dotpublic.org
https://dotpublic.org · 41/74 checks passed
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 29/37 (8 failed) |
| Level 2 — Enhanced | 12/27 (15 failed) |
| Level 3 — Advanced | 0/10 (8 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 10/13 |
| Accountability | 1/5 |
| AI & Automation | 2/8 |
| Interoperability | 1/3 |
| Privacy | 13/16 |
| Provenance | 2/2 |
| Security | 5/11 |
| Transparency | 7/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
- 1 colour-contrast violation reported by axe-core (text below 4.5:1).
AI & Automation
- robots.txt does not reference any known AI crawlers.
- Not found at any of: /ai-policy, /ai.
-
policy_exists: The about page contains no AI use policy or statement, only descriptions of the team and research programme.
Fix: Publish a dedicated AI use policy or statement, linked from the site navigation or footer.
-
scope_clear: The page never explains any use of AI, so the scope of AI use is undefined even though AI ethics is mentioned as an advisory topic.
Fix: Add a section describing whether and how AI is used in the programme's work and outputs.
Privacy
PASS
Session cookies only
PASS
No tracking pixels
Security
- x-frame-options: header not set on the response.
- content-security-policy: header not set on the response.
- referrer-policy: header not set on the response.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
response_timeframe: The contact page only provides an email address with no mention of when a response can be expected.
Fix: Add a stated response timeframe near the contact email, such as 'We aim to respond within 5 business days.'
-
specific: No timeframe of any kind is published, so no specific duration is given.
Fix: Publish a specific numeric timeframe (e.g. 'within 3 working days') rather than vague wording.
-
process_exists: The page offers only a general 'Email info@dotpublic.org' invitation with no documented complaints or feedback process.
Fix: Create and link a dedicated complaints/feedback procedure describing how issues are received and handled.
-
steps_clear: Because no complaints process is documented, there are no steps for a user to follow.
Fix: List clear, numbered steps for submitting a complaint, including where to send it and what happens next.
-
appeals_exists: The contact page only provides an email address and company registration details, with no documented appeals process.
Fix: Add a dedicated section or page describing how users can formally appeal decisions, including required steps and timelines.
-
independent: There is no appeals process described, so no independent or escalated review mechanism is present.
Fix: Document an escalation path that routes appeals to an independent reviewer or body separate from the original decision-maker.
AI & Automation
-
marking_policy: The page contains no policy or statement about how AI-assisted content is marked or labelled.
Fix: Add a clear policy explaining whether and how AI-assisted content is identified and labelled across the site.
-
consistent: With no AI content marking policy present, there is no evidence of consistent application of AI labelling.
Fix: Once a marking policy is established, apply AI-content labels uniformly to all relevant articles and pages, including the Voices and News updates.
-
oversight_exists: The page documents no human oversight process for any AI-generated or AI-assisted outputs.
Fix: Publish a statement describing how humans review and oversee any AI outputs used in the programme's work or content.
-
review_process: No review or approval workflow for AI content is described anywhere on the page.
Fix: Document a concrete review or approval process, specifying who checks AI outputs before publication and against what criteria.
-
accountability: Although editorial roles like 'Editorial voice and direction' and 'Editor' are listed, no individual is named as accountable for AI-generated content specifically.
Fix: Explicitly assign and name an individual or role responsible and accountable for AI-generated content.
-
detailed_scope: No AI policy exists on the page, so there is no detailed scope of AI use.
Fix: Create an AI policy that specifies the exact tasks, tools, and contexts in which AI is used.
-
limitations: The page does not acknowledge any limitations of AI systems.
Fix: Add a statement acknowledging the known limitations and risks of any AI systems employed.
-
safeguards: No safeguards or quality controls related to AI are described anywhere on the page.
Fix: Describe the human oversight, review processes, and quality controls applied to any AI use.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
equal_choices: The policy describes consent as the lawful basis for newsletter signup but the page shows no accept/reject controls, so equal prominence of choices cannot be demonstrated.
Fix: Add or reference a consent mechanism (e.g., newsletter opt-in and clearly equivalent decline/unsubscribe options) with equally prominent accept and reject controls.
-
banner_present: The page content shows no cookie or consent banner anywhere on the page.
Fix: Add a visible cookie/consent banner that appears on page load to inform users about cookie usage.
-
partner_sharing_mentioned: There is no banner or on-page consent copy, and no disclosure of data sharing with third-party partners is present.
Fix: Include explicit consent copy disclosing whether and how user data is shared with third-party partners.
-
partner_count_specific: No partner sharing is disclosed, so no specific numeric count of partners is stated anywhere on the page.
Fix: If partners receive data, state the exact number of partners (e.g., 'shared with X partners') in the consent disclosure.
-
necessity: The policy never explicitly states that data collection is limited to what is necessary or minimized.
Fix: Add a short data-minimization statement affirming that only data necessary for each stated purpose is collected.
Provenance
Security
- security.txt not published.
Transparency
-
role_clear: The page only labels Zelda Rhiando as 'Edited by' without stating her role, title, or authority for handling enquiries.
Fix: Add a clear role or title for the responsible person (e.g., 'Zelda Rhiando, Project Lead') and specify who handles enquiries sent to info@dotpublic.org.
-
annual_statement: The page shows an editorial 'Last updated' date but provides no evidence of any regular or periodic review of data practices.
