Cory Doctorow

https://craphound.com · 34/92 checks passed · media

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 18/37 (18 failed)
Level 2 — Enhanced 7/27 (19 failed)
Level 3 — Advanced 0/10 (4 failed)

By category

CategoryResult
Accessibility 5/13
Accountability 1/5
AI & Automation 3/8
Interoperability 1/3
Privacy 9/16
Provenance 1/2
Security 4/11
Transparency 1/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The page contains no AI use policy or statement; it is an author's about/news page with book announcements.
    Fix: Add a clearly labeled AI policy page or section stating whether and how AI is used in content creation on the site.
  • scope_clear: No AI policy is present, so the scope of AI use is not explained anywhere on the page.
    Fix: Publish a brief statement describing what AI tools (if any) are used for writing, editing, images, or site operations.

Privacy

Security

Transparency

  • purpose_clear: The page content shown is a list of news/book posts and does not clearly state the site's purpose.
    Fix: Include a short introductory paragraph at the top of the about page explaining what craphound.com is and its purpose.
  • disclosure_exists: The page contains no funding or sponsorship disclosure; it only lists books, posts, and archives.
    Fix: Add a clearly labeled funding/sponsorship disclosure section on the About page identifying any revenue sources supporting the site.
  • transparent: No funding sources are identified anywhere on the visible page content.
    Fix: Explicitly name funding sources (e.g., book sales, Patreon, affiliate links, sponsors) in a dedicated transparency statement.

Level 2 — Enhanced

Accessibility

Accountability

  • response_timeframe: The page is an author's about/news page with no published response timeframes for inquiries.
    Fix: Add a contact section stating an expected response time (e.g., 'We respond within 5 business days').
  • specific: No specific timeframes (days or hours) are provided anywhere on the page.
    Fix: Specify concrete response windows in days or business days on the contact or about page.
  • process_exists: There is no documented complaints or feedback process visible on the page, only book news and navigation links.
    Fix: Publish a clear complaints/feedback policy page linked from the main navigation.
  • steps_clear: Since no complaints process is documented, no steps are provided for users to follow.
    Fix: List numbered steps describing how to submit a complaint, what information to include, and where to send it.

AI & Automation

  • detailed_scope: There is no AI policy on the page, so detailed scope of AI use is absent.
    Fix: Create an AI policy section that itemizes specific use cases (e.g., drafting, translation, image generation) and where each applies.
  • limitations: No acknowledgment of AI system limitations appears on the page.
    Fix: Include a statement acknowledging AI limitations such as inaccuracy, bias, or hallucination risks relevant to the site's content.
  • safeguards: No safeguards or quality controls around AI use are described on the page.
    Fix: Describe concrete safeguards such as human review, fact-checking, and disclosure labels applied to any AI-assisted content.
  • marking_policy: The page contains no policy or statement about marking AI-assisted content.
    Fix: Add a clearly-linked policy page stating whether and how AI-assisted content is labeled on the site.
  • consistent: No AI content markings are visible on any posts, so consistency cannot be demonstrated.
    Fix: Apply a consistent label (e.g., 'AI-assisted') to any posts that use AI tools and document the convention publicly.
  • oversight_exists: The page does not document any human oversight process for AI outputs.
    Fix: Publish a brief statement describing how a human reviews any AI-generated material before publication.
  • review_process: There is no description of a review or approval process for AI content on this page.
    Fix: Describe the editorial review steps (who reviews, what is checked, when it is approved) in an editorial/AI policy section.
  • accountability: While Cory Doctorow is named as author, no one is specifically identified as accountable for AI-generated content.
    Fix: Name a specific person or role responsible for AI-generated content and provide contact information for concerns.

Interoperability

Privacy

  • exists: The /privacy path displays a tag archive of blog posts tagged 'privacy' rather than an actual privacy policy document.
    Fix: Create a dedicated privacy policy page at a clear URL (e.g., /privacy-policy) explaining how visitor data is handled on the site.
  • plain_language: No privacy policy text exists on the page to evaluate for plain-language writing.
    Fix: Draft and publish a privacy policy written in clear, everyday language that any visitor can understand.
  • comprehensive: The page contains no statement about what data the site collects or why.
    Fix: Include sections in the privacy policy that detail each category of data collected (e.g., analytics, cookies, comments) and the purpose for collecting it.
  • plain_language: There are no described data practices on the page at all, only a list of blog posts tagged 'privacy'.
    Fix: Publish a plain-language description of the site's actual data practices (cookies, logs, third-party embeds) free of legal jargon.
  • understandable: A non-expert visitor cannot learn what data is collected or why because no such information appears on the page.
    Fix: Add a visitor-friendly summary explaining what is collected, why it's collected, and who it's shared with in language accessible to non-experts.
  • necessity: The page does not include any statement limiting data collection to what is necessary.
    Fix: Add an explicit data-minimization statement to the privacy policy affirming that only data necessary to operate the site is collected.
  • proportionate: Without any description of collection practices, proportionality to the service cannot be established.
    Fix: Document each data element collected and justify how it is proportionate to the blog/shop functionality being offered.
  • retention_stated: No data retention policy is mentioned anywhere on the page.
    Fix: Add a retention section to the privacy policy stating how long each type of data is kept before deletion.
  • specific: Because no retention information is provided, there are no specific time periods to evaluate.
    Fix: Specify concrete retention durations (e.g., 'server logs retained for 30 days', 'comment data retained indefinitely unless deletion is requested').
  • no_dark_patterns: The page at /privacy shows a tag archive of posts about privacy topics rather than a privacy policy or consent mechanism, so no consent interface exists to evaluate for dark patterns.
    Fix: Publish an actual privacy policy and, if collecting personal data, implement a clear consent interface using neutral language free of manipulative framing.
  • equal_choices: No accept/reject consent choices are presented on the page, so equal prominence cannot be demonstrated.
    Fix: Add a consent banner or form that displays accept and reject options with equal visual weight, size, and styling.
  • no_forced_consent: Because no consent mechanism is visible on this page, it is impossible to confirm that consent is not bundled or forced.
    Fix: Provide granular, unbundled consent controls for distinct data purposes (e.g., analytics, marketing) that users can accept or decline independently without losing access to the site.
  • banner_present: No cookie or consent banner is visible anywhere in the page content.
    Fix: Add a visible cookie/consent banner on first visit that explains data practices and offers accept/reject controls.
  • partner_sharing_mentioned: There is no consent copy on the page and therefore no disclosure of third-party partner data sharing.
    Fix: Include explicit language in the consent banner and privacy policy disclosing any third-party partners with whom data is shared.
  • partner_count_specific: Because no partner sharing is disclosed, no specific numeric partner count is provided.
    Fix: State an exact number of third-party partners (e.g., 'shared with 12 partners') in the consent banner and link to the full list.

