How we work

A clear, four-step process for every accessibility audit and penetration test, with no surprises.

Our process

Four steps from first call to verified fix

  1. Scope

    A short call to understand your website, users, deadlines and the standards that apply.

    • Fixed quote with clear deliverables
    • NDA signed before we see anything confidential
    • Written authorisation and rules of engagement before any security test
  2. Test

    Automated tools find the obvious problems. Our experts find the rest by hand.

    • Accessibility: keyboard, screen readers, zoom, colour and cognitive checks
    • Security: manual testing of authentication, access control, injection and business logic
    • Testing only within the agreed scope and time window
  3. Fix

    Every finding comes with its impact, evidence and a clear fix.

    • Findings prioritised by severity and user impact
    • Code examples your developers can use straight away
    • Option for our developers to fix the issues for you
  4. Verify

    We retest every fix and give you documentation you can share.

    • Free retest included in every audit and penetration test
    • Accessibility Conformance Report (VPAT/ACR) or security report
    • Evidence for regulators, auditors and enterprise clients
Methodology

How we test

Accessibility testing

  • Screen readers: NVDA and JAWS (Windows), VoiceOver (macOS and iOS), TalkBack (Android)
  • Keyboard-only and switch navigation
  • 200% zoom, 400% reflow and text spacing
  • Colour contrast and high-contrast mode
  • Automated checks with axe, WAVE and Lighthouse

Security testing

  • OWASP Top 10, ASVS and Web Security Testing Guide
  • Burp Suite Professional and industry-standard tools
  • Manual testing of business logic and access control
  • API testing for REST and GraphQL
  • Severity scoring with CVSS
FAQ

Common questions

A typical website audit takes one to three weeks, depending on the number of pages and user journeys. We'll give you a timeline before we start.

We agree on the rules first, such as testing on a staging environment or outside business hours. We don't use destructive tests, and we only test with your explicit written authorisation.

Yes. Our remediation service works from any audit report, whoever wrote it.

No. Overlay widgets don't make a website accessible. We fix the actual code so it works with assistive technology.

Yes. We assess and remediate PDFs, including tags, reading order, headings, alternative text, tables and form fields, and validate them with PAC.

A signed authorisation, the scope (URLs, APIs and environments), test accounts for each user role, and a technical contact. We never ask for production passwords by email.

Ready to start?

Begin with a free accessibility review of your homepage, then decide what you need.