codeforsociety.org
https://codeforsociety.org · 42/89 checks passed
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 27/37 (10 failed) |
| Level 2 — Enhanced | 6/27 (16 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 9/13 |
| Accountability | 0/5 |
| AI & Automation | 2/8 |
| Interoperability | 1/3 |
| Privacy | 9/16 |
| Provenance | 1/2 |
| Security | 7/11 |
| Transparency | 4/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
- Heading hierarchy issues: h2 -> h4 (skipped h3).
- 1 colour-contrast violation reported by axe-core (text below 4.5:1).
AI & Automation
- robots.txt does not reference any known AI crawlers.
- Not found at any of: /ai-policy, /ai.
-
policy_exists: The About page contains no AI use policy or statement, only a general mission around data and technology.
Fix: Publish a dedicated AI use policy or statement describing how the organization uses AI.
-
scope_clear: The page mentions AI and machine learning as a partnership area but never explains what AI is used for by the organization itself.
Fix: Add clear language specifying the purposes and contexts in which AI is applied on the site or in operations.
Privacy
- Detected 1 data-leaking service across 1 category: plausible (plausible.io).
PASS
Session cookies only
PASS
No tracking pixels
Security
- content-security-policy: header not set on the response.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
-
actionable: The page offers only thematic links (Jobs, Events, Donate) but no direct email address, phone number, physical address, or contact form to reach the organisation.
Fix: Add a direct contact method such as an email address, phone number, or a contact form to the page so visitors can actually reach the organisation.
-
disclosure_exists: The page describes the organization's mission, strategy, and partnerships but contains no funding or sponsorship disclosure, only a donation prompt and links to financial documents.
Fix: Add a dedicated funding disclosure section on the About page naming the organization's funders and sponsors.
-
transparent: Funding sources are not identified anywhere on the page; it only references generic 'funders' and links to 'Financial and Legal Documents' without naming them.
Fix: Clearly identify each funding source by name directly on the page rather than relying on external document links.
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
named_person: The page lists only the organization 'Code for Science and Society' with no named person or role identified as responsible for the contact page or enquiries.
Fix: Add a named contact person or specific role (e.g., 'Community Manager') responsible for handling enquiries on this page.
-
contactable: The page provides no email address, phone number, contact form, or direct means to reach a responsible person or team.
Fix: Include a direct contact method such as an email address, phone number, or contact form on the page.
-
response_timeframe: The page provides no information about how quickly the organization responds to inquiries or contacts.
Fix: Add a stated response timeframe on the contact page, such as 'We aim to respond within 3 business days.'
-
specific: No timeframe of any kind is published, so no specific duration is provided.
Fix: Publish a concrete, specific response window measured in days rather than vague terms like 'promptly'.
-
process_exists: The page lists community and involvement links but documents no complaints or feedback process.
Fix: Create and link a dedicated complaints/feedback process describing how users can raise concerns.
-
steps_clear: Since no complaints process is documented, there are no clear steps for submitting a complaint.
Fix: Provide step-by-step instructions (e.g., contact channel, required information, and escalation path) for making a complaint.
-
appeals_exists: The contact/get-involved page contains only community engagement links (jobs, events, donate) and no documented appeals process.
Fix: Add a clearly labeled section or page describing how users can formally appeal or contest a decision, including steps and contact details.
-
independent: No appeals process is documented at all, so there is no indication it is independent or escalated to a separate reviewer.
Fix: Document an appeals mechanism that routes disputes to an independent party or a higher-level escalation body distinct from the original decision-maker.
AI & Automation
-
detailed_scope: There is no AI policy present, so no detailed scope of AI use is provided.
Fix: Create an AI policy that details each use case, the systems involved, and where they are deployed.
-
limitations: The page does not acknowledge any limitations of AI systems, only limitations of data and technology broadly.
Fix: Explicitly state the known limitations and risks of any AI systems the organization uses.
-
safeguards: No safeguards or quality controls for AI are described anywhere on the page.
Fix: Document the safeguards, human oversight, and quality-control measures applied to AI use.
-
marking_policy: The about page contains only organizational mission and contact information with no stated policy for marking AI-assisted content.
Fix: Publish a clear policy stating how AI-assisted content is labeled and where such labels appear on the site.
