How to read your first Veracly compliance report
Your first Veracly report is dense by design. Here is the section-by-section tour, the numbers that actually matter, and a triage plan for the first week.
Your first Veracly report is dense. The PDF is twelve to twenty pages, the dashboard has fewer pixels but more drill-down, and the cover page shows six numbers before you even get to the body. This article is the guided tour, what each section is for, which numbers matter, and how to get from “received” to “the top five fixes are filed in your tracker” in under thirty minutes.
One navigation note before the tour: the sections are not numbered. Each one carries a title and nothing else, so cite them by name when you forward the report or point somebody at a page. The headings below are the titles as they appear, in the order they appear.
The cover
The headline is your overall score and a status pill (green/yellow/red). The mini-cards below show one number per jurisdiction that fired. Two things to read here:
- The status pill is the at-a-glance verdict. Green (85+) means your site is in good shape; yellow (60 to 84) means you have actionable findings but no single catastrophic one; red (under 60) means at least one critical issue you should file today.
- The jurisdiction strip tells you which laws actually apply to your real traffic mix. We do not score laws that do not apply, if you have zero EU visitors, GDPR does not appear here.
Executive summary
One paragraph of natural-language summary, AI-drafted from data the rules engine has already finished producing: the verdicts, the scan statistics, and the top violation types. There is no review step after the drafting, and it would be dishonest to imply one, no human and no second engine pass reads that paragraph before it reaches you. What it does have is a deterministic floor: if the model is unreachable or errors, the report falls back to a templated summary built straight from the verdicts, so the section is never blank and never invented. The numbers in the stat cards beneath it come from the database, not from the model. Treat the prose as a readable gloss on those numbers and the numbers as the record.
The stat cards underneath translate the headline into traceable numbers: pages scanned, unique issues, jurisdictions evaluated, distinct critical findings. If something on the executive summary surprises you, the stats below tell you which page count is driving it.
Per-jurisdiction scorecard
One card per applicable jurisdiction. Each shows a score, a violation count, the critical count, and a severity-distribution bar (critical / high / medium / low). Read the bar shape, not just the number, two sites with a 72 can have wildly different fix workloads if one has all-low and the other has two criticals.
For AODA you will see two numbers side-by-side: the strict 2.1-AA score (used for cross-jurisdiction parity with the other cards) and the legal-floor score against IASR §14’s 2.0-AA bar (which is Ontario’s actual statutory requirement). The 2.0 number is what an Ontario regulator would compare against in practice.
Top priorities
This is where you start. Ten issues ranked by severity first, then by how many pages the issue affects, a critical that appears on every page outranks a critical on one page, which outranks any high. Each row has a one-paragraph plain-English explanation from the AI translator pass.
Those explanations are cached for 30 days, keyed to the violation type and the specific element sampled, so the same issue on the same element reads identically across two reports a fortnight apart. That is the point: stable wording makes a genuine change in a finding visible instead of drowning it in reworded prose. It also means the text you are reading may have been generated during an earlier scan.
If your team only does one thing with the report this week, file these ten as tickets and assign them. The downstream remediation appendix has the copy-paste fix for each.
Per-jurisdiction detail
One detail page per jurisdiction that fired. The ring at the top mirrors the scorecard number. The table below it lists the top ten findings for that jurisdiction, which can overlap with the cross-jurisdiction top priorities but often introduces a few jurisdiction-specific ones (an EAA accessibility statement requirement, a UK Equality Act reasonable-adjustments concern, an AODA-only IASR clause).
The cited regulations panel at the right is the answer to “under what law?” Use it when you forward the report internally, pasting the regulation reference into a Jira ticket converts “we have a compliance issue” into “Article X.Y of regulation Z requires the following.”
Remediation appendix
The longest section by page count. One card per top-priority finding, expanded to include: a one-paragraph plain-English explanation, an evidence screenshot (when the scanner could capture a stable element selector), a free-form fix-in-prose, and language-tagged code blocks (HTML / CSS / JavaScript) for the AI-generated patch.
