← All services

Accessibility & security

Compliant, hardened, and provably so.

The European Accessibility Act is no longer a deadline - it is the operating condition. I audit against WCAG 2.2 AA, fix what fails, harden what is exposed, and hand you documentation a regulator, a procurement officer and your own developer can all act on.

Request an audit

2.2 AA

The conformance level audited against - every success criterion checked by hand, not just by a scanner.

In force

EAA obligations apply now for most services sold in the EU. Enforcement is complaint-driven - one email starts it.

~6 wks

Typical path from first audit to remediated site with a published accessibility statement.

Two tracks, one report

Track one - accessibility

WCAG audit & remediation

Manual and automated review of your real user journeys - keyboard, screen reader, contrast, forms, focus. Findings arrive as a prioritised backlog with the fix written next to each failure. I can implement the fixes or hand the backlog to your team.

  • Full WCAG 2.2 AA audit, manual + automated
  • Remediation, retest, and evidence file
  • Accessibility statement, HR and EN
Track two - security

Hardening & watch

A review of your external surface - server configuration, TLS, headers, CMS and plugin exposure, backup integrity - followed by the fixes and an ongoing watch: patches applied, backups tested, incidents reported in plain language.

  • Surface + configuration review, OWASP-aligned
  • Hardening, WAF rules, patch routine
  • Monitored backups with restore drills

What lands on your desk

  1. Audit report

    Every failure mapped to its WCAG success criterion, with severity, affected journeys, and the concrete fix.

  2. Accessibility statement

    The public document the EAA expects you to publish - in Croatian and English, kept current after each retest.

  3. Security posture report

    What is exposed, what was hardened, what remains accepted risk - signed and dated for your records.

  4. Monthly watch note

    Patches applied, uptime, backup drill results, and anything that needs a decision from you. One page.

Why it is one service

Accessibility and security fail the same way

Quietly, and at the worst moment. Both are properties of the build, not features you bolt on - which is why the person who audits them should be someone who builds.

For e-commerce

Checkout is where accessibility failures cost money and where attackers aim. Both tracks start there.

For public sector & EU-funded

Conformance documentation shaped for procurement files and project audits, not just for developers.

For agencies

White-label audits and remediation backlogs your team ships under your own name. Quiet subcontracting is normal here.

Know where you stand before someone else checks.

[email protected]