-
consistent: No AI content marking appears anywhere on the page, so consistency cannot be demonstrated.
Fix: Apply consistent AI-content labels across all pages once a marking policy is defined and give examples of how they are displayed.
-
oversight_exists: The page provides no documentation of human oversight over any AI outputs.
Fix: Add a statement describing how humans review and oversee any AI-generated outputs used by the organization.
-
review_process: There is no description of any review or approval process for AI content on the page.
Fix: Document the specific steps and stages through which AI-generated content is reviewed and approved before publication.
-
accountability: The page names no person or role responsible for AI-generated content, only general team and contact references.
Fix: Identify a named role or team accountable for AI-generated content and provide a contact point for concerns.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
banner_present: The page content shows no cookie or consent banner anywhere on the homepage.
Fix: Add a visible cookie/consent banner that appears on page load allowing users to accept or reject non-essential cookies.
-
partner_sharing_mentioned: There is no banner or on-page consent copy, so no disclosure of data sharing with third-party partners exists.
Fix: Include clear language in the consent banner disclosing whether and how visitor data is shared with third-party partners.
-
partner_count_specific: No partner sharing is disclosed and no numeric count of partners appears anywhere on the page.
Fix: If data is shared with partners, state the specific number of partners in the consent disclosure.
SKIPPED
Human-readable privacy policy
Skipped: Target page not found in captured content
SKIPPED
Plain language data practices
Skipped: Target page not found in captured content
Skipped: Target page not found in captured content
SKIPPED
Published data retention periods
Skipped: Target page not found in captured content
Skipped: Target page not found in captured content
Provenance
- No author or date metadata found on the page.
Security
- security.txt not published.
Transparency
-
named_person: No named individual or team responsible for enquiries is identified; the page only offers general links like Jobs, Events, and Donate.
Fix: Identify a specific individual or team (e.g., 'Contact our Partnerships Team') responsible for responding to enquiries.
-
role_clear: Since no responsible person or team is named, their role or authority cannot be stated or assessed.
Fix: Once a contact is named, clearly state their role and authority (e.g., 'Jane Doe, Program Director') so users know who they are reaching.
-
annual_statement: The page contains no data practices statement or evidence of a regular privacy review, only mission and contact information.
Fix: Add a privacy statement with an explicit note that data practices are reviewed on a regular (e.g., annual) basis and link it from the About page.
-
dated: No data practices statement is present, so there is no date or version indicating when it was last updated.
Fix: Publish a dated or version-labelled data practices/privacy statement showing the last review date.
-
governance_exists: The page references community governance as a mission theme but never describes the organization's own governance or editorial structure.
Fix: Add a section outlining how CS&S is governed, such as its board structure, decision-making processes, and oversight mechanisms.
-
roles_clear: The page states CS&S is 'run by nonprofit experts' and links to a People page but does not identify key roles or responsibilities on this page.
Fix: List the key leadership roles (e.g., executive director, board members) and their responsibilities directly on the page or in a clearly summarized form.
-
detail: The page provides no funding amounts, percentages, or categories, mentioning only that CS&S partners with unspecified 'funders'.
Fix: Include meaningful funding detail such as amounts, percentages, or categories of support from each source.
-
complete: With no funding streams disclosed at all, the page cannot demonstrate coverage of major funding sources.
Fix: List all major funding streams (e.g., grants, donations, partnerships) so the disclosure is comprehensive.
-
algorithm_explained: The About page describes CS&S's mission and partnerships but does not explain the purpose of any algorithms, even while mentioning AI and machine learning as partner areas.
Fix: Add a section describing any algorithms the organization uses (or clarify that it uses none) and explain their purpose in plain language.
-
impact_clear: The page contains no description of how any algorithmic decisions affect users or communities.
Fix: Describe the concrete impacts of any algorithmic decision-making on users, or state explicitly that no algorithmic decisions are made on the site.
Level 3 — Advanced
Accessibility
-
statement_exists: The About page contains only mission, history, and contact information with no dedicated accessibility statement.
Fix: Create a dedicated accessibility statement page describing the site's commitment to accessibility and link to it in the footer navigation.
-
known_issues: No accessibility statement is present, so no known accessibility issues or limitations are acknowledged.
