Exactly what we check
Here is the full list: every check we run, which regulation it tests against, and whether it's included in the trial or requires a paid plan. No hand-picked examples — this is the same catalog that drives the scan.
How the trial differs from a paid plan
During the trial we run almost every check, but on a sample of the site's pages and with a limited number of examples per finding — enough to show you where you stand, not a complete review.
On a paid plan the site is scanned up to your plan's page count, every finding is shown, and the deeper accessibility tests run. Those require us to interact with each page — keyboard navigation, mobile viewport, form testing — and are therefore not part of unpaid scans. The "Paid plan" column applies to every paid plan: what matters is that the module is included in your plan, not which plan you chose.
About the methods: Deterministic means the check measures a fact in the browser — it cannot be a matter of opinion. AI means our compliance AI reads and assesses text. Vision AI means the AI assesses a screenshot visually. AI assessments are always presented as assessments for you to confirm, never as established violations.
Accessibility (WCAG / EAA)55 criteria
WCAG 2.2 at levels A and AA consists of 55 criteria — the table below accounts for every one of them. Some are machine-testable: those are tested by the automated sweep on every scanned page, using around sixty rules. On a paid plan we go further than automated scanning normally can — we tab through the pages with a keyboard, reload them in a mobile viewport, test forms, and let vision AI judge what otherwise needs a human eye. A number of criteria can't be tested without human judgment in context: those the scan does not cover, and they are openly marked as manual in the table — we never claim otherwise.
Of the 55 criteria, we test 45 fully or partially automatically. The remaining 10 require human judgment — but you're not left alone with them: our AI advisor guides you through what to check, how to do it, and what passes.
Deep dives: Contrast requirements · Alt text · Keyboard & focus · Accessible PDFs · What's new in WCAG 2.2
| Criterion (WCAG 2.2) | Level | How we test | Trial | Paid plan |
|---|---|---|---|---|
| 1.1.1 Non-text content — everything that isn't text (images, icons, buttons with symbols) must have a text description, so a screen-reader user knows what the image shows. Learn more → | A | Partially automatic · sweep + interactive + PDF | ✓ | ✓ |
| 1.2.1 Audio-only / video-only — a recording with only audio (e.g. a podcast) must have a text transcript, and a video without sound a text description, so the content works for those who can't hear or see. | A | Partially automatic · interactive | — | ✓ |
| 1.2.2 Captions (prerecorded) — recorded videos with speech must have captions, so people who can't hear can follow what is said. | A | Partially automatic · sweep + interactive | ✓ | ✓ |
| 1.2.3 Audio description or media alternative — recorded videos must have a narrator describing what's on screen, or a text version of the whole content, for those who can't see the picture. | A | Partially automatic · interactive | — | ✓ |
| 1.2.4 Captions (live) — live broadcasts must have captions too, not just recorded material. | AA | Manual review | — | — |
| 1.2.5 Audio description (prerecorded) — recorded videos must have audio description: a narrator describing important things that are only visible on screen. | AA | Partially automatic · interactive | — | ✓ |
| 1.3.1 Info and relationships — what looks like a heading, list or table must also be coded as one, so screen readers understand the page's structure instead of reading one long wall of text. | A | Partially automatic · sweep + PDF + interactive | ✓ | ✓ |
| 1.3.2 Meaningful sequence — content must sit in a sensible order, so someone hearing the page read aloud gets it in the same logical order as someone seeing it. | A | Manual review | — | — |
| 1.3.3 Sensory characteristics — instructions must not assume sight, like "click the green button on the right". Someone who can't perceive colour or position must still understand what's meant. | A | Partially automatic · vision AI | — | ✓ |
| 1.3.4 Orientation — the page must work with the screen held both portrait and landscape; it must not force the user to rotate their phone or tablet. | AA | Partially automatic · sweep | ✓ | ✓ |
| 1.3.5 Identify input purpose — fields for name, email, address and so on must be marked up so the browser can fill them in automatically — a big help for anyone who struggles to type. | AA | Partially automatic · sweep + interactive | — | ✓ |
| 1.4.1 Use of colour — colour must not be the only way something is shown, e.g. only marking invalid fields in red. People who don't perceive colour need a text or symbol too. | A | Partially automatic · sweep + interactive | ✓ | ✓ |
