National Trust
https://www.nationaltrust.org.uk · 33/92 checks passed · not_for_profit
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 24/37 (13 failed) |
| Level 2 — Enhanced | 3/27 (24 failed) |
| Level 3 — Advanced | 1/10 (8 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 10/13 |
| Accountability | 0/5 |
| AI & Automation | 3/8 |
| Interoperability | 1/3 |
| Privacy | 8/16 |
| Provenance | 0/2 |
| Security | 4/11 |
| Transparency | 2/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
- 1 WCAG 2.1 Level A violation reported by axe-core: aria-allowed-attr.
- 1 WCAG 2.1 Level A violation reported by axe-core: aria-allowed-attr.
AI & Automation
-
human_or_disclosed: The page only displays a browser verification interstitial with no substantive content, so authorship (human or AI) cannot be determined or disclosed.
Fix: Ensure the actual page content loads for reviewers/crawlers and include a clear statement of authorship or AI-use disclosure on the about page.
-
policy_exists: The page only displays a browser verification message with no AI policy content visible.
Fix: Publish an accessible AI use policy at /ai-policy that loads without requiring browser verification gating or ensure the policy content is reachable to users and crawlers.
-
scope_clear: No AI usage scope is described because the page content is blocked behind a verification screen.
Fix: Provide clear text on the page explaining what AI tools are used for across the organisation's services.
Privacy
- Detected 2 data-leaking services across 1 category: google fonts (fonts.googleapis.com, fonts.gstatic.com).
PASS
Session cookies only
PASS
No tracking pixels
Security
FAIL
HTTPS enforced
- strict-transport-security: header not set on the response.
- Redirect chain (1 hops): https://www.nationaltrust.org.uk
- x-frame-options: header not set on the response.
- content-security-policy: header not set on the response.
- referrer-policy: header not set on the response.
PASS
No mixed content
Transparency
-
contact_exists: The page only shows a browser verification message with an incident ID, so no contact page content is visible.
Fix: Ensure the /contact page renders actual contact information rather than being blocked by a browser verification interstitial.
-
findable: No contact details are rendered on the page; only a verification screen is displayed.
Fix: Allow the contact page to load for all legitimate visitors and surface phone, email, and address details prominently.
-
actionable: There is no phone number, email, form, or address provided—only a verification message.
Fix: Provide actionable contact methods (such as a phone number, email address, or contact form) directly on the contact page.
-
about_exists: The /about URL returns only a browser verification screen, not an actual about page.
Fix: Resolve the bot-check blocking issue so the about page content is reachable to users and reviewers.
-
purpose_clear: No statement of purpose is present because only the verification message is shown.
Fix: Display a clear statement of the National Trust's purpose at the top of the about page once accessible.
-
disclosure_exists: The page only shows a browser verification screen with no funding or sponsorship disclosure content visible.
Fix: Ensure the /funding page loads actual content with a clear funding/sponsorship disclosure section accessible to reviewers and users.
-
transparent: No funding sources are identified because only a browser verification message is present.
Fix: Publish a transparent list of funding sources (grants, donors, government support, commercial income) on the funding page.
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
named_person: The page only shows a browser verification message with no named person or role identified as responsible.
Fix: Once past the verification screen, ensure the contact page lists a named individual, team, or role responsible for handling enquiries.
-
contactable: No contact details (email, phone, form, or address) are visible; the page only displays a browser verification notice.
Fix: Provide accessible contact information such as an email address, phone number, or contact form directly on the page.
-
response_timeframe: The page only shows a browser verification message with no content about response timeframes.
Fix: Publish explicit acknowledgement and resolution timeframes for complaints once the page loads its actual content.
-
specific: No timeframes are visible at all, so specificity cannot be demonstrated.
Fix: State specific day-based targets (e.g. acknowledge within 3 working days, respond within 20) on the complaints page.
-
process_exists: The page displays only a browser verification screen with an incident ID and no complaints process content.
Fix: Ensure the /complaints page is accessible to users and publish a documented complaints or feedback process.
-
steps_clear: No complaint steps are visible because the page content is blocked by a verification screen.
Fix: Provide clearly numbered steps (how to submit, what happens next, escalation routes) on the accessible complaints page.
-
appeals_exists: The page only shows a browser verification challenge with an incident ID and no documented appeals process content is visible.
