{"schema_version":"1","site":"https://decosa.ai","id":"storefront-accessibility-pass","num":"89","name":"Storefront accessibility pass","tool_name":"Find accessibility fixes for a shop","short":"Storefront accessibility","blurb":"For online shops selling into the EU or the US, and the agencies that build them. A private headless browser opens the shop's pages, runs axe-core's automated WCAG 2.2 A/AA rules, tries add-to-cart and the checkout with the keyboard alone (reachable, answers Enter, focus visible, no trap), and asks an open model the questions a rule engine cannot answer: is this alt text right for this photo, is \"More\" a clear link name here, does \"Invalid input\" say how to fix the field, is the offer only inside a banner image. You get a fix list, purchase blockers first, each with its WCAG success criterion and a code fix, and a signed record of what was checked. An audit aid, not a certification; not legal advice.","status":"live","labels":{"industry":["sales-marketing","compliance-trust"],"job":["review","attest"],"input":["endpoint"],"deploy":["hosted","selfhost"],"status":"live","output":["record","data"],"data":["none"],"hardware":"gpu-96","licence":"permissive"},"industries":["sales-marketing","compliance-trust"],"runs_in":["hosted","selfhost"],"part_of":[],"built_from":["signed-record"],"models":"Qwen3.8-27B with vision (alt text against the image, text in images, link and button names, error messages) · axe-core 4.13 (MPL-2.0, automated WCAG rules) in headless Chromium","where":"Hosted or self-host","hardware":"1x RTX PRO 6000 (96 GB) for Qwen3.8-27B with its vision tower; headless Chromium and axe-core on CPU","final_artifact":"A fix list ranked by what blocks a purchase, each finding with its WCAG 2.2 success criterion, the element and a code fix, and a signed record of what was checked.","self_host_first":false,"verification":{"receipt_coverage":"partial","summary":"Receipt per model call; signed hash-chained record with the axe-core version and hash, the prompts' hashes, the pages and every finding","manual_qa":{"hosted":{"date":"2026-09-28","result":"pass","p50_ms":1847,"p95_ms":13303,"runs":6,"receipts_per_run":2,"cost_per_run_usd":0.000417},"selfhost":{"date":"2026-09-27","result":"pass","method":"Fresh clone of the branch into a clean directory, docker build of the api image with WITH_BROWSER=1, the api on host networking against the running local Qwen3.8-27B (vision, direct route); then torn down.","notes":"The rehearsal bundle passed 8 of 8 in 11 s; the three-page sample shop gave 13 findings (5 P1) and the clean shop none, receipts attested; a URL audit of a local http staging page (DECOSA_TESTRUNS_TARGETS + ALLOW_PRIVATE, 390 px) found its 6 issues with only GET requests reaching the server. The model server's own startup was not re-verified (no new GPU load)."},"known_limits":["Hosted numbers are from 6 production smoke runs after the merge: 3 on 27-28 Sep under load (10.7, 10.9, 13.3 s) and 3 on a quiet gateway on 28 Sep (1.8, 1.8, 1.8 s). Cost is the median at list price, model calls included (range $0.0004 to $0.0004).","Measured on one made-up shop template; real themes with lazy-loaded images, cookie banners and third-party widgets were not tested.","The model asks for an alt on a product photo used as a background behind real text; the page audit reports that as an advisory, not a finding.","Pages behind a login can only be audited self-hosted or pasted as HTML.","The demo console audits the sample shop and pasted HTML; live URLs need an API key and a verified domain."],"nightly_covers":null},"nightly":"https://api.decosa.ai/verify/status"},"eval_summary":{"metrics":[{"name":"Planted issues caught","value":"122 / 127","unit":null,"n":127,"split":"test","note":"17 issue types on 30 pages of four test products; axe-core 52/52, keyboard and form passes 18/18, model 52/57. Misses: two wrong alts, three links named \"Details\"."