Skip to content
https://astonishing-marigold-c4563e.netlify.app

Compliance

· 23 checks — WCAG, consent & privacy, language, viewport, cookie inventory, and legal pages rolled into one auditable list.
SCORE
63
GRADE
D
FIX
3
REVIEW
4
PASS
13
INFO
3
Checks
23
13 PASS 4 REVIEW 3 FIX
F
GDPR Article 13 Disclosures
Action
0 / 8 Art. 13 categories matched in homepage body
FIX
0 / 8 Art. 13 categories matched in homepage body
Warning::
GDPR Article 13 disclosure coverage: 0 / 8 categories
Scanned the homepage body text AND the linked /privacy page for GDPR Article 13 disclosures. Matched 0 of 8 categories: . Missing: Data Protection Officer contact (where applicable), Data retention period, Data subject rights (access, erasure, rectification, etc.), Identity / contact details of the data controller, International data transfers, Legal basis for processing, Recipients of personal data, Right to lodge a complaint with a supervisory authority. Note: only the FIRST same-origin privacy-policy link is followed; deeper sub-pages (e.g. /legal/data-subject-rights) are not fetched.
Got: 0/8
D
Third-Party Trackers
Action
7 trackers detected
FIX
7 trackers detected
Info::
7 third-party trackers detected
Found 4 analytics, 1 advertising, 1 marketing, 1 tag manager, 0 session-replay, 0 heatmap trackers.
Got: 7 trackers
Warning::
1 advertising/retargeting trackers detected
Advertising trackers collect user data for ad targeting. Under GDPR, these typically require explicit consent.
Warning::
Trackers detected but no cookie policy found
This page loads 7 trackers but no cookie policy was detected. GDPR requires disclosure when using tracking cookies.
Warning::
Trackers detected but no privacy policy found
Most data protection regulations require a privacy policy when collecting user data via trackers.
B
Accessibility Statement
No accessibility statement detected
REVIEW
No accessibility statement detected
Warning::
No accessibility statement detected
Sites are increasingly expected to publish an accessibility statement. Required by EU Web Accessibility Directive 2016/2102 for public-sector bodies; recommended best practice elsewhere. Common URLs: /accessibility, /accessibility-statement, /a11y. Detection is by link URL and anchor text, in a limited set of languages, so this is an unconfirmed absence.
C
Compliance Badges
Action
0 compliance badge(s) detected
REVIEW
0 compliance badge(s) detected
Info::
No compliance badges detected
No recognized compliance certification badges or seals were found. This is common — many sites do not display compliance badges.
SOC 2
ISO 27001
PCI DSS
GDPR Certified
HIPAA Compliant
Better Business Bureau
TRUSTe / TrustArc
Privacy Shield
McAfee SECURE / TrustedSite
Norton Secured
Badge detection is based on image alt text, link URLs, and page content. Detection does not verify that certifications are current or valid.
A+
WCAG Compliance
No testable criteria
PASS
No testable criteria
Level A
Level AA

0

Passed

0

Failed

0

Partial

0

Manual review

0

Not tested

Key accessibility barriers

Form controls without labels

Assistive technology cannot identify 1 input(s)

Screen reader and voice-control users

Automated testing covers ~30–40% of WCAG criteria. Manual review is recommended for full conformance.

Full WCAG 2.1 AA compliance checklist — paste into a client deliverable or ticket

A+
Tracker Inventory
4 known tracker(s) detected
PASS
4 known tracker(s) detected
Info::
4 known tracker(s) detected
Inventory of trackers loaded by the page (matched against a curated SDK URL registry): tag-manager: Google Tag Manager, Segment | analytics: Google Analytics 4, Amplitude Each entry maps a script URL pattern to a known vendor SDK. This is purely informational -- consent posture / pre-consent firing is graded by the consent analyzer.
A
Language & i18n
Lang attribute present
PASS
Lang attribute present
Info::
<html lang> attribute is present
Info::
<html lang> value is valid
Info::
No Content-Language HTTP header
Info::
Language signals are inconsistent
The <html lang> attribute and Content-Language header should agree.
Page Language DetectedContent-Language Header ——Consistent No—

The <html lang> attribute and Content-Language header should agree.

Why this matters

<html lang>, Content-Language, or og:locale disagree — pick one source of truth and align the others.

Learn more ▾

Browsers and assistive tech use different sources for language. When they disagree, behavior is undefined: some pronounce by <html lang>, some by Content-Language. Decide on the canonical language for the page and set all signals to match.

Source: WCAG 2.1 SC 3.1.1

A+
Hreflang Configuration
No hreflang tags on this page
PASS
No hreflang tags on this page
Info::
No hreflang tags found (single-language site)
A+
Internationalization Extras
No additional i18n signals detected
PASS
No additional i18n signals detected
Info::
No additional i18n signals detected
A+
Readability & Typography
Font sizes and tap targets checked
PASS
Font sizes and tap targets checked
A+
Viewport Configuration
Viewport properly configured
PASS
Viewport properly configured
Info::
Viewport meta tag is present
Info::
width=device-width is set
Info::
User zooming is allowed
Viewport Configuration Good
Content
width=device-width, initial-scale=1
width=device-width

