Accessibility & security
Compliant, hardened, and provably so.
The European Accessibility Act is no longer a deadline - it is the operating condition. I audit against WCAG 2.2 AA, fix what fails, harden what is exposed, and hand you documentation a regulator, a procurement officer and your own developer can all act on.
The conformance level audited against - every success criterion checked by hand, not just by a scanner.
EAA obligations apply now for most services sold in the EU. Enforcement is complaint-driven - one email starts it.
Typical path from first audit to remediated site with a published accessibility statement.
Two tracks, one report
WCAG audit & remediation
Manual and automated review of your real user journeys - keyboard, screen reader, contrast, forms, focus. Findings arrive as a prioritised backlog with the fix written next to each failure. I can implement the fixes or hand the backlog to your team.
- Full WCAG 2.2 AA audit, manual + automated
- Remediation, retest, and evidence file
- Accessibility statement, HR and EN
Hardening & watch
A review of your external surface - server configuration, TLS, headers, CMS and plugin exposure, backup integrity - followed by the fixes and an ongoing watch: patches applied, backups tested, incidents reported in plain language.
- Surface + configuration review, OWASP-aligned
- Hardening, WAF rules, patch routine
- Monitored backups with restore drills
What lands on your desk
-
Audit report
Every failure mapped to its WCAG success criterion, with severity, affected journeys, and the concrete fix.
-
Accessibility statement
The public document the EAA expects you to publish - in Croatian and English, kept current after each retest.
-
Security posture report
What is exposed, what was hardened, what remains accepted risk - signed and dated for your records.
-
Monthly watch note
Patches applied, uptime, backup drill results, and anything that needs a decision from you. One page.
Accessibility and security fail the same way
Quietly, and at the worst moment. Both are properties of the build, not features you bolt on - which is why the person who audits them should be someone who builds.
For e-commerce
Checkout is where accessibility failures cost money and where attackers aim. Both tracks start there.
For public sector & EU-funded
Conformance documentation shaped for procurement files and project audits, not just for developers.
For agencies
White-label audits and remediation backlogs your team ships under your own name. Quiet subcontracting is normal here.