| 1.4.2 Audio control — if sound starts automatically when the page opens, it must be possible to pause or turn off, otherwise it drowns out the screen reader's voice. | A | Partially automatic · sweep | ✓ | ✓ |
| 1.4.3 Contrast (minimum) — text must have enough contrast against its background to be readable with low vision — light grey text on a white background is the classic failure. Learn more → | AA | Automatic · sweep + vision AI | ✓ | ✓ |
| 1.4.4 Resize text — it must be possible to enlarge the text to double size without content disappearing or ending up off-screen. | AA | Partially automatic · sweep + interactive | ✓ | ✓ |
| 1.4.5 Images of text — text must be real text, not baked into an image. Text in images turns blurry when enlarged and is completely invisible to screen readers. | AA | Partially automatic · vision AI | — | ✓ |
| 1.4.10 Reflow — the page must work on a narrow screen (320 pixels, roughly a small phone) without having to scroll sideways to read. | AA | Automatic · interactive | — | ✓ |
| 1.4.11 Non-text contrast — things that aren't text — icons, input-field borders, parts of charts — must also have enough contrast to be distinguishable. Learn more → | AA | Partially automatic · interactive | — | ✓ |
| 1.4.12 Text spacing — the page must not break if the user increases line and letter spacing, which people with dyslexia or low vision often do to be able to read. | AA | Automatic · sweep + interactive | ✓ | ✓ |
| 1.4.13 Content on hover or focus — content that appears when pointing at something (tooltips, fold-out menus) must be dismissible and must not vanish when you try to move the pointer to it. | AA | Partially automatic · interactive | — | ✓ |
| 2.1.1 Keyboard — everything on the page must be usable with a keyboard alone, because many people can't use a mouse — e.g. people with motor impairments or low vision. Learn more → | A | Partially automatic · sweep + interactive | ✓ | ✓ |
| 2.1.2 No keyboard trap — someone navigating by keyboard must never get stuck in a part of the page (e.g. a popup) with no way to move on or back out. Learn more → | A | Partially automatic · interactive | — | ✓ |
| 2.1.4 Character key shortcuts — if the page has single-key shortcuts (e.g. S opens search), they must be possible to turn off or remap, otherwise voice control and stray keystrokes trigger them by accident. | A | Manual review | — | — |
| 2.2.1 Timing adjustable — if something has a time limit (e.g. being logged out, or a booking expiring), the limit must be extendable or possible to turn off — not everyone is equally fast. | A | Partially automatic · sweep | ✓ | ✓ |
| 2.2.2 Pause, stop, hide — image carousels, autoplaying videos and other moving content must be pausable. Motion breaks concentration, especially for people with ADHD or cognitive impairments. | A | Partially automatic · sweep + interactive | ✓ | ✓ |
| 2.3.1 Three flashes or below threshold — nothing on the page may flash intensely more than three times per second, because rapid flashing can trigger epileptic seizures. | A | Partially automatic · interactive | — | ✓ |
| 2.4.1 Bypass blocks — someone navigating by keyboard must be able to skip past what repeats on every page (the menu, the header) instead of tabbing through all of it every time. | A | Partially automatic · sweep | ✓ | ✓ |
| 2.4.2 Page titled — every page must have a title describing what it's about. It's the first thing a screen reader announces, and what shows in the browser tab. Learn more → | A | Partially automatic · sweep + interactive + PDF | ✓ | ✓ |
| 2.4.3 Focus order — when tabbing through the page, the highlight must move in a sensible order, not jump back and forth across the page. Learn more → | A | Partially automatic · interactive | — | ✓ |
| 2.4.4 Link purpose — the link text must say where the link leads. "Read more" and "click here" mean nothing to someone hearing all the page's links read out as a list. | A | Partially automatic · sweep + interactive | ✓ | ✓ |
| 2.4.5 Multiple ways — the menu counts as ONE way to find a page; there must be at least one more, e.g. a search function, a sitemap, or links within the content. | AA | Partially automatic · interactive | — | ✓ |
| 2.4.6 Headings and labels — headings and field labels must describe their content, so you understand what a section is about or what to fill in without guessing. | AA | Partially automatic · vision AI | — | ✓ |
| 2.4.7 Focus visible — when tabbing through the page it must be visible where you are, e.g. with a clear outline around the highlighted element. Learn more → | AA | Partially automatic · interactive | — | ✓ |
| 2.4.11 Focus not obscured (minimum) — the element you've tabbed to must not sit hidden behind a fixed menu or cookie banner, leaving you navigating blind. Learn more → | AA | Automatic · interactive | — | ✓ |
