What it looks like
A letter arrives from a lawyer you have never heard of.
It names your website, cites a standard you have never read, and gives you a deadline. Nothing about your business changed. Somebody ran a scanner.
Compliance engineering
Accessibility, privacy, consent, and security controls are engineered into the build, not bolted on before launch. Here is exactly what ships today, exactly what gets scoped per engagement, and where our work ends and your counsel's begins.
Four frameworks ship by default · two are scoped, with the precondition stated before any work starts
Why anyone reads a page like this
Not a badge, and not a maybe.
What it looks like
It names your website, cites a standard you have never read, and gives you a deadline. Nothing about your business changed. Somebody ran a scanner.
What it feels like
You would like one honest answer about where you stand. What you get is a vendor selling a badge and an attorney explaining that it depends.
Why that is not on you
You bought a cookie banner and reasonably assumed it blocked something. It was drawn over trackers that had already fired.
At a glance
Every competitor claims all six. Here is the honest split, before you read a single control.
Running on live client sites right now. Ships by default, on every build, at no extra line item.
ADA / WCAG · GDPR · California / US states · Cookie consent / GPC
We build to the controls the framework calls for. The framework itself carries a precondition we state up front, before any work starts.
SOC 2 · HIPAA
Framework by framework
Each panel names the mechanisms, the receipts, and for the two scoped frameworks, the precondition.
WCAG 2.1 AA is the standard the Department of Justice and the courts reference, and it is the target every build is engineered against. Accessibility is a conformance target plus an ongoing practice, so we ship the mechanisms and the public statement that documents them.
What we build
Receipts
Lighthouse 100 on accessibility across whole sites, not cherry-picked pages: 346 runs across 195 routes on one build, 173 pages on another.
The widget is code you own outright. It is the thing other studios rent to you as a monthly subscription.
3,117
Plaintiffs filed 3,117 federal website accessibility lawsuits in 2025, up 27% over 2024, and 64% of the defendants had annual revenue under $25 million.
Seyfarth Shaw and UsableNet. Calendar year 2025.
We have built GDPR-ready sites where consent is a real gate in the code, not a banner drawn over trackers that already fired. If a user has not opted in, there is no script tag, no network request, and no cookie.
What we build
Receipts
Privacy policies of 16 to 23 sections, written as typed data that matches actual code behaviour rather than a template pasted in at launch.
The claim is verifiable by anyone: open the network tab before accepting and watch nothing fire.
11 of 11
A March 2026 forensic audit of 7,634 sites found all 11 consent platforms it evaluated failed to consistently block advertising cookies after opt-out, with three Google-certified platforms failing 77%, 90% and 91% of the time.
webXray Global Privacy Audit. March 2026.
California set the pattern and 20 more states have followed, each with its own thresholds and its own opt-out mechanics. We build the rights machinery once, correctly, so a site does not need re-engineering every time another state law takes effect.
What we build
Receipts
Roughly 1,500 CIPA wiretapping suits were filed in the 18 months to August 2025, most turning on trackers a site's own privacy page did not disclose. Our privacy pages are generated from the same typed data the trackers are gated by.
The California Privacy Protection Agency issued a record $1.35 million fine against Tractor Supply in September 2025, largely over ineffective opt-out mechanisms.
12 states
As of January 1, 2026, twelve US states require businesses to honor universal opt-out preference signals, and California's AB 566 requires every browser serving California users to ship a built-in opt-out setting from January 1, 2027.
Tannenbaum Helpern and IAPP. January 2026.
A cookie banner is not consent. Consent is whether the code can prove the tracker never ran, and most banners on the web today fail that test in the network tab.
What we build
Receipts
Zero tracker bytes before consent is an architectural property of the build, which is also why these sites are fast.
No rented consent platform sits underneath any of this. It is code, written for your build, that you own the day we hand it over.
125,106
55% of 7,634 audited sites set advertising cookies after the user had opted out, depositing 125,106 advertising cookies post-opt-out, and 80% of the 242 ad-tech vendors measured ignored the Global Privacy Control signal outright.
webXray Global Privacy Audit. March 2026.
SOC 2 audits an organization, not a website, and the report is issued by your auditor. What we do is build the web layer so that when your auditor asks how a control is implemented, there is a specific answer in the code with the control number written next to it.
The precondition, stated up front
Spider Digital Group is not SOC 2 audited and holds no SOC 2 report. We build your site and platform to the controls, and document them so your auditor can trace each one. The report itself comes from your auditor, against your organization.
What we build
Receipts
A full document pack ships with the build: SECURITY-POLICY, INCIDENT-RESPONSE, RISK-REGISTER, RUNBOOK, and a subprocessor disclosure.
A security audit with SOC 2 control mapping across a 492-URL site returned 43 findings: 0 critical, 0 high.
The HIPAA Security Rule names a set of technical safeguards: access control, audit controls, integrity, authentication, and transmission security. We build those safeguards, and we have shipped them on regulated platform work.
The precondition, stated up front
A HIPAA engagement requires a signed Business Associate Agreement and HIPAA-eligible hosting. That is scoped per project, before any protected health information is involved. No protected health information flows through a standard build.
What we build
Receipts
These are not proposals. Each one is running in a regulated platform build we shipped.
The healthcare platform behind this work is a pre-sales build and stays unnamed. We do not trade on client names we have not been given permission to use.
Where our work ends
Compliance is a legal determination about an organization. A website either implements the controls a framework calls for, or it does not, and that part is engineering. We will not tell you that you are compliant, because that is not ours to say. We will show you exactly which controls are implemented, where they live in the code, and what is still open, in language your attorney and your auditor can both work from.
There is no such thing as an ADA-certified website, and a website is never SOC 2 compliant. Any studio selling you either one is selling you a badge, not a build.
Every control on this page maps to code in a build we shipped. Ask us to show you the file and we will show you the file.
The consent library, the accessibility widget, the security headers, the policy data: it is your code on your repository. Nothing here is a subscription that stops working when you stop paying us.
If a framework needs an agreement, specific hosting, or your counsel's involvement before we can start, you hear that in the first conversation, not after the invoice.
Straight answers
Including the two where the honest answer is no.
If a framework needs an agreement, specific hosting or your counsel involved before we can start, you hear it in the first conversation, not after the invoice.
Scope your requirements