Skip to content

Trust

Accuracy and liability, in plain words

You are about to rely on software for something with consequences. Here is exactly what we stand behind, where we stop, and what happens when we are wrong — before you pay, and in the language you would use rather than the language a contract uses.

What we stand behind

The scan reports what it found
A WCAG result lists the failures the checks actually detected on the page we fetched, at the time we fetched it, with the element and the rule behind each one. We do not pad a result to look thorough, and we do not withhold one to look clean — including on our own site, which we scan with the same scanner.
Every report is signed and checkable
Reports are signed with Ed25519 and carry their own hash and verification link. Anyone you hand one to can confirm, without an account, that it came from us and has not been altered since. That is a fact about the document, and it is checkable in seconds.
Registry entries carry the date they were verified
Each jurisdiction entry says when it was last checked against its primary sources, and the method and the dates are published.
We fix what we get wrong, and we date the fix
Tell us an entry is wrong and send the source. We correct it, move its verification date, and it appears in the changelog. We reply within 4 working days.

Where we stop

Said once, plainly. A tool that overstates itself is worse than one that is honest about its edges, because you would plan around the overstatement.

An automated scan cannot find every accessibility barrier
Roughly a third of WCAG success criteria can be evaluated by machine at all; the rest need a person, often a person using a screen reader. Every result page says so on the result page, not in a footnote. A clean automated scan means the machine-testable failures are gone — it is not a statement that your site is accessible to everyone.
A registry entry is not legal advice
It records what we verified and when. Whether an instrument applies to your business, and what it requires of you specifically, is a legal question. We are not a law firm, we do not have an attorney-client relationship with you, and nothing we produce is a substitute for counsel who has read your facts.
We do not certify anybody
A CMMC certification assessment is performed by an accredited third party. We are not a C3PAO. What we produce is the readiness work that comes before one.
Documents are drafted from what you tell us
A policy, an SSP or a DPIA generated here reflects the answers you gave. If an answer is wrong, the document is wrong. They are drafts for your review and your counsel’s signature, not filings.

If something we produced was wrong

Tell us. We will correct it, date the correction, and say what changed. If a mistake of ours cost you money on your subscription — a duplicate charge, a billing error on our side — we put that right too; the Refund Policy says how.

What we cannot do is carry your legal risk. The Terms of Service set the limit of our liability, in the way every software contract does, and they are the binding text — this page explains them, it does not replace them. The practical answer is the one above: use the citations, keep the dated records, and have counsel read anything that decides something important.