| 2.5.1 Pointer gestures — functions that require swipes or multi-finger gestures must also work with simple taps. | A | Partially automatic · interactive | — | ✓ |
| 2.5.2 Pointer cancellation — a click must be possible to abort by moving the finger or pointer away before releasing — important for people with tremors who often hit the wrong thing. | A | Manual review | — | — |
| 2.5.3 Label in name — the text shown on a button must be part of the button's name in the code, otherwise voice control ("click Submit") doesn't work as expected. | A | Automatic · sweep + interactive | ✓ | ✓ |
| 2.5.4 Motion actuation — functions controlled by shaking or tilting the device must have an ordinary alternative — not everyone can make those movements, and a wheelchair-mounted device can't be shaken. | A | Partially automatic · interactive | — | ✓ |
| 2.5.7 Dragging movements — functions that require drag-and-drop (e.g. sorting a list) must also be possible with simple clicks. Learn more → | AA | Manual review | — | — |
| 2.5.8 Target size (minimum) — buttons and links must be large enough to hit, even with trembling hands or large fingers on a small screen. Learn more → | AA | Automatic · sweep + interactive | ✓ | ✓ |
| 3.1.1 Language of page — the page's language must be declared in the code. Otherwise a screen reader may read Swedish text with English pronunciation — incomprehensible to the listener. Learn more → | A | Automatic · sweep + PDF | ✓ | ✓ |
| 3.1.2 Language of parts — if parts of the page are in another language, that must be marked up, so the screen reader switches pronunciation for just that passage. | AA | Partially automatic · sweep + interactive | — | ✓ |
| 3.2.1 On focus — highlighting an element with the keyboard must not trigger anything unexpected, like a popup opening or being sent to another page. | A | Partially automatic · interactive | — | ✓ |
| 3.2.2 On input — filling in a field or picking from a list must not automatically submit the form or move the user somewhere else without warning. | A | Partially automatic · interactive | — | ✓ |
| 3.2.3 Consistent navigation — menus must sit in the same place and order on every page, so you don't have to relearn the site on each new page. | AA | Partially automatic · interactive | — | ✓ |
| 3.2.4 Consistent identification — the same function must be named and look the same across the site — the search icon can't mean different things on different pages. | AA | Manual review | — | — |
| 3.2.6 Consistent help — if help features (contact details, chat, FAQ) appear on several pages, they must sit in the same place on all of them, so anyone needing help always knows where to find it. The requirement is consistency, not that help must exist. Learn more → | A | Manual review | — | — |
| 3.3.1 Error identification — when something goes wrong in a form, the error must be pointed out and explained in text — not just with a red border, which not everyone perceives. | A | Partially automatic · interactive | — | ✓ |
| 3.3.2 Labels or instructions — form fields must have a visible label or instruction explaining what to fill in, e.g. which date format applies. | A | Partially automatic · sweep | ✓ | ✓ |
| 3.3.3 Error suggestion — error messages should suggest how to fix the error where possible, e.g. "enter the date as YYYY-MM-DD", not just state that something is wrong. | AA | Manual review | — | — |
| 3.3.4 Error prevention — for important commitments (purchases, agreements, deletions) the user must be able to review their input, undo, or confirm before it goes through. | AA | Manual review | — | — |
| 3.3.7 Redundant entry — information the user already provided earlier in the same flow must not have to be entered again, e.g. the same address in two checkout steps. Learn more → | A | Manual review | — | — |
| 3.3.8 Accessible authentication (minimum) — logging in must not require solving memory tasks or puzzles, and pasting a password from a password manager must not be blocked. Learn more → | AA | Partially automatic · interactive | — | ✓ |
| 4.1.2 Name, role, value — custom-built components (bespoke menus, sliders, tabs) must tell assistive technology what they are, what they're called and what state they're in — otherwise they're invisible to screen readers. | A | Partially automatic · sweep + interactive | ✓ | ✓ |
| 4.1.3 Status messages — confirmations and status updates ("item added to cart") must reach screen readers even when they only appear visually on screen. | AA | Partially automatic · interactive | — | ✓ |
Policies & terms66 checks
We locate the privacy policy, cookie policy and terms, read them as documents, and verify two things: that they contain what the law requires, and that what they claim matches what the scan actually measured on the site.
