Back to Home

Global Legal, Accessibility & Security Compliance

Accessibility Conformance Report (VPAT® 2.5 / WCAG 2.1 AA / EN 301 549), GDPR Data Sovereignty, & Security Overview

Product Name: Heritage OS Platform
Report Version: VPAT 2.5 Rev INT (2026 Release)
Published Date: July 2026
Evaluation Methods: Automated (AXE Core) & Manual AT Testing (NVDA, VoiceOver, Tactile Braille)

Section 1: Accessibility Conformance Report (VPAT® / Section 508)

This Accessibility Conformance Report (ACR) documents the degree of conformance for the Heritage OS visitor Progressive Web App (PWA) micro-shell and curation interface under Section 508 of the US Rehabilitation Act, WCAG 2.1 Level AA, and European Standard EN 301 549 (European Accessibility Act).

WCAG 2.1 Level A & AA Conformance Summary Table

Criteria / Standard Conformance Level Remarks & Functional Explanations
1.1.1 Non-text Content (Level A)
Screen reader text alternatives
Supports All exhibit imagery, maps, and audio controls include explicit alt attributes and programmatic ARIA labels for NVDA/VoiceOver.
1.3.1 Info & Relationships (Level A)
Tactile & Visual Structure
Supports Semantic HTML5 hierarchy throughout. Tactile Braille physical faceplates map directly to programmatic DOM triggers.
1.4.3 Contrast (Minimum) (Level AA)
Visual High Contrast Ratio
Supports Text and interactive UI components maintain a minimum 4.5:1 contrast ratio against background elements (exceeds 7:1 in high-contrast mode).
2.1.1 Keyboard (Level A)
Full Keyboard Accessibility
Supports All interactive exhibit features, audio controls, and grievance reporting nodes are 100% operable via standard keyboard tabbing.
3.1.2 Language of Parts (Level AA)
Multi-lingual Auto-Detection
Supports Automatically detects the user's smartphone language string profile to serve regional dialects natively on initial page parse.
3.3.1 Error Identification (Level A)
Facility Grievance Reporting
Supports Facility grievance mapping alerts provide screen-reader accessible error notices with localized resolution guidance.

Section 2: GDPR & Privacy Architecture Statement

Heritage OS is engineered under a strict Privacy-by-Design paradigm. Public sector cultural institutions in the EU and USA require complete visitor telemetry protection and zero unauthorized tracking.

Zero-App PWA Micro-Shells

Visitors access rich exhibit content instantly over temporary Progressive Web App (PWA) micro-shells. Eliminates friction and prevents harvesting of personal contact profiles or app-store identities.

Zero Personal Profile Harvesting

The platform collects zero Personally Identifiable Information (PII). No user tracking cookies, device advertising IDs, or personal email requirements exist for visitors accessing museum guides.

GDPR & CCPA Data Sovereignty

All anonymous visitor interaction telemetry is aggregated locally within regional data centers (EU/US), satisfying global data sovereignty laws and municipal privacy mandates.

Anonymized Visitor Telemetry

Analytics dashboards display aggregated visitor flow metrics and asset health telemetry without tracking individual movement paths or storing personal location logs.

Section 3: Cloud Infrastructure & Security Overview

Heritage OS provides enterprise-tier cloud reliability hosted on Google Cloud Platform (GCP), satisfying global cybersecurity standards for municipal and federal cultural institutions.

Security Domain Architecture Specification Compliance Guarantee
Cloud Infrastructure Hosted on Google Cloud Platform (GCP) with multi-region failover redundancy. ISO 27001, SOC 2 Type II, FedRAMP Certified Data Centers
Data Encryption Enforced TLS 1.3 encryption in-transit; AES-256 cloud encryption at-rest (GCP KMS). Protection against network interception and data tampering
Curator Access Control Role-Based Access Control (RBAC) with Multi-Factor Authentication (MFA) for administrative staff. Prevents unauthorized exhibit modification or administrative override
Backup & Continuity Automated daily database snapshots with point-in-time recovery and zero open inbound ports. 99.9% uptime SLA with rapid disaster recovery capabilities