How we audit
Every claim in our reports traces to either a deterministic check or a named human reviewer. Nothing in between.
Deterministic, and proud of it
No AI produces our findings. Our audit pipeline is deterministic software: audit the same site twice against the same pinned ruleset, get the same report — down to the byte. That means re-audits measure your progress, disputes resolve by re-running instead of arguing, and every verdict in the report traces to a documented rule.
Honest about automation
Most of WCAG cannot be checked by software — anyone who says otherwise is counting generously. Our public WCAG 2.2 Coverage Map classifies all 86 success criteria: which ones our tooling checks deterministically (about a quarter, counted strictly), which ones get human review, and where the industry's bigger numbers come from. We also built our own checks for criteria that off-the-shelf scanners skip entirely — reflow at mobile widths, text-spacing tolerance, and minimum target sizes.
Verifiable end to end
Every scan, every triage decision, every generated artifact is written to a hash-chained audit log — tamper-evident, like a ledger. Your engagement bundle ships with it, and one command verifies the chain. Your compliance team can check our work without trusting our word.
Respectful capture
Our crawler renders pages in a real browser (so single-page apps are audited as users experience them), honors robots.txt, rate-limits itself, and identifies honestly as BSTA11yBot. Anything we couldn't reach is disclosed as a coverage gap — never quietly skipped.
Built for healthcare remediation
For AAA-track engagements, every gap is attributed to the team that owns the fix — design system, content, or application architecture — so the roadmap you hand your teams is assignments, not homework.