Fix: Publish a dedicated appeals page describing the steps, timelines, and contact methods for submitting an appeal.
-
independent: No information about independent review or escalation pathways is present on the page, which displays only a browser verification notice.
Fix: Document an independent reviewer or external escalation route (e.g., ombudsman or independent panel) within the appeals process.
AI & Automation
-
detailed_scope: The page shows only a verification notice and contains no detailed scope of AI use.
Fix: Add a detailed section listing specific AI applications, use cases, and business areas where AI is deployed.
-
limitations: No acknowledgement of AI limitations is present on the accessible page content.
Fix: Include a section that openly describes known limitations, risks, and failure modes of the AI systems used.
-
safeguards: No safeguards or quality controls are described because the policy content is not visible.
Fix: Document the human oversight, review processes, and quality assurance measures applied to AI outputs on the policy page.
-
marking_policy: The page only shows a browser verification message with no AI content marking policy visible.
Fix: Publish the AI policy content on the page describing how AI-assisted content is labeled and disclosed.
-
consistent: No AI content marking is visible because the page content is blocked by a browser verification screen.
Fix: Ensure the AI policy page is accessible and demonstrates consistent labeling conventions across AI-assisted content.
-
oversight_exists: Human oversight of AI outputs is not documented on the accessible page content.
Fix: Add a section explicitly describing how humans oversee and validate AI outputs before publication.
-
review_process: No review or approval process is described on the visible page.
Fix: Document the step-by-step review/approval workflow for AI-generated content on the policy page.
-
accountability: No accountable party or role is named for AI-generated content on the visible page.
Fix: Name a specific role, team, or contact accountable for AI-generated content within the policy.
Interoperability
- No RSS/Atom feeds discovered.
-
open_formats: The page only shows a browser verification challenge with no actual HTML content delivered.
Fix: Ensure the about page content is served as accessible HTML rather than being blocked behind an unresolved bot-check interstitial.
-
no_proprietary_lock: Access requires passing a proprietary browser verification script before any content is shown.
Fix: Provide a fallback or progressive enhancement so content is reachable without executing proprietary verification scripts.
Privacy
-
exists: The page only shows a browser verification/challenge screen with no privacy policy content visible.
Fix: Ensure the /privacy URL serves the actual privacy policy content to reviewers and bots, or allow-list compliance crawlers past the bot challenge.
-
plain_language: No policy text is accessible to evaluate language clarity due to the verification interstitial.
Fix: Publish the privacy policy in plain English and make it reachable without a browser challenge blocking access.
-
comprehensive: No content about data collection or purposes is present on the page.
Fix: Provide a full policy covering categories of data collected, purposes, legal bases, sharing, and rights on this URL.
-
plain_language: No data-practice descriptions are visible because the page is stuck on a verification screen.
Fix: Make the privacy page content render for all visitors and write data practices in jargon-free language.
-
understandable: A non-expert cannot understand data practices when no text is shown.
Fix: Include clear, user-friendly explanations of what is collected and why, accessible without passing a bot challenge.
-
necessity: The page contains no statement about limiting data collection to what is necessary.
Fix: Add an explicit data minimisation statement confirming only necessary data is collected.
-
proportionate: No information is available to assess proportionality of data collection.
Fix: Describe each data collection purpose and justify that the data gathered is proportionate to the service.
-
retention_stated: No retention information appears on the verification page.
Fix: Publish a retention schedule within the privacy policy explaining how long each data type is kept.
-
specific: With no retention content visible, specific periods cannot be confirmed.
Fix: State concrete retention durations (e.g., '24 months after last activity') rather than vague terms like 'as long as necessary'.
-
no_dark_patterns: The page displays only a browser verification challenge with no visible consent interface, so dark-pattern-free consent cannot be confirmed.
Fix: Ensure the privacy page is accessible to reviewers and presents consent choices in neutral, non-manipulative language.
-
equal_choices: No accept or reject options are visible on the page, as it only shows a browser verification screen.
Fix: Provide accessible accept and reject buttons of equal visual prominence on the privacy/consent interface.
-
no_forced_consent: The page is blocked by a verification challenge and shows no consent interface, preventing confirmation that consent is not bundled or forced.
Fix: Make the privacy page reachable and ensure consent is granular and not a precondition for accessing the site.