},{"name":"Clean items flagged","value":"0 / 207","unit":null,"n":207,"split":"test","note":"Good alts, clear names and labelled fields on the same pages; advisories do not count."},{"name":"Clean pages with any finding","value":"0 / 7","unit":null,"n":7,"split":"test","note":null},{"name":"Alt judgement: bad alts caught / good alts flagged","value":"111 / 113 and 0 / 38","unit":null,"n":151,"split":"test","note":"Wrong product, colour swapped, file name, vague, keyword-stuffed or empty-but-needed; colour swaps 16/18."},{"name":"Blind comparison, alt cases right: Qwen3.8 / Opus 5.5","value":"57 / 60 and 59 / 60","unit":null,"n":60,"split":"test","note":"Claude Code Opus 5.5 as a blind sub-agent with the same instructions; Qwen's 3 misses are plain background photos it wants an alt for."},{"name":"Blind comparison, planted names caught: Qwen3.8 / Opus 5.5","value":"10 / 12 and 11 / 12","unit":null,"n":12,"split":"test","note":"Both left all 28 clean names alone."},{"name":"Dev: planted caught / clean items flagged","value":"73 / 74 and 0 / 119","unit":null,"n":193,"split":"dev","note":"Prompts and empty-alt rules set here in three rounds."}],"dataset":"Harbor & Pine, a made-up shop: six invented products (2 dev, 4 test, split by product) plus home, cart and checkout pages; 50 pages with 201 planted issues of 17 types and 326 clean items; alt variants per image.","held_out":true,"caveats":["Same author built the shop, the plants, the checker and the labels; one synthetic template, no real themes.","The demo scenarios use two test-split products and were run during development; the eval pages were not.","Small n for some types: keyboard trap 2, unlinked error 2, label mismatch 1.","The frontier comparison is one blind sample of 100 cases, scored by us.","Latency was measured on a shared, loaded gateway."],"date":"2026-09-27","doc_url":"https://decosa.ai/metrics/evals/storefront-accessibility-pass"},"stack":{"summary":"A private headless Chromium opens the shop's pages and runs axe-core's automated WCAG 2.2 A and AA rules. It then tabs through the page to check that add-to-cart and the checkout can be reached and used with the keyboard, that focus is visible and that no dialog traps focus, and submits empty forms to read the error messages (it never sends a real order). Qwen3.8-27B with vision answers what a rule engine cannot: is this alt text right for this image, is a link or button name clear in context, does an error message say how to fix the field, is an offer only inside an image. Each finding comes with its WCAG success criterion, the element and a code fix, and a signed record says what was checked. For small online shops selling into the EU or the US, and the agencies that build them.","tagline":"Audit up to five pages of an online shop: automated WCAG 2.2 rules, a keyboard pass over add-to-cart and checkout, open-model judgements on alt text, names and error messages, and a fix list ranked by what blocks a purchase.","deployment":"hosted-or-self-host","regulatory_note":"An audit aid, not a certification or a statement that a site conforms to WCAG, the ADA or the European Accessibility Act; not legal advice. Sources read on the primary pages on 27 Sep 2026. EU: the European Accessibility Act, Directive (EU) 2019/882 (https://eur-lex.europa.eu/eli/dir/2019/882/oj/eng), covers e-commerce services to consumers (Art. 2(2)(f), defined in Art. 3(30)) and applies from 28 Jun 2025 (Art. 31(2)); microenterprises providing services (fewer than 10 staff and annual turnover or balance sheet of no more than EUR 2 million, Art. 3(23)) are exempt (Art. 4(5)); harmonised standards give a presumption of conformity (Art. 15), and the one used for web content, EN 301 549, points to WCAG 2.1 AA (the EN 301 549 version was not re-checked); penalties are set by each Member State (Art. 30). US: DOJ's web guidance of 18 Mar 2022 (https://www.ada.gov/resources/web-guidance/) says ADA Title III covers the goods and services businesses open to the public offer online, with no Title III regulation setting a technical