Accessibility & Compliance

Held to a higher bar?
It's how the platform already works.

Most WordPress sites just need to be fast, secure, and online. Some carry an extra duty — accessibility law, security requirements, procurement standards. Wordimatic is built so that when your work is held to a higher bar, meeting it isn't a separate project you bolt on later.

Straight talk

Everything on this page is something you can put in front of your review board — including the parts where we tell you exactly where we are.

WCAG 2.1 AA / Section 508

Accessibility as a first-class part of the build.

Public-sector, education, and many private-sector sites are legally required to be usable by everyone. We treat that as part of the work, not a footnote.

Built toward the standard

Sites are built and maintained toward WCAG 2.1 AA and Section 508 — the same standards your work is measured against.

Checked on a schedule, not once a year

Every hosted site is scanned automatically on a recurring monthly schedule, whether or not anyone remembers to ask. Checks also run as a review gate on deliverables before they're approved, and on demand from your dashboard. If a score drops or new violations appear, we tell you — so issues surface while the work is still in hand, not in an annual audit you file and forget.

A real engineer remediates

When something needs fixing, an engineer does the remediation and explains what changed — no ticket queue, no automated hand-wave.

Accessibility earns its keep on every other site we run too: better reach, better SEO, and lower legal risk under the ADA. That's why the scheduled check is included on every hosted plan from Maintain up, not sold as an add-on. (Connected sites — ones we monitor but don't host — can be scanned on demand from the dashboard, but aren't put on the monthly schedule.)

Security & change control

An immutable, change-controlled platform.

The posture that makes a site defensible under a compliance regime is the same posture that keeps every site from getting hacked.

Immutable, signed builds

Site software is assembled from a signed catalog and hydrated read-only at runtime — no arbitrary, unsigned, or mutable code on production.

Maps to NIST 800-53 CM-3 / CM-5 / CM-7 / CM-11, SI-7, SA-12.

Change control on every deploy

Core, theme, and plugin updates are reviewed and staged before production, with an approval gate and an audit-logged trail of who changed what, when.

Least-privilege access

Least-privilege access and audit logging across both the hosting platform and the dashboard — access is scoped, and every action leaves a trail.

Vulnerability management: we ingest the public CVE record daily — the CVE List, the National Vulnerability Database, and CISA's Known Exploited Vulnerabilities catalog — and match it against the plugin, theme, and core inventory each site actually runs, opening a reviewed change request when an affected component is found. Separately, every container image is scanned against known CVE databases on build with a full software bill of materials (SBOM) per release, so "are we affected?" is a lookup, not an investigation. We're precise about the boundary: a CVE feed can only cover software with a public identity, so bespoke code carries no advisory and is covered by our integrity monitoring instead.

Authorizations

You will never be blindsided in a procurement review.

Our control mapping is written to drop straight into a security questionnaire, and we're precise about what is mapped versus what is certified. Vendors who blur that line cost their customers a re-procurement. We won't do that to you.

Today

Aligned to NIST 800-53 Moderate with a documented control mapping; accessibility toward WCAG 2.1 AA / Section 508.

As we grow

SOC 2 Type II as our first third-party attestation.

When the work requires it

StateRAMP authorization for public-sector cloud — which reuses the same NIST 800-53 basis, so nothing built now is wasted.

We will never tell you we're FedRAMP or StateRAMP authorized when we aren't. If your procurement needs an authorization we don't hold yet, you'll hear it from us in the first conversation — not from your reviewer in the last one.

For agencies serving regulated clients

The platform layer that carries the weight.

If you're an agency delivering sites into government, education, or other regulated spaces, Wordimatic carries the accessibility and compliance weight so you don't have to build and defend it yourself.

You keep the client relationship and white-label the platform; we keep the sites accessible, hardened, and audit-ready underneath. See the Partner tier on our pricing page.

Wordimatic platform
Talk to us

Held to a standard we should build to?

Tell us your requirements and a real engineer will walk through them with you — including the parts we haven't authorized yet.