Deep dives: Privacy policy contents · The cookie policy · Consent in forms · The accessibility statement · Right of withdrawal & the 2026 function · Terms of purchase · Encrypted forms · The data protection officer · Policy in Swedish · Dental prices on the web · Advertising trackers on healthcare sites
| What we check | Regulation | Method | Trial | Paid plan |
|---|---|---|---|---|
| Privacy policy: present & accessible7 | ||||
| That a privacy policy exists and is reachable. Learn more → | GDPR art. 13–14 | Deterministic | ✓ | ✓ |
| That the links to the policy pages work and don't lead to error pages. Learn more → | GDPR art. 12.1 | Deterministic | ✓ | ✓ |
| That the policy can be read without first being forced to accept cookies. Learn more → | GDPR art. 12.1 | Deterministic | ✓ | ✓ |
| That a site addressing a Swedish audience has its policy in Swedish. Learn more → | SE · språklagen 10 § | Deterministic | ✓ | ✓ |
| That forms collecting personal data have a link to the privacy policy nearby. Learn more → | GDPR art. 12.1 · 13.1 | Deterministic | ✓ | ✓ |
| That a policy address written out in text next to a form is also clickable. Learn more → | GDPR art. 12.1 | Deterministic | ✓ | ✓ |
| The AI judges whether the policy is comprehensible to an ordinary reader — the GDPR requires clear and plain language. Learn more → | GDPR art. 12.1 | AI | ✓ | ✓ |
| GDPR information (Articles 13–14)21 | ||||
| That the policy names which company is responsible for the personal data. Learn more → | GDPR art. 13.1 a | Deterministic | ✓ | ✓ |
| That the policy doesn't name the wrong company as responsible — a common trace of copied templates. Learn more → | GDPR art. 13.1 a | Deterministic | ✓ | ✓ |
| That the party responsible for the data can be contacted — email, phone, address or a contact page. Learn more → | GDPR art. 13.1 a | Deterministic | ✓ | ✓ |
| That the policy explains why the data is collected and what it is used for. Learn more → | GDPR art. 13.1 c | Deterministic | ✓ | ✓ |
| That the policy states on what legal footing the data is handled — for example consent, a contract, or a legal obligation. Learn more → | GDPR art. 6.1 · 13.1 c | Deterministic | ✓ | ✓ |
| That the policy describes what kinds of data are handled — for example name, email, IP address or purchase history. Learn more → | GDPR art. 14.1 d | Deterministic | ✓ | ✓ |
| That the policy tells you who the data is shared with — for example suppliers, payment services or analytics tools. Learn more → | GDPR art. 13.1 e | Deterministic | ✓ | ✓ |
| That the policy states how long the data is kept — or how that is decided. Learn more → | GDPR art. 13.2 a | Deterministic | ✓ | ✓ |
| That the policy lists the visitor's rights — to see their data, have it corrected or deleted, and more. Learn more → | GDPR art. 15–22 | Deterministic | ✓ | ✓ |
| That it's clear how to exercise those rights in practice — an email address, a form or a contact page. Learn more → | GDPR art. 12.2 | Deterministic | ✓ | ✓ |
| That it's clear you can complain to the Swedish privacy authority (IMY) if you believe your data is mishandled. Learn more → | GDPR art. 13.2 d | Deterministic | ✓ | ✓ |
| That it's clear a given consent can be withdrawn. Applies when the site relies on consent. Learn more → | GDPR art. 7.3 · 13.2 c | Deterministic | ✓ | ✓ |
| That contact details for the data protection officer are present — the person who oversees that data is handled correctly. Applies to public-sector bodies. Learn more → | GDPR art. 37 | Deterministic | ✓ | ✓ |
| The AI verifies that every form collecting personal data has a corresponding explained purpose in the policy. Learn more → | GDPR art. 13.1 c | AI | ✓ | ✓ |
