codeforsociety.org

https://codeforsociety.org · 42/89 checks passed

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 27/37 (10 failed)
Level 2 — Enhanced 6/27 (16 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 9/13
Accountability 0/5
AI & Automation 2/8
Interoperability 1/3
Privacy 9/16
Provenance 1/2
Security 7/11
Transparency 4/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The About page contains no AI use policy or statement, only a general mission around data and technology.
    Fix: Publish a dedicated AI use policy or statement describing how the organization uses AI.
  • scope_clear: The page mentions AI and machine learning as a partnership area but never explains what AI is used for by the organization itself.
    Fix: Add clear language specifying the purposes and contexts in which AI is applied on the site or in operations.

Privacy

Security

Transparency

  • actionable: The page offers only thematic links (Jobs, Events, Donate) but no direct email address, phone number, physical address, or contact form to reach the organisation.
    Fix: Add a direct contact method such as an email address, phone number, or a contact form to the page so visitors can actually reach the organisation.
  • disclosure_exists: The page describes the organization's mission, strategy, and partnerships but contains no funding or sponsorship disclosure, only a donation prompt and links to financial documents.
    Fix: Add a dedicated funding disclosure section on the About page naming the organization's funders and sponsors.
  • transparent: Funding sources are not identified anywhere on the page; it only references generic 'funders' and links to 'Financial and Legal Documents' without naming them.
    Fix: Clearly identify each funding source by name directly on the page rather than relying on external document links.

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page lists only the organization 'Code for Science and Society' with no named person or role identified as responsible for the contact page or enquiries.
    Fix: Add a named contact person or specific role (e.g., 'Community Manager') responsible for handling enquiries on this page.
  • contactable: The page provides no email address, phone number, contact form, or direct means to reach a responsible person or team.
    Fix: Include a direct contact method such as an email address, phone number, or contact form on the page.
  • response_timeframe: The page provides no information about how quickly the organization responds to inquiries or contacts.
    Fix: Add a stated response timeframe on the contact page, such as 'We aim to respond within 3 business days.'
  • specific: No timeframe of any kind is published, so no specific duration is provided.
    Fix: Publish a concrete, specific response window measured in days rather than vague terms like 'promptly'.
  • process_exists: The page lists community and involvement links but documents no complaints or feedback process.
    Fix: Create and link a dedicated complaints/feedback process describing how users can raise concerns.
  • steps_clear: Since no complaints process is documented, there are no clear steps for submitting a complaint.
    Fix: Provide step-by-step instructions (e.g., contact channel, required information, and escalation path) for making a complaint.
  • appeals_exists: The contact/get-involved page contains only community engagement links (jobs, events, donate) and no documented appeals process.
    Fix: Add a clearly labeled section or page describing how users can formally appeal or contest a decision, including steps and contact details.
  • independent: No appeals process is documented at all, so there is no indication it is independent or escalated to a separate reviewer.
    Fix: Document an appeals mechanism that routes disputes to an independent party or a higher-level escalation body distinct from the original decision-maker.

AI & Automation

  • detailed_scope: There is no AI policy present, so no detailed scope of AI use is provided.
    Fix: Create an AI policy that details each use case, the systems involved, and where they are deployed.
  • limitations: The page does not acknowledge any limitations of AI systems, only limitations of data and technology broadly.
    Fix: Explicitly state the known limitations and risks of any AI systems the organization uses.
  • safeguards: No safeguards or quality controls for AI are described anywhere on the page.
    Fix: Document the safeguards, human oversight, and quality-control measures applied to AI use.
  • marking_policy: The about page contains only organizational mission and contact information with no stated policy for marking AI-assisted content.
    Fix: Publish a clear policy stating how AI-assisted content is labeled and where such labels appear on the site.
  • consistent: No AI content marking appears anywhere on the page, so consistency cannot be demonstrated.
    Fix: Apply consistent AI-content labels across all pages once a marking policy is defined and give examples of how they are displayed.
  • oversight_exists: The page provides no documentation of human oversight over any AI outputs.
    Fix: Add a statement describing how humans review and oversee any AI-generated outputs used by the organization.
  • review_process: There is no description of any review or approval process for AI content on the page.
    Fix: Document the specific steps and stages through which AI-generated content is reviewed and approved before publication.
  • accountability: The page names no person or role responsible for AI-generated content, only general team and contact references.
    Fix: Identify a named role or team accountable for AI-generated content and provide a contact point for concerns.