standard; WCAG is named as helpful guidance, and lawsuits and settlements usually cite WCAG 2.1 AA. The Title II web rule (28 CFR part 35 subpart H, published 24 Apr 2024, https://www.ada.gov/resources/2024-03-08-web-rule/) sets WCAG 2.1 AA for state and local governments only, not private shops; an interim final rule published 20 Apr 2026 moved its compliance dates to 26 Apr 2027 and 26 Apr 2028. Overlays: the FTC's final order against accessiBe (22 Apr 2025, USD 1 million, https://www.ftc.gov/news-events/news/press-releases/2025/04/ftc-approves-final-order-requiring-accessibe-pay-1-million) bars claims that an automated tool makes a site WCAG-compliant without evidence, which is why this pass reports what it checked and never says compliant. Licences: Qwen3.8-27B Apache-2.0; axe-core MPL-2.0 (vendored unmodified, source and licence shipped with it); Playwright Apache-2.0; Chromium BSD-3-Clause.","components":[{"id":"llm","role":"Looks at each image with its alt text (right, wrong, poor, needed but empty, decorative), reads offer text drawn into banners, judges link and button names in their context and the form's error messages","name":"Qwen3.8-27B (NVIDIA NVFP4)","hf_repo":"nvidia/Qwen3.8-27B-NVFP4","license":"Apache-2.0","params":"27.8B","quant":"NVFP4 (MLP) + FP8 (attention/GDN), FP8 KV cache, MTP speculative decoding k=3","vram_gb":57,"memory_gb_estimate":null,"engine":"vLLM 0.29.0, served with its vision tower","receipt_coverage":"strong","in_hosted_demo":true,"tiers":["standard"],"alternative_to":null},{"id":"browser","role":"Opens each page in a private headless Chromium (one per audit), runs axe-core, the keyboard pass (Tab order, Enter on add-to-cart, visible focus, Escape from dialogs) and the empty-submit form pass; blocks every request that is not GET or HEAD","name":"axe-core 4.13.0 in headless Chromium (Playwright 1.58)","hf_repo":null,"license":"MPL-2.0 (axe-core) + Apache-2.0 (Playwright) + BSD-3-Clause (Chromium)","params":null,"quant":null,"vram_gb":0,"memory_gb_estimate":null,"engine":"Playwright for Python, chromium-headless-shell","receipt_coverage":"partial","in_hosted_demo":true,"tiers":["lite","standard"],"alternative_to":null},{"id":"report","role":"Merges the rule, keyboard, form and model results into findings ranked P1 (blocks a purchase) to P4, cites the WCAG 2.2 success criteria, writes a code fix per finding and seals the signed record","name":"decosa-api a11y module (decosa_api/verticals/a11y)","hf_repo":null,"license":"AGPL-3.0-or-later","params":null,"quant":null,"vram_gb":0,"memory_gb_estimate":null,"engine":"Python 3.12","receipt_coverage":"partial","in_hosted_demo":true,"tiers":["lite","standard"],"alternative_to":null}],"tiers":[{"id":"lite","label":"Lite · rules, keyboard and forms, no model (CPU)","summary":"axe-core, the keyboard pass and the form pass only (\"judge\": false): no GPU, no model calls. Misses wrong or keyword-stuffed alt text, vague names, unclear error messages and text only in images.","components":["browser","report"],"hardware":"CPU only (a headless Chromium per audit)","quality_evidence":[{"metric":"held-out test: planted issues found by the rule engine and the keyboard and form passes (no model)","value":"70 of 70 of those types; the 57 model-layer issues are not checked","source":"decosa-api docs/evals/storefront-accessibility-pass.md, measured on our server 2026-09-27, gateway route"}],"latency_note":"measured: seconds for the sample shop without the model (console run)","in_hosted_demo":true,"receipt_coverage":"partial","receipt_note":"No model calls; the record is signed by the instance (attested).","hosting":null},{"id":"standard","label":"Standard · rules, keyboard, forms and the model (hosted demo)","summary":"Adds Qwen3.8-27B with vision for the judgements a rule engine cannot make: alt text against the image, names in context, error messages, text only in images.","components":["llm","browser","report"],"hardware":"Qwen3.8-27B on one 96 GB card, or the hosted gateway; the