Wholisphere
Wholisphere VPAT

The compliance document procurement actually signs.

A VPAT is only worth signing if it's true. Ours reports only what the scan found — every verdict traced to its evidence, nothing derived or inferred. Open issues are disclosed, not hidden. Every approval SHA-256-hashed into a tamper-evident audit log.

Every WCAG 2.2 A + AA criterion — automated hard-fail detection

Not "conformance guaranteed" — we tell you exactly how each criterion is judged. All 55 Level A + AA criteria have automated hard-fail detection in the engine (80+ evaluators, pinned by three CI regression suites against a 196-page per-criterion testbed). 37 criteria hard-fail from static markup analysis alone; the rest use deterministic Playwright-driven browser probes (2.1.2 keyboard trap, 1.4.10 reflow at 320px, 2.4.7 focus visibility, measured flash rate for 2.3.1) or stability-verified vision and text judges (1.4.5 images-of-text, 1.4.1 use-of-color, 2.4.6 heading descriptiveness — criteria a rule-based scanner cannot evaluate). Cross-page aggregators check consistency across the page set (3.2.3 navigation, 3.2.6 help location), and an opt-in flow crawler proves 3.3.4 and 3.3.7 across multi-step checkout-style flows. All 86 criteria (AAA included) are evaluated with evidence; the 16 that still need human judgment are all Level AAA and flow through the in-VPAT Human Attestations table as confidence-scored verdicts for one-click reviewer signoff — so nothing is silently "passed."

Only what the scan found

Every row reflects the scan and nothing else — no verdict is derived, measured from an agent, or inferred. A "Does Not Support" is stated honestly and left openly disclosed until it is fixed at the source and a re-scan confirms it. Source-code remediation (a PR to your repo or a change through your CMS) is in development; the VPAT never claims a fix it can't evidence.

Attestation built for scrutiny

Every approved VPAT is hashed (SHA-256) and chained into a tamper-evident audit log. Mutating findings re-renders to a new hash; old approvals preserve the old hash. Reviewer overrides surface as a Human Attestations table on the VPAT itself — procurement reads exactly which verdicts were machine-emitted vs human-attested.

What you'd produce

Real VPAT 2.5 INT, rendered live from the same pipeline customers use. Mix of Supports / Partially Supports / Does Not Support / Not Applicable — exactly what a real scan looks like. Every row reflects only what the scan found; open issues are disclosed plainly rather than hidden.

Open the sample in a new tab →  ·  Download as markdown

Everything in the box

VPAT 2.5 INT
WCAG 2.2 (A / AA / AAA), Section 508 (Chapter 3 + E205), EN 301 549 (Annex A, Clauses 9–13). Edition picker; locked + suppressed standards enforced for semantic correctness.
CI integration
GitHub Action runs on every push or PR. Optional regression gate fails the build when WCAG conformance regresses since the previous scan.
Multi-product per org
Track marketing site + admin app + checkout flow as separate products. Each gets its own scan history, defaults, and approval roster.
Webhooks
scan.completed, scan.failed, vpat.approved, vpat.revoked — every event delivered through a signed outbox with retry + dead-letter.
Openly disclosed open issues
An issue we can't yet fix at the source is not hidden or papered over — it stays in the VPAT as a clearly disclosed open item, so the report always matches reality.
HTML / Markdown / API
Render the same structured findings as procurement-ready HTML (CMD+P → save as PDF), GitHub-renderable markdown, or JSON for your own tooling.
PDF documents in the same report
Scan with --include-pdfs and linked PDFs are graded against structural checks citing W3C PDF techniques — tagging, language, title, figure alt text, headings, tables, form labels, link text, bookmarks — plus opt-in rendered-page analysis: deterministic rendered-text contrast (measured from pixels, no model), vision-judged image-of-text detection, and a best-effort reading-order signal. Document findings aggregate into the same per-criterion VPAT rows as pages, covering the documents chapter of Section 508 and EN 301 549.

Drop a conformance badge in your README

Every product gets a shields.io endpoint URL that renders the latest scan's overall verdict — the same way GitHub shows build status. Below is the live sample-VPAT badge; the same shape ships per-product on every paid plan.

Sample WCAG conformance badge — AA, mixed verdicts
![WCAG](https://img.shields.io/endpoint?url=https://staging-api.wholisphere.ai/v1/public/sample-badge.json)

Color tracks the conforming-criterion percentage (Supports + Not Applicable / Total). Re-fetched once per day so a CI run flipping a verdict updates the badge automatically.

Compared to a consultancy VPAT

Consultancy ($5–20k one-time)Wholisphere VPAT
Time to first VPAT2–6 weeks≤ 10 minutes
Re-issue cost (next release)$5–20k againAuto-regenerated on every CI run
Real scan evidenceWord doc + screenshotsHashed evidence in tamper-evident audit log
Open issuesNarrative prose, easy to gloss overDisclosed per criterion, traceable to scan evidence
Approval signatureEmail signatureSHA-256 hash chained into audit log
CI regression gateNot possibleBuilt-in (fails build on regression)
PR comment with diffNot possibleAuto-posted on pull_request, updates in place
Editions coveredPick one upfrontINT / WCAG / 508 / EU — render any anytime
Vision-LLM-only criteria (1.4.5, 1.3.3)Not evaluated (no model)Verdict against the rendered page
Cross-page criteria (3.2.3, 3.2.6, 3.3.7)Not evaluated (single-page only)Multi-page aggregator runs after every scan
WCAG 2.2 A + AA coverageManual; 100% of the consultancy's hoursAutomated hard-fail detection for all 55 criteria — static analysis, deterministic browser probes, and stability-verified LLM judges, CI-pinned against a 196-page testbed
PDF documents (Section 508 / EN 301 549 documents chapter)Separate engagementOpt-in structural PDF checks plus rendered-page analysis (deterministic contrast, image-of-text detection, reading-order signal); document findings land in the same VPAT

Ready when procurement asks for one.

Get a working VPAT in your CI pipeline this week. Custom enterprise pricing for multi-product orgs and white-label deployments.