Accessibility Conformance Report (VPAT® 2.5 / WCAG 2.1 AA / EN 301 549), GDPR Data Sovereignty, & Security Overview
This Accessibility Conformance Report (ACR) documents the degree of conformance for the Heritage OS visitor Progressive Web App (PWA) micro-shell and curation interface under Section 508 of the US Rehabilitation Act, WCAG 2.1 Level AA, and European Standard EN 301 549 (European Accessibility Act).
| Criteria / Standard | Conformance Level | Remarks & Functional Explanations |
|---|---|---|
| 1.1.1 Non-text Content (Level A) Screen reader text alternatives |
Supports | All exhibit imagery, maps, and audio controls include explicit alt attributes and programmatic ARIA labels for NVDA/VoiceOver. |
| 1.3.1 Info & Relationships (Level A) Tactile & Visual Structure |
Supports | Semantic HTML5 hierarchy throughout. Tactile Braille physical faceplates map directly to programmatic DOM triggers. |
| 1.4.3 Contrast (Minimum) (Level AA) Visual High Contrast Ratio |
Supports | Text and interactive UI components maintain a minimum 4.5:1 contrast ratio against background elements (exceeds 7:1 in high-contrast mode). |
| 2.1.1 Keyboard (Level A) Full Keyboard Accessibility |
Supports | All interactive exhibit features, audio controls, and grievance reporting nodes are 100% operable via standard keyboard tabbing. |
| 3.1.2 Language of Parts (Level AA) Multi-lingual Auto-Detection |
Supports | Automatically detects the user's smartphone language string profile to serve regional dialects natively on initial page parse. |
| 3.3.1 Error Identification (Level A) Facility Grievance Reporting |
Supports | Facility grievance mapping alerts provide screen-reader accessible error notices with localized resolution guidance. |
Heritage OS is engineered under a strict Privacy-by-Design paradigm. Public sector cultural institutions in the EU and USA require complete visitor telemetry protection and zero unauthorized tracking.
Visitors access rich exhibit content instantly over temporary Progressive Web App (PWA) micro-shells. Eliminates friction and prevents harvesting of personal contact profiles or app-store identities.
The platform collects zero Personally Identifiable Information (PII). No user tracking cookies, device advertising IDs, or personal email requirements exist for visitors accessing museum guides.
All anonymous visitor interaction telemetry is aggregated locally within regional data centers (EU/US), satisfying global data sovereignty laws and municipal privacy mandates.
Analytics dashboards display aggregated visitor flow metrics and asset health telemetry without tracking individual movement paths or storing personal location logs.
Heritage OS provides enterprise-tier cloud reliability hosted on Google Cloud Platform (GCP), satisfying global cybersecurity standards for municipal and federal cultural institutions.
| Security Domain | Architecture Specification | Compliance Guarantee |
|---|---|---|
| Cloud Infrastructure | Hosted on Google Cloud Platform (GCP) with multi-region failover redundancy. | ISO 27001, SOC 2 Type II, FedRAMP Certified Data Centers |
| Data Encryption | Enforced TLS 1.3 encryption in-transit; AES-256 cloud encryption at-rest (GCP KMS). | Protection against network interception and data tampering |
| Curator Access Control | Role-Based Access Control (RBAC) with Multi-Factor Authentication (MFA) for administrative staff. | Prevents unauthorized exhibit modification or administrative override |
| Backup & Continuity | Automated daily database snapshots with point-in-time recovery and zero open inbound ports. | 99.9% uptime SLA with rapid disaster recovery capabilities |