| The AI judges whether it's clear why the data is collected already at the form — not just deep inside the policy. Learn more → | GDPR art. 13 | AI | ✓ | ✓ |
| When the policy uses the legal basis "legitimate interest": does it explain which interest is actually meant — or is only the phrase used? Learn more → | GDPR art. 6.1 f | AI | ✓ | ✓ |
| The AI judges whether the description of who the data is shared with is too vague — "trusted partners" says nothing. Learn more → | GDPR art. 13.1 e | AI | ✓ | ✓ |
| That it's clear whether data collected for one purpose is later used for something else — and if so, how. Learn more → | GDPR art. 13.3 | AI | ✓ | ✓ |
| That it's clear whether decisions about the visitor are made automatically or profiles are built — for example automated credit assessments. Learn more → | GDPR art. 13.2 f · 22 | AI | ✓ | ✓ |
| That it's clear where the data comes from when the person didn't provide it themselves — for example purchased address lists. Learn more → | GDPR art. 14.2 f | AI | ✓ | ✓ |
| That it's clear how to say no to marketing mailings. Learn more → | GDPR art. 21.2 | AI | ✓ | ✓ |
| Cookies, tracking & consent11 | ||||
| That cookie information exists — as its own document or a clear section. Learn more → | ePrivacy art. 5.3 | Deterministic | ✓ | ✓ |
| That the cookie information explains what each cookie does and why it's used — not just that cookies exist. Learn more → | ePrivacy · LEK 9 kap. | Deterministic | ✓ | ✓ |
| That it's stated how long each cookie stays in the visitor's browser. Learn more → | ePrivacy art. 5.3 · Planet49 | Deterministic | ✓ | ✓ |
| That every tracker we actually measured on the site is also mentioned in the cookie information — measured is compared against what's stated. Learn more → | GDPR art. 13.1 e | Deterministic | ✓ | ✓ |
| That the cookie banner and the cookie information say the same thing — the banner mustn't offer categories the information doesn't mention. Learn more → | ePrivacy · GDPR art. 12 | Deterministic | ✓ | ✓ |
| That a policy claiming data isn't shared with others isn't contradicted by what we actually measured on the site. Learn more → | GDPR art. 5.1 a | Deterministic | ✓ | ✓ |
| That a policy claiming no tracking cookies are used isn't contradicted by what the scan measured. Learn more → | GDPR art. 5.1 a | Deterministic | ✓ | ✓ |
| That consent checkboxes in forms (newsletter, marketing) aren't pre-ticked — pre-ticked consent is invalid. Learn more → | GDPR art. 4.11 · 7.1 (Planet49) | Deterministic | ✓ | ✓ |
| The AI reviews that one checkbox doesn't force several different yeses together — for example a single tick for both the terms and the newsletter. Learn more → | GDPR art. 7.4 | AI | ✓ | ✓ |
| The AI reviews form text claiming that submitting also constitutes consent to something else — "by submitting you also agree to mailings" is not valid consent. Learn more → | GDPR art. 4.11 · 7.4 (Planet49) | AI | ✓ | ✓ |
| That the policy doesn't describe an invalid consent setup — "by continuing to browse you accept cookies" is not valid consent. Learn more → | GDPR art. 4.11 · 7 (Planet49) | AI | ✓ | ✓ |
| Third-country transfers (Articles 44–49)2 | ||||
| That the policy explains what protection is used when data is sent outside the EU — for example the EU's standard contractual clauses — instead of merely noting that it happens. Learn more → | GDPR art. 46 | Deterministic | ✓ | ✓ |
| That the policy tells you when we've measured data actually being sent to recipients outside the EU — for example US ad platforms. Learn more → | GDPR art. 13.1 f · 44 | Deterministic | ✓ | ✓ |
| Security in transit (Article 32)4 | ||||