Fix: Add a section to an accessibility statement that lists known accessibility barriers or limitations of the site.
-
remediation_timeline: The page provides no timeline or commitment for fixing accessibility issues.
Fix: Include a stated timeline or commitment in the accessibility statement for remediating identified accessibility issues.
-
feedback_channel: The only contact details are a general email and mailing address with no accessibility-specific feedback mechanism or response commitment.
Fix: Provide an accessibility feedback channel (e.g., dedicated email or form) along with a stated commitment on response time.
Accountability
-
policy_exists: The about page contains only mission, history, and contact information with no published moderation policy.
Fix: Publish a dedicated moderation policy page and link to it from the site navigation or footer.
-
criteria_clear: No moderation criteria are stated anywhere in the page content.
Fix: Add clear, specific criteria describing what content or behavior is subject to moderation.
-
enforcement: The page does not describe any enforcement process for moderation.
Fix: Document the enforcement process, including how violations are reported, reviewed, and acted upon.
Interoperability
- Not found at: /status
Security
-
plan_exists: The About page describes the organization's mission and programs but contains no published incident response plan or security policy.
Fix: Publish a dedicated incident response plan or security policy page and link to it from the site.
-
notification_commitment: The page makes no commitment to publicly notify users about significant security incidents.
Fix: Add an explicit statement committing to public notification of affected users in the event of a significant security incident.
-
timeframe: No timeframe for disclosing incidents to affected users is stated anywhere on the page.
Fix: Specify a concrete disclosure timeframe (e.g., notification within 72 hours of discovering an incident) in the incident response policy.
Skipped: Target page not found in captured content
Transparency
-
open_source: Despite championing free/libre/open source software, the page provides no link to a public code repository for its own projects or site.
Fix: Add a link to the organization's public code repository (e.g., a GitHub/GitLab org page) from the About or Projects section.
-
tech_docs: No technical documentation is published or linked anywhere on the page.
Fix: Publish and link technical documentation for CS&S's tools, infrastructure, or open-source projects from the About or Resources section.
-
criteria_published: No specific criteria used in any algorithmic decision are published anywhere on the page.
Fix: Publish the specific criteria applied in any algorithmic or automated decision process, such as within a linked policy document.
-
weighting: The page provides no information about the weighting or priority of any decision criteria.
Fix: Document how each criterion is weighted or prioritized in any automated decision-making the organization performs.
-
auditable: The page offers no technical or procedural detail that would enable external audit or review of any algorithm.
Fix: Provide sufficient methodological detail or an audit report link so external reviewers can independently assess any algorithms used.
Responsibility to the Future
-
disclosure_exists: The about page describes the organization's mission and values but contains no published environmental impact or sustainability disclosure.
Fix: Publish a dedicated environmental or sustainability statement describing the organization's environmental footprint and commitments.
-
specific_metrics: The page provides no specific figures on carbon, energy use, or emissions anywhere in its content.
Fix: Add quantified environmental metrics such as annual carbon emissions or energy consumption to the sustainability disclosure.
-
hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure.
Fix: Disclose the hosting provider's energy source or carbon profile, ideally noting use of green or renewable-powered hosting.
-
plan_exists: The About page describes mission, strategy, and history but contains no published plan for what happens if the organisation fails or exits.
Fix: Publish a succession or wind-down plan describing how the organisation would responsibly cease operations or transfer its work.
-
data_and_content_fate: The page does not address what would happen to user data or published content if the organisation ceased to operate.
Fix: Add a section specifying how user data and published content would be preserved, transferred, or deleted upon closure.
-
custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page.
Fix: Name specific custodians, mirror sites, or archival partners (e.g., an institutional repository) that would take over hosting content if the organisation exits.
-
policy_exists: The About page describes the organization's mission, strategy, and history but contains no published policy on worker wellbeing or working conditions.
Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the About or Get Involved section.
-
specific_commitments: The page makes no specific commitments regarding pay, hours, mental health, or benefits for workers.
Fix: Add explicit commitments covering fair pay, working hours, mental health support, and benefits within a documented worker wellbeing policy.
-
accountability: The page does not identify any person, team, or oversight body responsible for worker conditions.
Fix: Name a responsible role or oversight body (e.g., HR lead or board committee) accountable for monitoring and enforcing worker conditions.