-
ads_labelled: The page only shows a browser verification challenge, so no advertising or sponsored content labelling is visible.
Fix: Ensure the actual content loads for reviewers and clearly label any advertising or sponsored content with visible tags such as 'Ad' or 'Sponsored'.
-
disclosure: The page displays a verification interstitial with no disclosure of any advertiser relationships.
Fix: Publish an accessible disclosure statement describing any commercial or advertiser relationships on the site.
-
partner_sharing_mentioned: The banner only mentions 'embedded third party tools (such as video and audio players)' but does not disclose data sharing with third-party partners for marketing or analytics purposes.
Fix: Update the banner copy to explicitly disclose that cookies may share data with third-party advertising, analytics, and marketing partners.
-
partner_count_specific: No specific numeric count of third-party partners is stated anywhere in the banner copy.
Fix: Add a specific partner count (e.g., 'We share data with X partners') in the banner or link to a vendor list that states the exact number.
Provenance
- No author or date metadata found on the page.
-
authorship_clear: The verification interstitial contains no information about who creates or curates the content.
Fix: Once the page loads, clearly identify the National Trust team or department responsible for the about content.
-
credentials: No author credentials or organisational background are visible on the verification page.
Fix: Include organisational background and credentials of contributors on the about page itself.
Security
Transparency
-
named_person: The page content does not identify any named individual or team responsible for enquiries, only a browser verification message.
Fix: Publish the name of the responsible individual or team (e.g., Customer Service Team) on the contact page.
-
role_clear: No role or authority is stated because the page displays only a verification challenge.
Fix: Clearly describe the role, remit, or authority of the contact person or team (e.g., scope of enquiries they handle).
-
substantive: There is no substantive content visible—only a verification interstitial.
Fix: Publish a detailed purpose statement on the about page beyond a tagline, covering scope and activities.
-
mission_clear: No mission or editorial approach is articulated on the served page.
Fix: Add a clearly written mission statement describing the National Trust's conservation and editorial approach.
-
detail: No details such as amounts, percentages, or categories of funding appear on the page.
Fix: Include specific figures or percentage breakdowns by funding category (e.g., memberships, legacies, grants, commercial).
-
complete: Without any disclosure content loaded, coverage of major funding streams cannot be demonstrated.
Fix: Provide a comprehensive disclosure covering all major funding streams, ideally linking to the latest annual report.
-
governance_exists: The page only displays a browser verification challenge with no governance or editorial structure content visible.
Fix: Ensure the /about page renders actual content describing the organisation's governance structure rather than a bot-check interstitial.
-
roles_clear: No roles or responsibilities are identified because the page content is blocked by a browser verification screen.
Fix: Publish accessible content identifying key leadership roles and responsibilities, and ensure crawlers/reviewers can reach it without being blocked.
-
algorithm_explained: The page only displays a browser verification challenge with no content explaining any algorithms in use.
Fix: Ensure the actual About page content loads and include a section describing any algorithms used and their purposes.
-
impact_clear: No information about algorithmic decisions or their impact on users is visible on the page.
Fix: Publish a description of how algorithmic decisions affect users on the accessible About page.
-
annual_statement: The content shown is only a browser-verification message with no evidence of a periodic data practices review.
Fix: Publish a privacy/data practices page that references an annual or periodic review cycle and ensure it is reachable by crawlers.
-
dated: No data practices statement or version/date information is present on the verification page.
Fix: Include a 'Last updated' date or version number at the top of the data practices/privacy statement.
Level 3 — Advanced
Accessibility
-
statement_exists: The page only displays a browser verification interstitial ('Verifying your browser before proceeding...') with no accessibility statement content.
Fix: Ensure the actual /about content loads for reviewers and provide a dedicated, linkable accessibility statement page.
-
known_issues: No accessibility content is present because the page is blocked by a browser-verification screen, so no known issues are acknowledged.
Fix: Publish an accessibility statement that lists known accessibility limitations and non-conformances of the site.
-
remediation_timeline: The interstitial page contains no timeline or commitment to fix any accessibility issues.
Fix: Include target dates or a commitment schedule for remediating identified accessibility issues in the statement.
-
feedback_channel: No feedback mechanism or response commitment is shown on the verification-only page.
Fix: Add a feedback channel (email or form) for accessibility problems along with a stated response timeframe.
