Accessibility audits for mobile apps

No opinions. Evidence.

Evidence-based accessibility audits for mobile apps. Every finding carries the measurement that produced it, mapped to WCAG 2.2 and EN 301 549 — and every check we could not run is published as a gap, never as a pass.

Listing not live yet — what a credit costs Explore the sample report

$149.99 per audit · No account required · See the full output before you buy

The sample report — what one audit hands back:

499
checks run 257 pass · 53 fail · 110 n/a · 79 not testable
20
findings every one carrying the measurement that produced it
1/9/10
critical / major / minor at 84.2% coverage

A real finding — not a screenshot

AP-DYN-001 CRITICAL Critical severity

1 control is drawn off the screen at the largest text size

Evidence

xxl-font · Onboarding step runs/bd1bf437/t2/xxl-font/iphone-17-pro/r1/step-00.png

Screenshot from the audited build, unedited. SuppLab is our own app — see the build digest above to check the artifact this frame came out of.

bottom_pt
1046.3
clipped
4
elements
'Get Started'
fixed_elements
7
screen_height_pt
874

Reproduced in 3 of 3 attempts

Seen on 1 of 1 recorded states of this screen

Three layers. One report. Nothing of yours left behind.

Every automated finding comes from a deterministic rule that cannot hallucinate, and the 7 rules a person measures arrive with the device recording that produced them. What is still a commitment is the agent executing those task rules instead of a human — marked as such below rather than described as if it had already run.

  1. 01 Your side

    You upload one file

    Your app built for the iOS Simulator and zipped — not an .ipa. The Mac app refuses the wrong file type in front of you.

    no account · no repository access

  2. 02 Layer 1 · deterministic

    Rules measure it

    Missing labels, labels that hide their visible text, controls with no role, unlabelled fields, targets under 44pt, reading order — measured, with the value found and the value required.

    14 automated rules + 7 on a recorded device pass · WCAG 2.2 · EN 301 549 · no model in any finding

  3. 03 Layer 2 · agent

    An agent uses itPlanned

    Built to drive your app across tasks and environments so a failure arrives as a recording, not as a claim. 7 of the layer's 9 rules are active and appear in reports today — performed by a person on a recorded device, not by the agent. Agent execution is what is planned here.

    evidence policy: failure frame only

  4. 04 Layer 3 · human

    A person confirms it

    A person performs 7 of the active rules on a physical device with VoiceOver on and the screen recorded, and the recording ships with the report. What cannot be reached is published as not testable, never as a pass.

    not_testable is never silent

  5. 05 Your side

    You get one report

    Every finding with its evidence, the severity mix, and a coverage percentage that is never folded into it.

    48h target · no 0-100 score until it can be explained

Then, on retention window elapsed — 14 days after your report:

Destroyed

  • build binary
  • screen recordings
  • screenshot originals
  • demo credentials
  • notification email address

Kept

  • normalized finding rows
  • score
  • coverage
  • audit metadata
  • audit id

The window exists for one declared purpose — free re-runs and support — and you can end it from the app at any moment; every deletion, ours or yours, produces a signed record you can check. A run we could not complete holds your build for 72 hours instead, so you can attach a fixed one to the same audit, then deletes it too. What stays is the measurement — it is linked to your audit, so it is pseudonymous rather than anonymous, and it is what lets a second audit tell you which findings you actually fixed. The full retention rules →

Two doors into the same requirement

EAA · Europe

You sell to the EU

The European Accessibility Act has applied since June 2025. It reaches a listed set of services offered to EU consumers — e-commerce, consumer banking, e-books, telecoms, access to media, passenger transport and emergency communications — wherever the company itself is established. Companies under ten people that stay under the €2M ceiling are exempt as service providers. For everyone else on that list, penalties are set per country.

ADA · United States

You carry US legal risk

There is no US regulation telling a private app what to meet — Title III has no web or app rule, and the circuits disagree about whether a service with no physical place behind it is reachable at all. What does exist is a filing pattern, an appellate decision that covers an app by name, and a Title II rule with dates in it. A recorded, reproducible audit is the artifact that survives a dispute, because it is evidence rather than an opinion.

Audit Credit

$149.99

One audit — one app, one platform. Delivered within 48h.

CI MonthlyPlanned

$99.99/mo

2 audits/month + a regression diff on every build.

AgencyPlanned

$299.99/mo

5 apps · white-label PDF export.

Questions

Is this a compliance certificate?

No. It is a technical readiness assessment — a measured, reproducible view of where your app stands against WCAG 2.2 and EN 301 549. It is not legal advice, and we never claim certification.

How the assessment is produced

Why not just run Lighthouse or axe?

Those are excellent for a web DOM. They cannot install and drive your iOS app, turn on VoiceOver, or record a checkout that traps a screen-reader user. Closing that gap is what this product is built around. What ships today is the deterministic layer — 14 rules measured against the accessibility tree your build exposes — plus 7 task rules a person runs on a physical device with VoiceOver on and the screen recorded. The report names the method behind every row, so you always know which one you are reading, and a row nobody measured says so instead of passing.

The honest comparison table

What exactly do I send you?

One artifact: your app built for the iOS Simulator and zipped — what xcodebuild -sdk iphonesimulator produces, not an .ipa. The app shows you the command and refuses the wrong file type in front of you, not two days later. If you would rather run one thing than assemble two, our packaging script is public on GitHub as readyaudit-package: about a hundred lines of bash, MIT, no network calls, meant to be read before it is run.

What if the build cannot be opened?

You attach a fixed one to the same audit — up to twice, within 72 hours, at no further cost. Being straight about the other half: the credit is spent when we accept the build, and a failed run does not return it, so what we give you is the attempts rather than a refund we have no mechanism to make. Failures on our side are re-run automatically and do not use up those attempts.

Refund and credit policy

What happens to my build and recordings?

They run on isolated simulators. Your build and the run's recordings are kept for 14 days after your report is delivered — for free re-runs and support, nothing else — and are then destroyed automatically. You can have them destroyed sooner at any time, and every destruction produces a signed record you can check. The visual evidence is embedded in the report itself, and once the window closes we keep no copy of it. What we do keep is the measurement: the finding rows, the score and the coverage. That is what lets a later audit tell you which findings you fixed, and it is linked to your audit, so it is pseudonymous rather than anonymous. Only the benchmark projection is de-identified, and you can have either the benchmark inclusion or the whole record dropped by asking.

Privacy policy

All questions, including the ones about what this cannot do →

Audit your app. Keep the evidence.

Listing not live yet — what a credit costsHow it works