rest on CPU","quality_evidence":[{"metric":"held-out test (frozen): planted issues caught / clean items flagged / clean pages with any finding","value":"122 of 127 / 0 of 207 / 0 of 7","source":"decosa-api docs/evals/storefront-accessibility-pass.md, measured on our server 2026-09-27, gateway route"},{"metric":"blind comparison on 60 alt and 40 name cases: Qwen3.8-27B vs Claude Code Opus 5.5","value":"alt 57/60 vs 59/60; planted names 10/12 vs 11/12","source":"decosa-api docs/evals/storefront-accessibility-pass.md, measured on our server 2026-09-27, gateway route"}],"latency_note":"measured: under a minute per page under eval load on the shared gateway","in_hosted_demo":true,"receipt_coverage":"strong","receipt_note":"Gateway receipt per model call on the hosted route; the rule and keyboard findings are attested by the instance.","hosting":null}],"alternates":[],"services":[{"name":"decosa-api","port":8445,"image":"${DECOSA_REGISTRY}/decosa-api:0.1.0","purpose":"GET /a11y/info, /a11y/samples, /a11y/store/*; POST /a11y/audit (SSE or JSON); /a11y/domains. Build with WITH_BROWSER=1 for the headless Chromium. No GPU."},{"name":"decosa-llm","port":8000,"image":"${DECOSA_REGISTRY}/decosa-llm:0.1.0","purpose":"vLLM OpenAI endpoint for Qwen3.8-27B, served with its vision tower (image input). Internal to the compose network."}],"tools":[{"name":"axe-core","url":"https://github.com/dequelabs/axe-core","license":"MPL-2.0","purpose":"The automated WCAG 2.0-2.2 A/AA rules (tags wcag2a, wcag2aa, wcag21a, wcag21aa, wcag22aa), injected into each page."},{"name":"Playwright for Python","url":"https://github.com/microsoft/playwright-python","license":"Apache-2.0","purpose":"Drives the private headless Chromium: page loads, request blocking, the keyboard pass and screenshots."},{"name":"WCAG 2.2 Understanding documents (W3C)","url":"https://www.w3.org/WAI/WCAG22/Understanding/","license":"W3C Document License","purpose":"Linked from each finding's success criterion."},{"name":"decosa test runs (tool 27) domain verification","url":"https://decosa.ai/apps/test-runs","license":"AGPL-3.0-or-later (decosa-api; the test-run CI client is Apache-2.0)","purpose":"The DNS TXT or well-known-file proof that a key may audit a domain; the browser is pinned to that domain's checked public addresses."},{"name":"decosa record (vertical 07) and POST /record/verify","url":"https://decosa.ai/apps/record","license":"AGPL-3.0-or-later (decosa-api; the record format and its verifier are Apache-2.0)","purpose":"The signed record anyone can re-check."},{"name":"scripts/a11y_build_store.py and scripts/a11y_eval.py","url":null,"license":"Apache-2.0","purpose":"Harbor & Pine, a made-up shop: six products (packshots drawn with Pillow, lifestyle scenes by Wan2.2-VACE-Fun-A14B), 50 eval pages with planted issues and clean versions, split by product into dev and test; the eval runner and scorer."}],"hardware":[{"tier":"1x RTX PRO 6000 96 GB","fits":true,"notes":"The hosted setup: Qwen3.8-27B NVFP4 with its vision tower on one card; Chromium, axe-core and the rest on CPU."},{"tier":"CPU only","fits":true,"notes":"The rules, keyboard and form passes, the fix list and the record run on CPU (\"judge\": false); the alt-text, name and error-message judgements then need the hosted gateway or a GPU."}],"latency":[{"lane":"one page, full audit (about 4 model calls), hosted gateway route","typical_ms":51800,"source":"measured on our server 2026-09-27: median over the 30 test pages, with the alt eval running in parallel on a shared gateway (28.7 s median on the 20 dev pages)"},{"lane":"the three-page sample shop, self-hosted (direct route to a local Qwen3.8-27B)","typical_ms":11600,"source":"measured on our server 2026-09-27: 2 runs in the self-host check (10.7 and 12.6 s)"}],"benchmark":null,"notes":[]},"buyer_facts":[{"label":"What it checks","value":"axe-core's automated WCAG 2.2 A/AA rules; add-to-cart and the checkout with the keyboard alone (reachable, answers Enter or Space, visible focus, no trap); error messages after an empty submit; and, by the model, whether each alt text fits its image, whether link and button names are clear in context, whether errors say how to fix the field, and offer text that exists only inside an image. Up to five pages of one shop per audit, desktop or 390 px wide."