Interoperability

Privacy

  • banner_present: The page content shows no cookie or consent banner anywhere on the homepage.
    Fix: Add a visible cookie/consent banner that appears on page load allowing users to accept or reject non-essential cookies.
  • partner_sharing_mentioned: There is no banner or on-page consent copy, so no disclosure of data sharing with third-party partners exists.
    Fix: Include clear language in the consent banner disclosing whether and how visitor data is shared with third-party partners.
  • partner_count_specific: No partner sharing is disclosed and no numeric count of partners appears anywhere on the page.
    Fix: If data is shared with partners, state the specific number of partners in the consent disclosure.

Provenance

Security

Transparency

  • named_person: No named individual or team responsible for enquiries is identified; the page only offers general links like Jobs, Events, and Donate.
    Fix: Identify a specific individual or team (e.g., 'Contact our Partnerships Team') responsible for responding to enquiries.
  • role_clear: Since no responsible person or team is named, their role or authority cannot be stated or assessed.
    Fix: Once a contact is named, clearly state their role and authority (e.g., 'Jane Doe, Program Director') so users know who they are reaching.
  • annual_statement: The page contains no data practices statement or evidence of a regular privacy review, only mission and contact information.
    Fix: Add a privacy statement with an explicit note that data practices are reviewed on a regular (e.g., annual) basis and link it from the About page.
  • dated: No data practices statement is present, so there is no date or version indicating when it was last updated.
    Fix: Publish a dated or version-labelled data practices/privacy statement showing the last review date.
  • governance_exists: The page references community governance as a mission theme but never describes the organization's own governance or editorial structure.
    Fix: Add a section outlining how CS&S is governed, such as its board structure, decision-making processes, and oversight mechanisms.
  • roles_clear: The page states CS&S is 'run by nonprofit experts' and links to a People page but does not identify key roles or responsibilities on this page.
    Fix: List the key leadership roles (e.g., executive director, board members) and their responsibilities directly on the page or in a clearly summarized form.
  • detail: The page provides no funding amounts, percentages, or categories, mentioning only that CS&S partners with unspecified 'funders'.
    Fix: Include meaningful funding detail such as amounts, percentages, or categories of support from each source.
  • complete: With no funding streams disclosed at all, the page cannot demonstrate coverage of major funding sources.
    Fix: List all major funding streams (e.g., grants, donations, partnerships) so the disclosure is comprehensive.
  • algorithm_explained: The About page describes CS&S's mission and partnerships but does not explain the purpose of any algorithms, even while mentioning AI and machine learning as partner areas.
    Fix: Add a section describing any algorithms the organization uses (or clarify that it uses none) and explain their purpose in plain language.
  • impact_clear: The page contains no description of how any algorithmic decisions affect users or communities.
    Fix: Describe the concrete impacts of any algorithmic decision-making on users, or state explicitly that no algorithmic decisions are made on the site.

Level 3 — Advanced

Accessibility

  • statement_exists: The About page contains only mission, history, and contact information with no dedicated accessibility statement.
    Fix: Create a dedicated accessibility statement page describing the site's commitment to accessibility and link to it in the footer navigation.
  • known_issues: No accessibility statement is present, so no known accessibility issues or limitations are acknowledged.
    Fix: Add a section to an accessibility statement that lists known accessibility barriers or limitations of the site.
  • remediation_timeline: The page provides no timeline or commitment for fixing accessibility issues.
    Fix: Include a stated timeline or commitment in the accessibility statement for remediating identified accessibility issues.
  • feedback_channel: The only contact details are a general email and mailing address with no accessibility-specific feedback mechanism or response commitment.
    Fix: Provide an accessibility feedback channel (e.g., dedicated email or form) along with a stated commitment on response time.