Fix: Publish a linked privacy statement that documents a scheduled annual or periodic review of data practices and note the date of the most recent review.
-
dated: The page links to a 'Privacy' page but this about page contains no dated or versioned data practices statement, only an editorial 'Last updated 18 August 2026' note for the content itself.
Fix: Add a clearly dated or version-numbered data practices/privacy statement (or surface that date on this page) so users can see when it was last revised.
-
detail: The disclosure describes funding only in vague categories ('subsistence funds', 'application fee') without amounts or percentages.
Fix: Add specific figures or percentage breakdowns for each contribution, such as the actual amount of the subsistence funds and application fee.
-
complete: The page references seeking additional funding and Open Collective donations but does not disclose those donation totals or any current ongoing income streams, leaving major streams uncovered.
Fix: Include all funding streams such as total Open Collective donations received and any other current or pending grants to give a complete picture.
-
algorithm_explained: The about page describes the organisation, team, and mission but does not mention or explain any algorithms or their purpose.
Fix: If the site uses any algorithms, add a section explaining what each algorithm does and why it is used.
-
impact_clear: The page contains no description of any algorithmic decisions or how they affect users.
Fix: Document any algorithmic decisions and clearly describe their impact on users, or state explicitly that no such decisions are made.
Level 3 — Advanced
Accessibility
-
known_issues: The statement claims full WCAG 2.2 AA compliance and states 'We are not currently aware of any accessibility issues,' acknowledging no limitations.
Fix: List any known accessibility issues or non-accessible content, or clearly explain how users can report problems if none are currently known after thorough testing.
-
remediation_timeline: Because no known issues are acknowledged, there is no timeline or commitment for fixing accessibility problems.
Fix: Add a section committing to fix identified issues within a stated timeframe once any are found or reported.
Accountability
-
policy_exists: The terms page covers privacy, copyright, and data rights but publishes no content moderation policy.
Fix: Add a dedicated moderation policy section describing what user-generated or submitted content is permitted and prohibited.
-
criteria_clear: No moderation criteria are stated anywhere on the page defining what content would be removed or restricted.
Fix: Clearly list the specific criteria (e.g. prohibited content types, standards for acceptable submissions) used to make moderation decisions.
-
enforcement: The page explains no enforcement process for moderation, such as review steps, actions taken, or appeals.
Fix: Describe the enforcement workflow, including how violations are identified, what actions result, and how users can appeal decisions.
Interoperability
- Not found at: /status
Security
Skipped: Target page not found in captured content
Transparency
-
open_source: The page mentions engineering and architecture roles but provides no link to publicly available source code or a code repository.
Fix: Add a visible link to a public code repository (e.g., GitHub) where the project's source code can be reviewed.
-
tech_docs: No technical documentation or link to it is published on the page despite references to protocols, infrastructure, and standards work.
Fix: Publish and link to technical documentation covering the standards, protocols, and architecture the programme is developing.
-
criteria_published: No specific criteria for any algorithmic decision are published anywhere on the page.
Fix: Publish the concrete criteria used in any algorithmic decisions, or confirm that none are in use.
-
weighting: The page provides no information about the weighting or priority of any decision criteria.
Fix: Explain how any decision criteria are weighted or prioritised relative to one another.
-
auditable: The page offers no technical detail that would enable an external audit of any algorithmic process.
Fix: Provide sufficient methodological and technical detail (or link to documentation) to allow independent external review of any algorithms used.
Responsibility to the Future
-
disclosure_exists: The About page describes the programme's team, partners, and mission but contains no published environmental impact or sustainability disclosure.
Fix: Publish a dedicated sustainability or environmental impact statement describing the programme's environmental commitments and footprint.
-
specific_metrics: The page provides no specific figures for carbon emissions, energy use, or other environmental metrics.
Fix: Include concrete measured figures such as annual carbon emissions or energy consumption in a sustainability disclosure.
-
hosting_disclosure: There is no mention of the carbon or energy profile of the hosting infrastructure anywhere on the page.
Fix: Disclose the hosting provider's energy sources and the carbon or energy profile of the infrastructure serving the site.
-
plan_exists: The about page describes team structure, governance, and mission but contains no published plan for what happens if the organisation fails or exits.
Fix: Publish a succession or wind-down plan describing what would happen to the programme, domain, and standards if dotPublic ceases operations.
-
data_and_content_fate: The page does not address what would happen to user data or published content in the event of organisational failure or exit.
Fix: Add an explicit statement covering how user data and published content would be preserved, transferred, or deleted if the organisation ceases to operate.
-
custodians_or_mirrors: While Trinity College Dublin and Sense about Science are named as partners, no custodians, mirrors, or archive partners are identified for preserving assets after an exit.
Fix: Name specific custodians, mirror sites, or archive partners (e.g., a library or archive) committed to safeguarding content and data should the organisation close.
-
policy_exists: The page is a team/people directory listing bios and contains no published policy on worker wellbeing or working conditions.
Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the site.
-
specific_commitments: No specific commitments on pay, hours, mental health, or benefits appear anywhere on this bios page.
Fix: Add concrete, measurable commitments covering pay, working hours, mental health support, and benefits within a wellbeing policy.
-
accountability: The page names team members and their roles but assigns no accountability or oversight for worker conditions.
Fix: Designate a named role or committee responsible for overseeing worker conditions and state this in the policy.