AA criteria covered & evidenced 1 append-only ledger behind every export
Source AServer-side crawler

Every public page, on schedule

Source BJourney extension

Authenticated flows, recorded

Source CGuided manual audits

Human judgement, signed off

ConsolidatedCoverage matrix

50 criteria, one state each

RecordedEvidence ledger

Append-only, timestamped

ExportedYour paperwork

Conformance report · statement · regulator pack

The whole platform in one line: sources fill the matrix, the matrix and every event feed the ledger, the ledger backs the exports.

01SOURCE A

Continuous monitoring

The server-side crawler.

Included from Free · full schedules from Growth

A headless browser renders every page on every domain and subdomain you’ve verified, runs 90+ automated WCAG 2.1 AA checks against the live DOM, and files the findings — on a monthly, weekly or daily schedule, or triggered by your deploys on the top tier.

Findings are deduplicated to template-level root causes: sixty-one contrast failures across a shop are usually one broken template, so your developers get one fix, not sixty-one tickets. Subdomains are discovered automatically from certificate-transparency logs, so the staging site nobody mentioned still gets scanned.

Scanning infrastructure is EU-located. The crawler covers the machine-checkable share of WCAG — roughly a third to half of the criteria — and the matrix says exactly which.

Crawler — specification
Engine
Headless browser + axe-core
Checks
90+ automated rules → WCAG 2.1 AA
Schedules
Monthly · weekly · daily · per-deploy
Scope
Unlimited domains & subdomains within capacity
Discovery
CT-log subdomain detection
Dedupe
Template-level root causes
Residency
EU-located scanning
02SOURCE B

Authenticated coverage

The journey extension.

Included from Scale

Enforcement looks at checkout, login and account flows — pages a crawler can’t reach. The journey extension is a Chrome extension installed by one authorized developer or QA tester during a designated audit sprint, never rolled out company-wide. They click Record and walk your real flows in their own browser; accessibility checks run against the live DOM at every step — modals, dropdowns, cart states included.

Credentials never leave their browser. No test logins are shared with us, ever. Before anything uploads, page snippets are stripped to selectors and rule IDs with configurable redaction — which is what makes the DPA signable. Payloads are only accepted for a verified domain under your organization’s key.

Journey — specification
Form
Chrome extension (Manifest V3)
Installer
One authorized dev/QA per audit sprint
Credentials
Never leave the tester’s browser
Payloads
Selectors + rule IDs, redaction configurable
Gating
Verified domain + organization key
Covers
Checkout · login · account · flows behind auth
03SOURCE C

Human judgement, structured

Guided manual audits.

Included from Growth

Some criteria no machine can judge: whether keyboard focus is ever trapped, whether the focus order makes sense, whether a screen reader announces something a person can actually act on. For each of these, the platform provides a structured checklist — what to test, how, and what pass looks like — so a competent person can verify it without being a WCAG scholar.

Each completed check is signed off by name into the ledger: who verified it, when, against which checklist version. That named entry is what turns “we looked at it” into evidence.

Sign-off — as it lands in the ledger
  1. human.verified2.1.2 No Keyboard Trap — M. Keller (QA), checklist EAA-M4
  2. human.verified2.4.3 Focus Order — M. Keller (QA), checklist EAA-M7
  3. review.due1.2.2 Captions — re-verification window opened
04CONSOLIDATED

The coverage doctrine

The coverage matrix & conformance report.

Included from Growth

Per domain, every one of the 50 WCAG 2.1 AA success criteria holds exactly one state: auto-pass · auto-fail · needs-human · human-verified (who, when) · not-applicable. The headline metric is criteria covered — and the target is all fifty, each by the right method.

The matrix exports as a continuously maintained conformance report (EN 301 549 aligned) — the document EU procurement teams and regulators actually request. It regenerates as evidence changes, so it is never a stale PDF from last year’s audit.