Accountability
-
policy_exists: The page only displays a browser verification message and incident ID, with no moderation policies published.
Fix: Publish a clear moderation policy document accessible at this URL or link to one from the moderation page.
-
criteria_clear: No moderation criteria are stated on the page; it only shows a browser verification interstitial.
Fix: Add a section that clearly lists the criteria used to moderate content, such as prohibited behaviors and content types.
-
enforcement: There is no explanation of the enforcement process, only a verification notice and incident ID.
Fix: Document the enforcement workflow, including actions taken, appeal rights, and response timelines, directly on the moderation page.
Interoperability
Security
-
plan_exists: The page only shows a browser verification/security interstitial with an incident ID and contains no published incident response plan or policy.
Fix: Publish an accessible incident response plan or security policy page outlining how incidents are detected, managed, and resolved.
-
notification_commitment: The interstitial content includes no commitment to publicly notify users of significant security incidents.
Fix: Add a clear statement committing to public notification of affected users when significant incidents occur.
-
timeframe: No disclosure timeframe is mentioned anywhere on the browser-verification page.
Fix: Specify a concrete timeframe (e.g., within 72 hours of discovery) for disclosing incidents to affected users.
Skipped: Target page not found in captured content
Transparency
-
criteria_published: The page shows only a verification screen and does not publish any decision criteria.
Fix: Make the About page accessible and list the specific criteria used in any algorithmic decisions.
-
weighting: No weighting or prioritisation of criteria is provided on the visible content.
Fix: Add an explanation of how criteria are weighted or prioritised in algorithmic decisions.
-
auditable: The verification placeholder provides no detail that would support external audit or review.
Fix: Publish sufficiently detailed algorithm documentation (inputs, logic, outcomes) to enable independent review.
-
open_source: No links to source code repositories appear on the verification page.
Fix: Link to any publicly available source code repositories from the about or developer section of the site.
-
tech_docs: No technical documentation is referenced or linked from the displayed content.
Fix: Publish and link to technical documentation (e.g., API docs, platform info) from the about page.
Responsibility to the Future
-
disclosure_exists: The page only shows a browser verification/security interstitial ('Verifying your browser before proceeding...') with no accessible content or sustainability disclosure.
Fix: Ensure the actual /about page content loads for reviewers and publish an environmental impact or sustainability disclosure on an accessible page.
-
specific_metrics: No specific figures on carbon, energy use, or emissions are present because only a browser verification message is displayed.
Fix: Include concrete quantified metrics such as annual carbon emissions, energy consumption, and reduction targets in the disclosure.
-
hosting_disclosure: There is no information about the carbon or energy profile of hosting infrastructure, as the page content is inaccessible behind a verification screen.
Fix: Disclose your hosting provider's carbon/energy profile, such as use of renewable-powered or green-certified data centers, on the accessible site content.
-
plan_exists: The governance page describes organisational structure, constitution, and the Governance Handbook, but contains no published plan for what happens if the organisation fails or exits.
Fix: Publish a continuity or wind-down plan that describes what would happen to the organisation's activities and assets in the event of failure or dissolution.
-
data_and_content_fate: The page makes no mention of what would happen to user data or published content should the Trust cease operating.
Fix: Add a section specifying how user data and published content would be preserved, transferred, or deleted in a wind-down scenario.
-
custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the governance page.
Fix: Name specific custodians, mirror sites, or archive partners (e.g., a national archive) responsible for safeguarding content and data if the organisation exits.
-
policy_exists: The page is an 'About us' overview that references a Modern slavery statement and a Gender and Diversity Pay Gap Report but contains no published policy dedicated to worker wellbeing or working conditions.
Fix: Publish a dedicated worker wellbeing/working conditions policy and link to it from this page or the careers/jobs section.
-
specific_commitments: The content mentions inclusion, diversity and safeguarding generally but states no specific commitments on pay, hours, mental health, or benefits for workers.
Fix: Add concrete, measurable commitments on fair pay, working hours, mental health support, and employee benefits.
-
accountability: While the page lists governance bodies like the Executive Team and Board of Trustees, none are identified as accountable specifically for worker conditions or wellbeing.
Fix: Name a specific role or body (e.g., an HR/People Director or committee) responsible for overseeing worker wellbeing and working conditions.