},{"label":"What it does not do","value":"It does not certify conformance or say a site meets WCAG, the ADA or the European Accessibility Act, and it is not legal advice. It does not test screen-reader output, reading order, zoom and reflow, captions or cognitive load, every widget, or pages behind a login on the hosted service. It never pays, places an order or submits a form to your server. The model judgements are suggestions for a person to review."},{"label":"Data retention","value":"Nothing is stored: pages, screenshots and images live in memory and a private browser profile for the audit and are dropped when it ends. The result and its signed record are returned to you, not kept. Logs carry counts and ids, never URLs, alt text or page text."},{"label":"What leaves the box (hosted demo)","value":"Page images, alt text, link and button names and error messages go to Qwen3.8-27B through our gateway, operated by Decosa. The headless browser only fetches the pages you list, on a domain your key has verified. Self-hosted, nothing leaves the machine except the browser's requests to your own site."},{"label":"Output","value":"A fix list ranked P1 (blocks a purchase) to P4, each finding with its WCAG 2.2 success criteria, the page, the element's HTML and a code fix, plus advisories, what was and was not checked, and a signed record (verify at /record/verify) with the axe-core version and hash, the prompts' hashes and a receipt per model call."},{"label":"Cost per page","value":"A fraction of a cent of model calls per page (a few calls) at the gateway list price, measured over the test pages. Without the model it is CPU only."}],"data_handling":{"page":"/data#storefront-accessibility-pass","self_host":{"level":"confidential","leaves":"nothing","summary":"Runs on your machine; nothing is sent to Decosa or a third party by default."},"hosted":{"level":"operator-processed","demo_only":false,"summary":"TLS to Decosa's server, then decrypted and processed by Decosa's API server, with the open models run by NEAR AI through OpenRouter, with Reka AI as the only fallback under Decosa's account.","gpus":"operator-contracted","third_parties":[],"retention":"Nothing is stored: pages, screenshots and images live in memory and a private browser profile for the audit and are dropped when it ends. The result and its signed record are returned to you, not kept. Logs carry counts and ids, never URLs, alt text or page text.","used_for_training":false,"encrypted_while_processed":false},"sealed_tier":{"applies":false,"note":"The sealed tier (raw chat only, never use-case pipelines) is paused at launch (/docs/sealed-tier)."},"external_calls":[{"to":"The shop's own pages (the URLs you list)","route":"both","sends":"your-system","what":"GET and HEAD requests from the headless browser to the domain the key verified (hosted) or the hosts you list (self-host). Every other request method is blocked.","default":"on","off":"Paste the HTML (synthetic: true) or use the sample shop instead of URLs."}]},"console":{"href":"/tools/operations/storefront-accessibility-pass","input":"a11y","lanes":[{"id":"rules","title":"Automated rules","kind":"list"},{"id":"keyboard","title":"Keyboard pass","kind":"list"},{"id":"judgements","title":"Model judgements","kind":"list"},{"id":"fixes","title":"Fix list and record","kind":"json"}],"samples":[{"n":1,"id":"shop-with-issues","title":"Shop with issues","deep_link":"/tools/operations/storefront-accessibility-pass?sample=1&autorun=0"},{"n":2,"id":"clean-shop","title":"Clean shop","deep_link":"/tools/operations/storefront-accessibility-pass?sample=2&autorun=0"},{"n":3,"id":"product-page","title":"Product