Accountability

  • policy_exists: The about page contains only mission, history, and contact information with no published moderation policy.
    Fix: Publish a dedicated moderation policy page and link to it from the site navigation or footer.
  • criteria_clear: No moderation criteria are stated anywhere in the page content.
    Fix: Add clear, specific criteria describing what content or behavior is subject to moderation.
  • enforcement: The page does not describe any enforcement process for moderation.
    Fix: Document the enforcement process, including how violations are reported, reviewed, and acted upon.

Interoperability

Security

  • plan_exists: The About page describes the organization's mission and programs but contains no published incident response plan or security policy.
    Fix: Publish a dedicated incident response plan or security policy page and link to it from the site.
  • notification_commitment: The page makes no commitment to publicly notify users about significant security incidents.
    Fix: Add an explicit statement committing to public notification of affected users in the event of a significant security incident.
  • timeframe: No timeframe for disclosing incidents to affected users is stated anywhere on the page.
    Fix: Specify a concrete disclosure timeframe (e.g., notification within 72 hours of discovering an incident) in the incident response policy.

Transparency

  • open_source: Despite championing free/libre/open source software, the page provides no link to a public code repository for its own projects or site.
    Fix: Add a link to the organization's public code repository (e.g., a GitHub/GitLab org page) from the About or Projects section.
  • tech_docs: No technical documentation is published or linked anywhere on the page.
    Fix: Publish and link technical documentation for CS&S's tools, infrastructure, or open-source projects from the About or Resources section.
  • criteria_published: No specific criteria used in any algorithmic decision are published anywhere on the page.
    Fix: Publish the specific criteria applied in any algorithmic or automated decision process, such as within a linked policy document.
  • weighting: The page provides no information about the weighting or priority of any decision criteria.
    Fix: Document how each criterion is weighted or prioritized in any automated decision-making the organization performs.
  • auditable: The page offers no technical or procedural detail that would enable external audit or review of any algorithm.
    Fix: Provide sufficient methodological detail or an audit report link so external reviewers can independently assess any algorithms used.

Responsibility to the Future

  • disclosure_exists: The about page describes the organization's mission and values but contains no published environmental impact or sustainability disclosure.
    Fix: Publish a dedicated environmental or sustainability statement describing the organization's environmental footprint and commitments.
  • specific_metrics: The page provides no specific figures on carbon, energy use, or emissions anywhere in its content.
    Fix: Add quantified environmental metrics such as annual carbon emissions or energy consumption to the sustainability disclosure.
  • hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure.
    Fix: Disclose the hosting provider's energy source or carbon profile, ideally noting use of green or renewable-powered hosting.
  • plan_exists: The About page describes mission, strategy, and history but contains no published plan for what happens if the organisation fails or exits.
    Fix: Publish a succession or wind-down plan describing how the organisation would responsibly cease operations or transfer its work.
  • data_and_content_fate: The page does not address what would happen to user data or published content if the organisation ceased to operate.
    Fix: Add a section specifying how user data and published content would be preserved, transferred, or deleted upon closure.
  • custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page.
    Fix: Name specific custodians, mirror sites, or archival partners (e.g., an institutional repository) that would take over hosting content if the organisation exits.
  • policy_exists: The About page describes the organization's mission, strategy, and history but contains no published policy on worker wellbeing or working conditions.
    Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the About or Get Involved section.
  • specific_commitments: The page makes no specific commitments regarding pay, hours, mental health, or benefits for workers.
    Fix: Add explicit commitments covering fair pay, working hours, mental health support, and benefits within a documented worker wellbeing policy.
  • accountability: The page does not identify any person, team, or oversight body responsible for worker conditions.
    Fix: Name a responsible role or oversight body (e.g., HR lead or board committee) accountable for monitoring and enforcing worker conditions.