Global Legal, Accessibility & Security Compliance

Accessibility Conformance Report (VPAT® 2.5 / WCAG 2.1 AA / EN 301 549), GDPR Data Sovereignty & Security Overview

Product Name: HeritageOS Platform
Report Version: VPAT 2.5 Rev INT (2026 Release)
Published Date: July 2026
Evaluation Methods: Automated (AXE Core) & Manual Testing (NVDA, VoiceOver, Tactile Braille)

Section 1: Accessibility Conformance Report (VPAT® / Section 508)

This Accessibility Conformance Report (ACR) documents the degree of conformance for the HeritageOS visitor Progressive Web App (PWA) and curation interface under Section 508 of the US Rehabilitation Act, WCAG 2.1 Level AA, and European Standard EN 301 549 (European Accessibility Act).

WCAG 2.1 Level A & AA Conformance Summary Table

Criteria / Standard Conformance Level Remarks & Functional Explanations
1.1.1 Non-text Content (Level A)
Screen reader text alternatives
Supports All exhibit imagery, maps, and audio controls include explicit alt attributes and programmatic ARIA labels for NVDA/VoiceOver.
1.3.1 Info & Relationships (Level A)
Tactile & Visual Structure
Supports Semantic HTML5 hierarchy throughout. Tactile Braille physical faceplates map directly to programmatic DOM triggers.
1.4.3 Contrast (Minimum) (Level AA)
Visual High Contrast Ratio
Supports Text and interactive UI components maintain a minimum 4.5:1 contrast ratio against background elements.
2.1.1 Keyboard (Level A)
Full Keyboard Accessibility
Supports All interactive exhibit features, audio controls, and reporting nodes are 100% operable via standard keyboard tabbing.
3.1.2 Language of Parts (Level AA)
Multi-lingual Auto-Detection
Supports Automatically detects the user's smartphone language profile to serve regional dialects natively on initial page parse.

Section 2: GDPR & Privacy Architecture Statement

HeritageOS is engineered under a strict Privacy-by-Design framework. Public sector cultural institutions in the EU and USA require complete visitor telemetry protection and zero unauthorized tracking.

Zero-App PWA Access

Visitors access rich exhibit content instantly over temporary Progressive Web App micro-shells without harvesting personal contact profiles or app-store identities.

Zero Personal Profile Harvesting

The platform collects zero Personally Identifiable Information (PII). No user tracking cookies or personal email requirements exist for visitors accessing museum audio guides.

GDPR & CCPA Data Sovereignty

All anonymous visitor interaction telemetry is aggregated locally within regional data centers (EU/US), satisfying global data sovereignty laws and municipal privacy mandates.

Anonymized Visitor Telemetry

Analytics dashboards display aggregated visitor flow metrics and asset health telemetry without tracking individual movement paths or storing personal location logs.

Section 3: Cloud Infrastructure & Security Overview

HeritageOS provides enterprise-tier cloud reliability hosted on Google Cloud Platform (GCP), satisfying global cybersecurity standards for municipal and federal cultural institutions.

Security Domain Architecture Specification Compliance Guarantee
Cloud Infrastructure Hosted on Google Cloud Platform (GCP) with multi-region failover redundancy. ISO 27001, SOC 2 Type II, FedRAMP Certified Data Centers
Data Encryption Enforced TLS 1.3 encryption in-transit; AES-256 cloud encryption at-rest (GCP KMS). Protection against network interception and data tampering
Curator Access Control Role-Based Access Control (RBAC) with Multi-Factor Authentication (MFA) for administrative staff. Prevents unauthorized exhibit modification or administrative override
Backup & Continuity Automated daily database snapshots with point-in-time recovery and zero open inbound ports. 99.9% uptime SLA with rapid disaster recovery capabilities