Matrix — one state per criterion
auto-pass
Machine-verified passing, every scan
auto-fail
Machine-verified failing → triage
needs-human
Awaiting journey or guided audit
human-verified
Signed off — who, when, checklist
not-applicable
Documented as N/A with reason
Why we will never say “fully automated” A vendor that marketed “30% compliant immediately, AI closes the rest” is under a $1M FTC order (final April 2025) barring exactly that claim. We state the automation limit openly — and cover all fifty criteria anyway, each by the right method.
05INTEGRITY

Verified monitoring

Domain verification — with a grace period on the record.

All plans

Nothing enters monitoring unverified. Every root domain is verified by DNS TXT record (meta-tag and file-upload fallbacks) at the moment it is added, covering all its subdomains, and re-checked periodically — because a verification gap would taint the evidence chain.

If the TXT record vanishes — a DNS migration, an overzealous cleanup — monitoring doesn’t silently break. A 72-hour grace period starts: the ledger logs a warning, you’re notified by email and dashboard banner, and scanning continues for three days. Only then does it hard-pause. Every step is logged, never hidden — the ledger tells the honest, dated story, which is exactly what keeps it defensible.

The 72-hour grace flow
  1. T+0Verification WarningTXT record missing — logged, email + banner sent, scans continue
  2. T+0 → T+72hGrace periodMonitoring continues; evidence continuity preserved
  3. T+72hVerification LapsedUnrestored — scans hard-pause, entry logged
  4. On fixVerification RestoredTXT re-detected — monitoring resumes, entry logged
06TRIAGE

From findings to fixes

The triage engine & the rules reference.

Fix lists from Free · full triage from Growth

Raw scanner output is noise; triage makes it a work plan. Findings are collapsed to template-level root causes, then ranked by severity × legal weight — what actually blocks a user and what enforcement actually cites — so the fix list starts with the changes that matter.

Every detectable violation links to a permanent page in the public rules reference: what the rule means, who it affects, how to fix it, with code. Your developers get explanations, not just error codes — and the reference is public, so it’s citable in your remediation correspondence.

Triage — one root cause, not 61 tickets
Raw findings
61 × contrast failures (1.4.3)
Root cause
1 × product-card template, muted price color
Rank
Severity: serious · Legal weight: high
Fix
1 CSS change, guidance with code
Result
61 findings resolved in the next scan
07RECORD

The evidence layer

The append-only ledger & the exports.

Ledger on all plans · exports from Growth

Every scan, recorded journey, human sign-off and verification event lands in a timestamped, append-only ledger — including the awkward entries. A record that only tells the good story wouldn’t be evidence.

From the ledger, three exports: the conformance report (EN 301 549, continuously maintained), the accessibility statement generator (the statement the law requires you to publish, kept consistent with your actual evidence), and the regulator response pack — a dated PDF dossier assembled for the day a demand letter or information request arrives.

Ledger — newest first
  1. scan.completed1,412 pages · 0 new critical · 3 resolved
  2. human.verified2.4.3 Focus Order — M. Keller (QA)
  3. journey.recordedCheckout — 14 steps, 2 findings
  4. verify.restoredDNS TXT re-detected
  5. verify.warningTXT missing — 72 h grace started
08INTEGRATE

API & integrations

Pull it all into your own systems.

Included from Scale

Everything the dashboard shows, the API serves: scans, violations, the coverage matrix, the evidence ledger, compliance status, tracker data. Keys are per-organization, rate limits per plan, and outbound webhooks push events as they happen.

Three uses we designed for: CI gates — fail a deploy when new critical violations appear; agency dashboards — embed each client’s live status in your own portal; GRC pulls — feed the evidence ledger into the compliance tooling your auditors already live in. Full reference arrives with the public API.

Endpoints & events — excerpt
GET /api/v1/scans GET /api/v1/violations GET /api/v1/coverage GET /api/v1/ledger GET /api/v1/status
webhook scan.completed webhook violation.new webhook coverage.changed webhook verify.warning

Per-org keys · per-plan rate limits · JSON throughout.

For web agencies

One workspace. Every client site. Your brand on the reports.

Multi-site rollups, white-label reporting, and the Client Reseller Kit — a retainer template and the margin math for reselling monitoring per client while the platform carries the evidence work.

Ready to open a file?

Plans are metered by scan capacity — unlimited domains within it, never per scan.