Stay compliant
Let someone using a screen reader, a keyboard, or one hand get a quote from you, and have the statement to prove it.
Someone using a screen reader, or a keyboard, or one hand, can still get a quote from you, and you have the statement to prove it.
Compliance engineering · proven on 3 live builds
Receipts
Numbers from live builds
- A self-built accessibility widget shipped on 14 sites, with 7 one-click profiles and 22 to 25 adjustments
- A WCAG 2.1 AA accessibility statement page live on every site we ship
- 346 Lighthouse runs across 195 routes, all 100 on accessibility
- Reduced motion honored in 10 to 38 places on a single build
What you get
What is in your hands
- A site built to WCAG 2.1 AA, with a public accessibility statement page
- An accessibility widget for user preference on top of real conformance, never as a substitute for it
- A consent layer where every tracker is gated in the render tree, verifiable in your own network tab
- Global Privacy Control honored as a binding opt-out, with withdrawal that clears cookies already set
- A privacy policy, Do Not Sell or Share link, and rights request flow generated from the build's real behaviour
- Server-side defenses annotated with the SOC 2 control each one maps to, for your auditor to trace
Before you ask
Four questions about this one
Is an accessibility widget enough?
No. We ship one because it genuinely helps people set their own preferences, and we are straight about its limits: the FTC fined an overlay vendor $1,000,000 and barred it from claiming automation makes a site WCAG-compliant. Conformance lives in the markup, and that is where we build it.
What does it mean that your consent banner actually blocks?
The tracker components return null until consent is granted, so there is no script tag, no network request and no cookie to fail. You can verify it in your own network tab. In a March 2026 audit of 7,634 sites, all 11 consent platforms tested still failed to reliably block advertising cookies after opt-out.
Can you help with our customer's SOC 2 questionnaire?
Yes, for the part that is ours. The build ships server defenses annotated with the SOC 2 control each one maps to, CC6.1 on the contact route, CC6.6 and CC6.7 on the Content Security Policy, CC7.2 on route logging, P4.1 in middleware, CC8.1 in a release runbook. The audited organization is you, not us.
What do we get on paper?
A documentation pack: security policy, incident response, risk register, runbook and subprocessor disclosure, plus a public WCAG 2.1 AA accessibility statement live on the site.
Tell us what you need
Six questions, no call required, and you get a written scope, a fixed price and a timeline.
Start the brief