Provenance

  • credentials: The visible content lists works and awards but does not provide a clear biographical credentials statement on this page.
    Fix: Add a concise bio paragraph on the about page summarizing Cory Doctorow's credentials, affiliations (e.g., EFF), and professional background.

Security

Transparency

  • substantive: There is no substantive statement of purpose visible—only promotional posts and navigation elements.
    Fix: Write a detailed about-section describing the site's focus, topics covered, and why it exists beyond a tagline.
  • mission_clear: No mission or editorial approach is articulated on the visible page.
    Fix: Add an explicit mission statement outlining the editorial stance and goals of the site.
  • detail: No funding details such as amounts, percentages, or categories are provided on the page.
    Fix: Include meaningful specifics like percentage breakdowns or category-level descriptions of each funding stream.
  • complete: Without any disclosure present, there is no coverage of major funding streams.
    Fix: Publish a comprehensive disclosure enumerating all major funding streams (book royalties, speaking fees, Patreon/subscriptions, affiliate commissions, grants, etc.).
  • governance_exists: The page is a personal author site listing books and news posts with no description of any governance or editorial structure.
    Fix: Add a brief governance or editorial policy section explaining how content decisions are made on the site.
  • roles_clear: No roles or responsibilities are identified beyond Cory Doctorow as the author/poster of entries.
    Fix: Include an 'About' section identifying key roles (e.g., author, editor, webmaster) and their responsibilities.
  • algorithm_explained: The page is an author's about/news listing with no explanation of any algorithms in use.
    Fix: Add a brief disclosure describing any algorithms (e.g., for sorting posts, recommendations, or analytics) and their purpose.
  • impact_clear: No description of how algorithmic decisions might affect users (e.g., post ordering, content filtering) is provided.
    Fix: Include a short statement outlining how any automated systems influence what users see or experience on the site.
  • annual_statement: There is no evidence on the page of any regular or periodic review of data practices.
    Fix: Publish a privacy/data practices statement and commit to (and document) an annual review cycle linked from the site footer.
  • dated: No data practices statement appears on the page, so none is dated or versioned.
    Fix: Add a dated or version-numbered privacy/data practices statement accessible from the site navigation or footer.

Level 3 — Advanced

Accessibility

Accountability

  • policy_exists: The page contains no published moderation policy; it is an author's about/news page with book announcements and archives.
    Fix: Publish a clearly linked moderation policy page outlining what content is allowed on the site and in comments.
  • criteria_clear: No moderation criteria are stated anywhere on the visible page content.
    Fix: Add explicit criteria (e.g., prohibited content categories like harassment, spam, hate speech) to a dedicated moderation policy section.
  • enforcement: There is no explanation of how moderation decisions are made, appealed, or enforced on the page.
    Fix: Document the enforcement workflow including who moderates, response timelines, removal actions, and an appeals process.

Interoperability

Security

Transparency

  • criteria_published: The page does not publish any criteria used by algorithmic systems.
    Fix: Publish the specific criteria (e.g., recency, tags, popularity) used by any site algorithms in a dedicated transparency section.
  • weighting: No information about how criteria are weighted or prioritized is present.
    Fix: Document the relative weighting or priority order of each algorithmic criterion alongside the criteria list.
  • auditable: The page provides no technical or procedural detail sufficient for external audit.
    Fix: Provide an audit-ready description (or link to documentation/source) detailing inputs, logic, and outputs of any algorithms used.
  • open_source: No link to source code or any open-source repository is visible on the page.
    Fix: Add a link to a public repository (e.g., GitHub) for the site's theme or code, if available.
  • tech_docs: No technical documentation is published or linked from the page.
    Fix: Publish basic technical documentation (e.g., platform used, feed formats, licensing) and link it from the about page.

Responsibility to the Future