| That forms with personal data or logins are submitted encrypted (https) — unencrypted forms can be eavesdropped in transit. Learn more → | GDPR art. 32 | Deterministic | ✓ | ✓ |
| That the site's security certificate is valid — not expired, self-signed or issued for the wrong address. Learn more → | GDPR art. 32 | Deterministic | ✓ | ✓ |
| That no personal identity numbers are printed in the site's visible text — a number left in a set of minutes or a form is personal data anyone can read. | GDPR art. 5.1(f) · 32 | Deterministic | ✓ | ✓ |
| That a sole trader's registration number, which is the owner's personal identity number, is only printed where it is needed to identify the business. | Dataskyddslagen 3 kap. 10 § · GDPR art. 5.1(c) | Deterministic | ✓ | ✓ |
| E-commerce & consumer rights8 | ||||
| That sites selling something have purchase or user terms that can be found. Learn more → | SE · konsumentlagstiftning | Deterministic | ✓ | ✓ |
| That the terms tell a dissatisfied customer they can turn to the Swedish National Board for Consumer Disputes (ARN). Applies to sites selling to consumers. Learn more → | SE · lag 2015:671 (ARN) | Deterministic | ✓ | ✓ |
| That the terms no longer reference the EU's ODR dispute platform — it shut down in July 2025, so the reference points to something that no longer exists. Learn more → | EU ODR (nedlagd 2025) | Deterministic | ✓ | ✓ |
| That company name, address and email are easy to find on the site — a legal requirement for businesses selling or marketing online. Learn more → | SE · e-handelslagen 8 § | Deterministic | ✓ | ✓ |
| That selling sites have an online withdrawal function — a place where the customer can cancel their purchase directly on the site. A legal requirement from 19 June 2026; we flag it in advance. Learn more → | SE · distansavtalslagen 2 kap. 10 a § | Deterministic | ✓ | ✓ |
| That selling sites show a phone number — consumers buying at a distance must be able to reach the business by phone (Distance Contracts Act, ch. 2 s. 2). Applies to sites selling to consumers. | SE · distansavtalslagen 2 kap. 2 § | Deterministic | ✓ | ✓ |
| The AI reviews that the terms inform correctly about the right of withdrawal. Applies to selling sites. Learn more → | SE · distansavtalslagen | AI | ✓ | ✓ |
| The AI reviews that the price information in the terms is correct and complete. Applies to selling sites. Learn more → | SE · prisinformationslagen | AI | ✓ | ✓ |
| Sensitive data & sector-specific duties9 | ||||
| That public-sector organisations have an accessibility statement — the page where, by law, they report how accessible their site is. Learn more → | DOS-lagen (SE) | Deterministic | ✓ | ✓ |
| That an accessibility statement claiming the site is fully accessible isn't contradicted by what our scan actually found. Learn more → | DOS-lagen (SE) | Deterministic | ✓ | ✓ |
| That the policy explains on what legal footing sensitive data is handled — health, religion, political opinions and more have extra-strong protection under the GDPR. Learn more → | GDPR art. 9 | AI | ✓ | ✓ |
| Healthcare-specific review: the legal footing for health data, the Swedish Patient Data Act, and that the website is kept separate from the medical-record system. Applies to care providers. Learn more → | GDPR art. 9.2 h · PDL (SE) | AI | ✓ | ✓ |
| Municipality-specific review of the legal footing — public authorities can rarely ask citizens for consent, since the citizen has no free choice. Applies to municipalities and public-sector bodies. Learn more → | GDPR art. 6.1 e (SE) | AI | ✓ | ✓ |
| That dental practices show price information on the web — prices, a price list or reference prices. Advisory: the duty applies to the practice, not specifically the website. Learn more → | SE · förordning 2008:193 (tandvårdsstöd) | Deterministic | ✓ | ✓ |
