Skip to content
https://pendo.io

Compliance

· 13 checks — WCAG, consent & privacy, language, viewport, cookie inventory, and legal pages rolled into one auditable list.
SCORE
82
GRADE
B
FIX
0
REVIEW
4
PASS
6
INFO
3
Checks
13
6 PASS 4 REVIEW
C
Third-Party Trackers
Action
5 trackers detected
REVIEW
5 trackers detected
Info::
5 third-party trackers detected
Found 4 analytics, 0 advertising, 0 marketing, 1 tag manager trackers.
Got: 5 trackers
Warning::
Trackers detected but no cookie policy found
This page loads 5 trackers but no cookie policy was detected. GDPR requires disclosure when using tracking cookies.
Warning::
Trackers detected but no privacy policy found
Most data protection regulations require a privacy policy when collecting user data via trackers.
A+
WCAG Compliance
No testable criteria
PASS
No testable criteria
Level A
Level AA

0

Passed

0

Failed

0

Partial

0

Manual review

0

Not tested

Key accessibility barriers

Links with unclear purpose

50 link(s) have empty or generic text

Screen reader users navigating by link list

Automated testing covers ~30–40% of WCAG criteria. Manual review is recommended for full conformance.

Full WCAG 2.1 AA compliance checklist — paste into a client deliverable or ticket

A
Language & i18n
Lang attribute present
PASS
Lang attribute present
Info::
<html lang> attribute is present
Info::
<html lang> value is valid
Info::
No Content-Language HTTP header
Info::
Language signals are inconsistent
The <html lang> attribute and Content-Language header should agree.
Page Language DetectedContent-Language Header Consistent No

The <html lang> attribute and Content-Language header should agree.

Why this matters

<html lang>, Content-Language, or og:locale disagree — pick one source of truth and align the others.

Learn more

Browsers and assistive tech use different sources for language. When they disagree, behavior is undefined: some pronounce by <html lang>, some by Content-Language. Decide on the canonical language for the page and set all signals to match.

Source: WCAG 2.1 SC 3.1.1

A+
Readability & Typography
Font sizes and tap targets checked
PASS
Font sizes and tap targets checked
A+
Viewport Configuration
Viewport properly configured
PASS
Viewport properly configured
Info::
Viewport meta tag is present
Info::
width=device-width is set
Info::
User zooming is allowed
Viewport Configuration Good
Content
width=device-width, initial-scale=1
width=device-width

Responsive layout enabled

initial-scale=1

Correct initial zoom level

User zooming allowed

Accessibility-friendly — users can zoom

A
Compliance Badges
4 compliance badge(s) detected
PASS
4 compliance badge(s) detected
Info::
SOC 2 badge detected
Found via body text: 'soc2'. Note: the presence of a badge does not verify the certification is current or valid.
Got: Detected by: body text
Info::
PCI DSS badge detected
Found via body text: 'pci dss'. Note: the presence of a badge does not verify the certification is current or valid.
Got: Detected by: body text
Info::
GDPR Certified badge detected
Found via body text: 'gdpr compliant'. Note: the presence of a badge does not verify the certification is current or valid.
Got: Detected by: body text
Info::
HIPAA Compliant badge detected
Found via body text: 'hipaa compliant'. Note: the presence of a badge does not verify the certification is current or valid.
Got: Detected by: body text
SOC 2 detected

Detected by: body text

Evidence: soc2

ISO 27001
PCI DSS detected

Detected by: body text

Evidence: pci dss

GDPR Certified detected

Detected by: body text

Evidence: gdpr compliant

HIPAA Compliant detected

Detected by: body text

Evidence: hipaa compliant

Better Business Bureau
TRUSTe / TrustArc
Privacy Shield
McAfee SECURE / TrustedSite
Norton Secured
Badge detection is based on image alt text, link URLs, and page content. Detection does not verify that certifications are current or valid.
Regulatory Indicators
4 regulatory indicator(s) detected
INFO
4 regulatory indicator(s) detected
Info::
This is a technical scan, not a legal assessment
BeaverCheck detects technical indicators that may suggest regulatory relevance. This is not a compliance audit and should not be relied upon for legal decisions. Consult qualified legal counsel for compliance assessments.
Info::
GDPR indicators detected (strong confidence)
Indicators suggesting GDPR may be relevant: Consent management platform detected: cookielaw.org; Text mentions: gdpr; Privacy policy page found. EU General Data Protection Regulation — governs collection and processing of personal data of EU residents.
Got: 3 indicators: Consent management platform detected: cookielaw.org, Text mentions: gdpr, Privacy policy page found
Info::
CCPA indicators detected (strong confidence)
Indicators suggesting CCPA may be relevant: Text mentions: do not sell; Link text: Do Not Sell or Share My Personal Information. California Consumer Privacy Act — gives California residents rights over their personal data.
Got: 2 indicators: Text mentions: do not sell, Link text: Do Not Sell or Share My Personal Information
Info::
PCI-DSS indicators detected (weak confidence)
Indicators suggesting PCI-DSS may be relevant: Text mentions: pci dss. Payment Card Industry Data Security Standard — applies to organizations handling credit card data.
Got: 1 indicators: Text mentions: pci dss
Info::
HIPAA indicators detected (weak confidence)
Indicators suggesting HIPAA may be relevant: Text mentions: hipaa. Health Insurance Portability and Accountability Act — protects sensitive patient health information.
Got: 1 indicators: Text mentions: hipaa

This is a technical scan, not a legal assessment.

BeaverCheck detects technical indicators that may suggest regulatory relevance. This should not be relied upon for legal decisions. Consult qualified legal counsel.

GDPR Strong

EU General Data Protection Regulation — governs collection and processing of personal data of EU residents.

Indicators detected

  • Consent management platform detected: cookielaw.org
  • Text mentions: gdpr
  • Privacy policy page found
CCPA Strong

California Consumer Privacy Act — gives California residents rights over their personal data.

Indicators detected

  • Text mentions: do not sell
  • Link text: Do Not Sell or Share My Personal Information
PCI-DSS Weak

Payment Card Industry Data Security Standard — applies to organizations handling credit card data.

Indicators detected

  • Text mentions: pci dss
HIPAA Weak

Health Insurance Portability and Accountability Act — protects sensitive patient health information.

Indicators detected

  • Text mentions: hipaa
Third-Party Data Sharing
0 third-party service(s) detected
INFO
0 third-party service(s) detected
Info::
Data inventory for transparency purposes
This inventory identifies third-party services that receive data from your site visitors. Under regulations like GDPR (Article 30), maintaining records of data processing activities is commonly considered a best practice. This automated scan provides a starting point — it may not capture all data flows.
Info::
No recognized third-party data-sharing services detected
This page does not appear to load external tracking, analytics, or advertising scripts.

No recognized data-sharing services detected.

This inventory identifies services receiving visitor data.

Under regulations like GDPR Article 30, maintaining records of data processing is commonly considered a best practice. This scan provides a starting point.

Readability Scores
1573 words, Flesch-Kincaid grade 10.2
INFO

Readability Analysis (Flesch-Kincaid)

Grade Level

10.2

Grade 10 (high school)

Reading Ease

45

Difficult

Words

1573

Sentences

122

All checks on this page are automated. Results are estimates - run targeted manual reviews when the score affects a release decision.

Send Feedback