Responsive layout enabled

initial-scale=1

Correct initial zoom level

User zooming allowed

Accessibility-friendly — users can zoom

A+
Tracking Pixel Inventory
No image data to inspect for tracking pixels
PASS
No image data to inspect for tracking pixels
Info::
No image data to inspect for tracking pixels
A+
Browser Fingerprinting
No browser-fingerprinting libraries detected
PASS
No browser-fingerprinting libraries detected
Info::
No browser-fingerprinting libraries detected
A+
Cross-Site Cookies (SameSite=None)
No cookies on the page
PASS
No cookies on the page
Info::
No cookies set on the page response
A+
Beacon Tracking (sendBeacon)
No navigator.sendBeacon usage detected in inline scripts
PASS
No navigator.sendBeacon usage detected in inline scripts
Info::
No navigator.sendBeacon usage detected in inline scripts
Regulatory Indicators
1 regulatory indicator(s) detected
INFO
1 regulatory indicator(s) detected
Info::
This is a technical scan, not a legal assessment
BeaverCheck detects technical indicators that may suggest regulatory relevance. This is not a compliance audit and should not be relied upon for legal decisions. Consult qualified legal counsel for compliance assessments.
Info::
PCI-DSS indicators detected (moderate confidence)
Indicators suggesting PCI-DSS may be relevant: Payment processor detected: js.stripe.com. Payment Card Industry Data Security Standard — applies to organizations handling credit card data.
Got: 1 indicators: Payment processor detected: js.stripe.com

This is a technical scan, not a legal assessment.

BeaverCheck detects technical indicators that may suggest regulatory relevance. This should not be relied upon for legal decisions. Consult qualified legal counsel.

PCI-DSS Moderate

Payment Card Industry Data Security Standard — applies to organizations handling credit card data.

Indicators detected

  • Payment processor detected: js.stripe.com
Third-Party Data Sharing
7 third-party service(s) detected
INFO
7 third-party service(s) detected
Info::
Data inventory for transparency purposes
This inventory identifies third-party services that receive data from your site visitors. Under regulations like GDPR (Article 30), maintaining records of data processing activities is commonly considered a best practice. This automated scan provides a starting point — it may not capture all data flows.
Info::
7 third-party services across 5 categories
7 third-party services detected across 5 categories: Analytics (3), Tag Management (1), Payment (1), Marketing (1), Security (1). Each of these services receives some user data from your site visitors.
Info::
Google Analytics (Analytics)
Detected via script URL. Typically collects: Page views, User behavior, Demographics, Device info, IP address. Privacy policy: https://policies.google.com/privacy. Data Processing Agreement available.
Got: Category: Analytics | Data types: Page views, User behavior, Demographics, Device info, IP address
Info::
Google Tag Manager (Tag Management)
Detected via script URL. Typically collects: Orchestrates other tracking scripts, Page views. Privacy policy: https://policies.google.com/privacy. Data Processing Agreement available.
Got: Category: Tag Management | Data types: Orchestrates other tracking scripts, Page views
Info::
Stripe (Payment)
Detected via script URL. Typically collects: Payment card data (PCI-scoped), Transaction details. Privacy policy: https://stripe.com/privacy. Data Processing Agreement available.
Got: Category: Payment | Data types: Payment card data (PCI-scoped), Transaction details
Info::
Segment (Analytics)
Detected via script URL. Typically collects: User events, Identity resolution, Data routing. Privacy policy: https://segment.com/legal/privacy/. Data Processing Agreement available.
Got: Category: Analytics | Data types: User events, Identity resolution, Data routing
Info::
HubSpot (Marketing)
Detected via script URL. Typically collects: Lead tracking, Form submissions, Page views, Email tracking. Privacy policy: https://legal.hubspot.com/privacy-policy. Data Processing Agreement available.
Got: Category: Marketing | Data types: Lead tracking, Form submissions, Page views, Email tracking
Info::
Amplitude (Analytics)
Detected via script URL. Typically collects: User events, Behavior analytics, Cohort analysis. Privacy policy: https://amplitude.com/privacy. Data Processing Agreement available.
Got: Category: Analytics | Data types: User events, Behavior analytics, Cohort analysis
Info::
reCAPTCHA (Security)
Detected via script URL. Typically collects: Browser behavior, Device info, IP address. Privacy policy: https://policies.google.com/privacy. Data Processing Agreement available.
Got: Category: Security | Data types: Browser behavior, Device info, IP address
Analytics (3)
Tag Management (1)
Payment (1)
Marketing (1)
Security (1)
Google Analytics Analytics
Detected by: script URL
Data typically collected:
Page viewsUser behaviorDemographicsDevice infoIP address
Privacy policy → DPA available ✓
Google Tag Manager Tag Management
Detected by: script URL
Data typically collected:
Orchestrates other tracking scriptsPage views
Privacy policy → DPA available ✓
Stripe Payment
Detected by: script URL
Data typically collected:
Payment card data (PCI-scoped)Transaction details
Privacy policy → DPA available ✓
Segment Analytics
Detected by: script URL
Data typically collected:
User eventsIdentity resolutionData routing
Privacy policy → DPA available ✓
HubSpot Marketing
Detected by: script URL
Data typically collected:
Lead trackingForm submissionsPage viewsEmail tracking
Privacy policy → DPA available ✓
Amplitude Analytics
Detected by: script URL
Data typically collected:
User eventsBehavior analyticsCohort analysis
Privacy policy → DPA available ✓
reCAPTCHA Security
Detected by: script URL
Data typically collected:
Browser behaviorDevice infoIP address
Privacy policy → DPA available ✓

This inventory identifies services receiving visitor data.

Under regulations like GDPR Article 30, maintaining records of data processing is commonly considered a best practice. This scan provides a starting point.

Readability Scores
39 words, Flesch-Kincaid grade 6.4
INFO

Readability Analysis (Flesch-Kincaid)

Grade Level

6.4

Grade 6

Reading Ease

72

Fairly Easy

Words

39

Sentences

3

All checks on this page are automated. Results are estimates - run targeted manual reviews when the score affects a release decision.

Send Feedback