| That healthcare websites don't leak visit data to advertising platforms (Meta pixel and others) before consent — especially on booking and contact pages (GDPR art. 32). Learn more → | GDPR art. 32 | Deterministic | ✓ | ✓ |
| That teeth whitening isn't marketed above the permitted peroxide limit (EU Cosmetics Regulation — at most 6% hydrogen peroxide via a dentist). | EU 1223/2009 bilaga III | Deterministic | ✓ | ✓ |
| That clinics offering aesthetic injections (wrinkle treatment/fillers) show the aesthetics-law information on the web — 18-year limit, IVO registration, reflection period. Advisory; doesn't apply to botox against bruxism (dental care). | SE · estetiklagen 2021:363 | AI | ✓ | ✓ |
| Maintenance & currency4 | ||||
| That the policy carries a last-updated date. Learn more → | GDPR art. 5.2 · 12 | Deterministic | ✓ | ✓ |
| That the policy contains no leftover template blanks like "[Company name]" or "Lorem ipsum" — signs of a copied template that was never filled in. Learn more → | — | Deterministic | ✓ | ✓ |
| That the policy doesn't reference Datainspektionen — the authority was renamed IMY in 2021, so such a reference is a strong sign the policy hasn't been maintained. Learn more → | SE | Deterministic | ✓ | ✓ |
| That the policy doesn't reference the old Swedish Personal Data Act (PUL) — it was replaced by the GDPR in 2018, so the reference means the policy is out of date. Learn more → | SE · GDPR | Deterministic | ✓ | ✓ |
AI Act1 check
Identifies chat and assistant widgets and flags the transparency duty in Article 50 of the AI Act: visitors must know when they are interacting with an AI.
Deep dives: AI transparency in chat
| What we check | Regulation | Method | Trial | Paid plan |
|---|---|---|---|---|
| Chat and assistant widgets are identified (Intercom, Drift, Humany and more) and the transparency duty is flagged: visitors must be informed when they interact with an AI. Binding from August 2026. Learn more → | AI-förordningen art. 50.1 | Deterministic | ✓ | ✓ |
Quality4 checks
Quality is the one module with no law behind it. Nobody is fined for a broken link or a language error — but on a public-sector site they are exactly what makes a visitor doubt everything else on the page. It is included in every plan and starts switched off, so you turn it on when you want it.
| What we check | Regulation | Method | Trial | Paid plan |
|---|---|---|---|---|
| That every link on the site still leads somewhere. Only 404 and 410 count as broken — a server saying outright that the page does not exist. | — | Deterministic | ✓ | ✓ |
| Links that answered something other than a clean OK or a clean “gone” — a 403, a server error, a timeout, or a page that answers OK while saying “not found”. Reported for you to judge, and dismissible with a reason. | — | Deterministic | ✓ | ✓ |
| Links that work but whose destination has no encryption — they answer over http even after every redirect. A visitor who clicks one sends the address, and what they type, in the clear. A link that lands on https is not counted. | — | Deterministic | ✓ | ✓ |
| Three kinds of error in the visible page text: misspellings, the right word in the wrong form, and words that have dropped out of a sentence. Always together with the sentence they appear in, and every suggestion is re-examined in a second AI pass before it is shown. Place names and specialist terms are the hard cases, so each word is a suggestion to check — never a verdict. | — | AI | ✓ | ✓ |
Want to see what we find on your site?
Run a free scan — all four modules included for 30 days, no card required.