The HTML/CSS/JS snippets are starting points, not patches to commit unreviewed. The scanner cannot see your component library or class-name conventions; treat the snippets the way you would treat a Stack Overflow answer, read it, adapt it, then commit.
Remaining issues
A flat inventory of every issue past the top ten. No fix detail (the top ten and the remediation appendix already cover the high-leverage class), this exists so the report is a complete record. A buyer who only ships the top ten on the first iteration can come back to this section for the second sprint.
Methodology, then glossary
What rule set we used, what each acronym means, what we did not evaluate (manual screen-reader testing, cognitive-load testing). Skip on first read; come back when a stakeholder or auditor asks “how was this measured?”
Legal disclaimer and integrity block
The disclaimer is standard auditor language: the report is a snapshot, not a legal opinion. The integrity block is more interesting, every Veracly report is signed with an Ed25519 key, and the Verification ID printed here is what a holder of the PDF pastes at veracly.app/verify/<uuid> to confirm the bytes are the ones we issued. Read the rest of that block before you forward the report: it states that the Verify URL is valid for 30 days from issue. On a paid report it also tells the recipient to request the stored fingerprint from support@veracly.app against the Verification ID after that; on a free scan it instead notes that once the anchor retires 60 days after issue the stored fingerprint is erased and byte-for-byte verification ends. The ID is the durable half; the URL is not. It also carries the corrections address, if you want to dispute a finding rather than fix it. See How to verify a Veracly report is authentic for the full mechanic.
A 30-minute workflow for the first report
- Open the PDF, read the executive summary (1 min).
- Scan the per-jurisdiction scorecard. Note the worst jurisdiction and the severity-bar shape (2 min).
- Go to Top Priorities. File each row as a ticket in your tracker with the title, severity, and the regulation reference from the corresponding detail page (15 min).
- For each ticket, open the remediation appendix card. Paste the explanation into the ticket description and link the AI snippet as a starting point (10 min).
- Schedule a re-scan for when the fixes land. Do not assume the automatic cadence will cover it, Starter runs monthly, Growth weekly or monthly, Pro and Agency daily, weekly, or monthly, and it is set per site. Use the Scan now button on the site detail page as soon as the fix ships (2 min).
What the report deliberately does not tell you
Compliance is not a percentage. A 95 with one critical finding is more exposed than an 80 with twenty mediums. Read the severity distribution, not the headline, when you are deciding whether a result is “good enough.”
And the report is silent on the things automation cannot reach: manual screen-reader usability, cognitive-load testing of complex forms, plain-language review of legal pages by an actual lawyer. The methodology section names these omissions on purpose.
See also: The top 10 issues Veracly finds, and how to fix them · Free scan vs. paid report: when to upgrade
Common questions
What does the overall score mean?
The headline score is the average of every jurisdiction that fired for your site. A 70 means a typical visitor mix lands in the yellow band, you have meaningful violations but no single critical one. Green is 85+; red is below 60.
Why are some jurisdictions marked "not evaluated"?
A jurisdiction only fires when your real visitor traffic includes the region it covers. An Australian-publisher site with zero EU visitors will see GDPR marked not-evaluated; we do not score what does not apply. That decision is shown on the report so it does not look like missing data.
What is the difference between an issue and a violation?
An issue is a unique rule that failed (for example "form-label-missing"). A violation is an instance of that issue (the report counts five form-label-missing findings as five violations of one issue). The executive summary uses unique issues; per-jurisdiction cards use violations.
Where do I start fixing?
The Top Priorities table. The report sections are not numbered, so look for that heading; it sits after the per-jurisdiction scorecard. Rows are ranked by severity first and then by how many pages the issue affects, so the ten items listed are the highest-leverage fixes regardless of which jurisdiction surfaced them. Anything beyond the top ten goes in the Remaining Issues inventory at the back.
See where your site stands.
Run a free Veracly scan and get a multi-jurisdiction report, EAA, GDPR, ADA, UK Equality Act, AODA, with copy-paste developer fixes.
Run a free scan