The platform
Everything the evidence file contains.
Three evidence sources fill one coverage matrix, every event lands on one append-only ledger, and the exports are the documents regulators and procurement actually ask for. This page is the full inventory — what each plan includes is on the pricing page.
Every public page, on schedule
Authenticated flows, recorded
Human judgement, signed off
50 criteria, one state each
Append-only, timestamped
Conformance report · statement · regulator pack
The whole platform in one line: sources fill the matrix, the matrix and every event feed the ledger, the ledger backs the exports.
Continuous monitoring
The server-side crawler.
Included from Free · full schedules from GrowthA headless browser renders every page on every domain and subdomain you’ve verified, runs 90+ automated WCAG 2.1 AA checks against the live DOM, and files the findings — on a monthly, weekly or daily schedule, or triggered by your deploys on the top tier.
Findings are deduplicated to template-level root causes: sixty-one contrast failures across a shop are usually one broken template, so your developers get one fix, not sixty-one tickets. Subdomains are discovered automatically from certificate-transparency logs, so the staging site nobody mentioned still gets scanned.
Scanning infrastructure is EU-located. The crawler covers the machine-checkable share of WCAG — roughly a third to half of the criteria — and the matrix says exactly which.
- Engine
- Headless browser + axe-core
- Checks
- 90+ automated rules → WCAG 2.1 AA
- Schedules
- Monthly · weekly · daily · per-deploy
- Scope
- Unlimited domains & subdomains within capacity
- Discovery
- CT-log subdomain detection
- Dedupe
- Template-level root causes
- Residency
- EU-located scanning
Authenticated coverage
The journey extension.
Included from ScaleEnforcement looks at checkout, login and account flows — pages a crawler can’t reach. The journey extension is a Chrome extension installed by one authorized developer or QA tester during a designated audit sprint, never rolled out company-wide. They click Record and walk your real flows in their own browser; accessibility checks run against the live DOM at every step — modals, dropdowns, cart states included.
Credentials never leave their browser. No test logins are shared with us, ever. Before anything uploads, page snippets are stripped to selectors and rule IDs with configurable redaction — which is what makes the DPA signable. Payloads are only accepted for a verified domain under your organization’s key.
- Form
- Chrome extension (Manifest V3)
- Installer
- One authorized dev/QA per audit sprint
- Credentials
- Never leave the tester’s browser
- Payloads
- Selectors + rule IDs, redaction configurable
- Gating
- Verified domain + organization key
- Covers
- Checkout · login · account · flows behind auth
Human judgement, structured
Guided manual audits.
Included from GrowthSome criteria no machine can judge: whether keyboard focus is ever trapped, whether the focus order makes sense, whether a screen reader announces something a person can actually act on. For each of these, the platform provides a structured checklist — what to test, how, and what pass looks like — so a competent person can verify it without being a WCAG scholar.
Each completed check is signed off by name into the ledger: who verified it, when, against which checklist version. That named entry is what turns “we looked at it” into evidence.
- human.verified2.1.2 No Keyboard Trap — M. Keller (QA), checklist EAA-M4
- human.verified2.4.3 Focus Order — M. Keller (QA), checklist EAA-M7
- review.due1.2.2 Captions — re-verification window opened
The coverage doctrine
The coverage matrix & conformance report.
Included from GrowthPer domain, every one of the 50 WCAG 2.1 AA success criteria holds exactly one state: auto-pass · auto-fail · needs-human · human-verified (who, when) · not-applicable. The headline metric is criteria covered — and the target is all fifty, each by the right method.
The matrix exports as a continuously maintained conformance report (EN 301 549 aligned) — the document EU procurement teams and regulators actually request. It regenerates as evidence changes, so it is never a stale PDF from last year’s audit.
- auto-pass
- Machine-verified passing, every scan
- auto-fail
- Machine-verified failing → triage
- needs-human
- Awaiting journey or guided audit
- human-verified
- Signed off — who, when, checklist
- not-applicable
- Documented as N/A with reason
Verified monitoring
Domain verification — with a grace period on the record.
All plansNothing enters monitoring unverified. Every root domain is verified by DNS TXT record (meta-tag and file-upload fallbacks) at the moment it is added, covering all its subdomains, and re-checked periodically — because a verification gap would taint the evidence chain.
If the TXT record vanishes — a DNS migration, an overzealous cleanup — monitoring doesn’t silently break. A 72-hour grace period starts: the ledger logs a warning, you’re notified by email and dashboard banner, and scanning continues for three days. Only then does it hard-pause. Every step is logged, never hidden — the ledger tells the honest, dated story, which is exactly what keeps it defensible.
- T+0Verification WarningTXT record missing — logged, email + banner sent, scans continue
- T+0 → T+72hGrace periodMonitoring continues; evidence continuity preserved
- T+72hVerification LapsedUnrestored — scans hard-pause, entry logged
- On fixVerification RestoredTXT re-detected — monitoring resumes, entry logged
From findings to fixes
The triage engine & the rules reference.
Fix lists from Free · full triage from GrowthRaw scanner output is noise; triage makes it a work plan. Findings are collapsed to template-level root causes, then ranked by severity × legal weight — what actually blocks a user and what enforcement actually cites — so the fix list starts with the changes that matter.
Every detectable violation links to a permanent page in the public rules reference: what the rule means, who it affects, how to fix it, with code. Your developers get explanations, not just error codes — and the reference is public, so it’s citable in your remediation correspondence.
- Raw findings
- 61 × contrast failures (1.4.3)
- Root cause
- 1 × product-card template, muted price color
- Rank
- Severity: serious · Legal weight: high
- Fix
- 1 CSS change, guidance with code
- Result
- 61 findings resolved in the next scan
The evidence layer
The append-only ledger & the exports.
Ledger on all plans · exports from GrowthEvery scan, recorded journey, human sign-off and verification event lands in a timestamped, append-only ledger — including the awkward entries. A record that only tells the good story wouldn’t be evidence.
From the ledger, three exports: the conformance report (EN 301 549, continuously maintained), the accessibility statement generator (the statement the law requires you to publish, kept consistent with your actual evidence), and the regulator response pack — a dated PDF dossier assembled for the day a demand letter or information request arrives.
- scan.completed1,412 pages · 0 new critical · 3 resolved
- human.verified2.4.3 Focus Order — M. Keller (QA)
- journey.recordedCheckout — 14 steps, 2 findings
- verify.restoredDNS TXT re-detected
- verify.warningTXT missing — 72 h grace started
API & integrations
Pull it all into your own systems.
Included from ScaleEverything the dashboard shows, the API serves: scans, violations, the coverage matrix, the evidence ledger, compliance status, tracker data. Keys are per-organization, rate limits per plan, and outbound webhooks push events as they happen.
Three uses we designed for: CI gates — fail a deploy when new critical violations appear; agency dashboards — embed each client’s live status in your own portal; GRC pulls — feed the evidence ledger into the compliance tooling your auditors already live in. Full reference arrives with the public API.
Per-org keys · per-plan rate limits · JSON throughout.
For web agencies
One workspace. Every client site. Your brand on the reports.
Multi-site rollups, white-label reporting, and the Client Reseller Kit — a retainer template and the margin math for reselling monitoring per client while the platform carries the evidence work.
Ready to open a file?
Plans are metered by scan capacity — unlimited domains within it, never per scan.