page","deep_link":"/tools/operations/storefront-accessibility-pass?sample=3&autorun=0"}],"deep_link_params":{"sample":"1-based index into samples, or a sample id","autorun":"1 = start the run once the sample is loaded; 0 (default) = only preselect","reduce-motion":"1 = turn off animations"}},"api":{"base":"https://api.decosa.ai","contract":"/api/contract.json","contract_markdown":"/api/contract.md","reference":"/docs/api","keys":"/account/keys"},"prompts":{"hosted":"/prompts/storefront-accessibility-pass-hosted.md","selfhost":"/prompts/storefront-accessibility-pass-selfhost.md","assemble":"/prompts/storefront-accessibility-pass-assemble.md","mac":null},"rehearsal":{"bundle":"/samples/storefront-accessibility-pass.zip","bundle_url":"https://decosa.ai/samples/storefront-accessibility-pass.zip","folder":"/samples/storefront-accessibility-pass/","expected":"/samples/storefront-accessibility-pass/expected.json","files":["/samples/storefront-accessibility-pass/expected.json","/samples/storefront-accessibility-pass/inputs/product-page.html"],"bytes":59560,"checks":["Add to cart, a div the keyboard cannot reach, is found and ranked first (P1)","the quantity field without a label is found by the rule engine","the packshot's alt text, which calls the orange can purple, is flagged by the model","the banner offer that exists only in the image is flagged","at least four findings, each with its WCAG references","every model call has a receipt","the signed record verifies","the clean sample shop, checked without the model, has no findings"],"licence":"Harbor & Pine is invented for decosa-api (AGPL-3.0-or-later): packshots drawn with Pillow, the banner photo drawn by Wan2.2-VACE-Fun-A14B (Apache-2.0).","about":"A product page from Harbor & Pine, a made-up shop, pasted as HTML with its images inline (the browser has no network for pasted pages). Four issues are planted: the packshot's alt says the can is purple (it is orange), Add to cart is a div the keyboard cannot reach, the quantity field has no label, and a banner offer exists only inside the image. The audit must find the rule-engine issue, the keyboard blocker (as P1) and the two model-judged ones, attach a receipt to every model call, and sign a record that verifies. Then the clean version of the sample shop, without the model, must come back with nothing found.","run":{"containers":"docker compose exec api python scripts/rehearse.py storefront-accessibility-pass","checkout":"python scripts/rehearse.py storefront-accessibility-pass --bundle storefront-accessibility-pass.zip --base-url http://127.0.0.1:8445","mac":".venv/bin/python scripts/rehearse.py storefront-accessibility-pass"},"guidance":"Set up with a coding agent (we recommend Claude Code with Claude Opus 5.5; any capable coding agent works) on mock data only, run the rehearsal until every check passes, then run your own data locally yourself. Never give the agent real data during setup."},"hardware_fit":{"check":"/self-host/hardware?use=storefront-accessibility-pass","data":"/api/hardware.json","tiers":[{"id":"lite","gpu_gb":0,"basis":null,"unknown":[]},{"id":"standard","gpu_gb":57.6,"basis":"stack","unknown":[]}],"mac":null},"links":{"page":"/tools/operations/storefront-accessibility-pass","json":"/use-cases/storefront-accessibility-pass.json","metrics":"/metrics/storefront-accessibility-pass","console":"/tools/operations/storefront-accessibility-pass","console_sample":"/tools/operations/storefront-accessibility-pass?sample=1&autorun=0","stack":"/tools/operations/storefront-accessibility-pass#stack","try_live":"/tools/operations/storefront-accessibility-pass","watch":"/tools/operations/storefront-accessibility-pass","build":"/tools/operations/storefront-accessibility-pass#build","self_host":"/tools/operations/storefront-accessibility-pass#self-host","prompts":{"hosted":"/prompts/storefront-accessibility-pass-hosted.md","selfhost":"/prompts/storefront-accessibility-pass-selfhost.md","assemble":"/prompts/storefront-accessibility-pass-assemble.md","mac":null}}}