Trust · from the assurance pack
Accessibility conformance
Published from docs/assurance/vpat.md as it ships with the software: the same text an auditor receives. A reference to another document of the pack or to a runbook is named, not linked; they ship beside it.
Scope: the VX Drive web application. Basis for claims: the UI is built on the GOV.UK Design System's markup and interaction patterns (one of the most accessibility-audited component sets in production anywhere), with app-specific behaviors listed below. Status: self-assessment; an external audit converts "Supports (self-assessed)" to "Supports (verified)" per the certification roadmap.
Product behaviors relevant to conformance
- Semantic landmarks (
header/nav/main/footer), skip link, focus handed tomainon SPA navigation with outline suppressed only for programmatic focus. - All forms: visible labels, hints, and error summaries that receive focus and link to the offending field (GOV.UK error pattern).
- Keyboard: every interactive element reachable and operable; disclosure menus close on Escape and outside click; no keyboard traps.
- Status information (tags, notification banners) conveyed in text, not color alone;
role="alert"on error summaries; success banners take focus. - Responsive to 400% zoom / 320px reflow per the project's layout rules (em-based breakpoints, no fixed heights, wrap-capable rows).
- Native theme respects
prefers-color-scheme; GOV.UK palette meets AA contrast. - Every table carries an accessible name; long lists page with Previous/Next links (keyset pages), never infinite scroll; selection in a table is a checkbox per row with a visually hidden label naming the row.
- Drawings and overlays have a text equivalent that is the real control: the connections
graph has a list with the same content; the page viewer's highlights and the redaction
screen's marks are
aria-hiddenand mirrored by a list of hits or of marks (each mark a row with its page, coordinates, reason and status, nudged and resized by keyboard); a forensic heat-map isaria-hiddenwith its regions written out beside it. - Two recorded exceptions to one-column GOV.UK pages (ADR-0016 decision 9): the
discovery review screen is two panes from 1100 px (the document beside its coding form)
and one column below 769 px or at 200 % text, with
scroll-paddingso focus is never under the sticky form, hotkeys that every button duplicates and a switch that turns them off; the redaction screen marks a region by two clicks or by Find on this page and Mark every match (marking by keyboard alone), with the list of marks as the control. - Regulated features are switched on through an interruption-style page (warning text, the notice as body text, one button that names the act), never a modal or a checkbox.
How the claims are checked
- Automated, every commit: the browser suite (
apps/web/e2e,docs/runbooks/testing.md) runs axe-core with the WCAG 2.0/2.1/2.2 A and AA rule sets, with an empty allowlist — any violation fails the merge gate — on twenty-three pages ina11y.spec.ts(the documents page and the front door, capture and scan jobs, search results, workspaces, retention, processing, the Settings index and its About, Ask, Modules, Integrity, Known files, Backups, Forensics, Processing, Scanners and Ingestion sources pages, Activity indicators, Your account, a document's page and its connections explorer) and, inside the scenarios that reach them, on every other page the product has: the sign-in page, the Modules switch and notice pages, the workspace page with its Evidence, Custodians, Court bundles and Legal discovery sections, a bundle, a matter and its import, fields, documents, review, redaction, QC, recall and output-set pages, an evidence item, an analysis with its heat-maps, a forensic image with its files and timeline, the keychain and AI-provider pages, the Backups page before and after a snapshot, the Licence page before and after an install, the locked page of an instance without a licence and that instance's sign-in page — 118 axe passes in all (counted on 2026-09-28 from the specs' calls, with the walk's twenty-three pages expanded: 115 in the main run and 3 in the core-only run, which repeats three of them with every module locked off). The same suite walks the skip link, focus hand-off on navigation, the account and sign-out disclosures, form validation with the error summary, the connections list by keyboard alone, a review batch by keyboard alone (Tab, digits,s), and the review screen at 1280 px and at 360 px with 200 % text. - Manual, per release: keyboard-only and screen-reader passes on new pages; 200% text and 320 px reflow per the project's layout rules.
- External audit: converts self-assessed rows below to verified ones.
The vendor's site and portal (ADR-0027)
The public site at vertexlake.com and the customer and administration areas are checked the
same way: every page the vendor browser suite lands on (vendor/web/e2e: the site's twenty
pages including the five assurance documents published under /trust, the checkout's
completion page, the sign-in and signup pages, the account's pages and the administration's —
since 2026-09-26 a separate bundle on a host of its own (the platform's default name, not published under the vendor's domain), built from the same
components and stylesheets as the account application, ADR-0031)
runs axe-core with the same WCAG 2.0/2.1/2.2 A and AA rule sets and an empty allowlist; every
site page and the account's key pages are also held to the reflow rule at 320 or 360 px and
200 % text; the site reads without JavaScript; the menu is a native disclosure; the home
page's rotating audience panel and its stop mechanisms are described in the accessibility
statement at /accessibility (ADR-0030 §4).
Table skeleton (per criterion, to be completed by the external audit)
| WCAG 2.2 criterion (A/AA) | Conformance | Remarks |
|---|---|---|
| 1.1.1 Non-text content | Supports (self-assessed) | Page thumbnails carry alt text; decorative SVGs are aria-hidden |
| 1.3.1 Info and relationships | Supports (self-assessed) | GDS markup; tables with scoped headers; summary lists as dl |
| 1.4.3 Contrast (minimum) | Supports (self-assessed) | GOV.UK palette |
| 1.4.10 Reflow | Supports (self-assessed) | Project layout rules; the browser suite asserts no horizontal scroll on the documents page at 200% text on a 360px viewport |
| 2.1.1 Keyboard | Supports (self-assessed) | Keyboard walkthroughs in the browser suite (skip link, disclosures, forms, the connections list including its pin controls and the link-target picker, a review batch coded by keyboard alone; every drawing has a list with the same content; the redaction screen marks by Find on this page and nudges by arrow keys) |
| 2.4.1 Bypass blocks | Supports (self-assessed) | Skip link is the first tab stop on load; focus moves to main on in-app navigation (checked by the suite) |
| 2.4.7 Focus visible | Supports (self-assessed) | GOV.UK focus states |
| 2.5.8 Target size (minimum) | Partially supports | Dense table action links (documents, review search, forensic image files); tracked |
| 3.3.1/3.3.3 Error identification & suggestion | Supports (self-assessed) | Error summary pattern |
| 4.1.2 Name, role, value | Supports (self-assessed) | ARIA on disclosures, expanded states as strings |
| … remaining criteria | To be completed | External audit engagement |
Known gaps under repair: the Capture page's camera panel relies on visual framing (an audio cue is planned); PDF page images depend on the searchable-PDF pipeline for text alternatives; the redaction screen's pointer path (click a word, click the last word) has no keyboard equivalent of its own — the keyboard path is Find on this page, which reaches every word the page's text layer holds but not a region of a picture; a forensic heat-map's text equivalent lists its regions and score, not the map's gradient.