Dispute a finding in a Veracly report
Veracly issues signed technical compliance reports produced by automated scanning. If you believe a specific finding in a report is factually wrong, the rule did not reproduce, the cookie is not there, the contrast value is computed incorrectly, this page documents the intake channel and the response you can expect from us.
What this channel is for
Use corrections@veracly.app if you are the operator (or representative of the operator) of a site that is the subject of a Veracly report, and you believe a specific finding is a false positive. Specifically:
- A rule is flagged but does not reproduce when you verify it independently, for example, the cookie is not set before a consent gesture in your own browser session, or the contrast ratio is within the WCAG AA threshold when measured with a reference tool.
- The finding is attributed to the wrong domain, a tracker or cookie belongs to a third-party service pre-loaded by your hosting provider, not to your own integration.
- The element selector in the report is stale, you fixed the issue before the scan ran, and the scan appears to have captured a cached or pre-deploy version of the page.
- A rule was applied to a page that is out of scope, for example, a private login portal that should not have been accessible to a public crawl.
If the report is accurate but you believe it is being used inappropriately against your site, as the basis of a cease-and-desist (Abmahnung) without independent legal review, or republished in a way that implies a regulatory verdict, that is the abuse channel, not the corrections channel. Email abuse@veracly.app instead. That channel is also documented at veracly.app/abuse.
What to include in your dispute
To process your request quickly, include:
- The Verification ID (UUID) printed on the final page of the PDF, or the URL of the
/verify/<id>page if you have it. This lets us locate the exact scan version you are disputing. - The domain the report is about.
- Which specific finding you are disputing, the rule name (e.g. color-contrast, pre-consent-cookie) and, if shown, the element selector or page URL.
- What you observed when you tried to reproduce the finding independently, and any supporting evidence (screenshot, DevTools export, contrast-ratio tool output).
- Whether you are the site operator, their counsel, or an authorised third party. We can act most quickly when the request comes from the operator or counsel of record.
You do not need to prove you control the domain to open a case. If a remedy requires confirming domain control (for example, reissuing the report to a different requester), we will ask for a DNS TXT record or equivalent at that point.
Response SLA
We commit to the following response times, measured from receipt at corrections@veracly.app during Sydney business hours (Mon–Fri, public holidays excluded):
- 1 business day
- Acknowledgement of receipt with a case number and the name of the responder.
- 5 business days
- Initial response with our finding and proposed remedy (see below). For straightforward reproductions where the finding clearly does not fire in an independent session, this is typically faster.
- Ongoing
- If the case requires a re-scan or coordination with the original requester, we will keep you updated at least weekly until closed.
Possible remedies
Depending on the outcome of our review, the remedies we can apply include:
- Re-scan and reissue. We run a fresh scan of the relevant pages, apply the same engine version, and issue a corrected report. The original verify URL is retired and a new one issued; the audit ledger records both scan IDs and the relationship between them.
- Retract. If the finding was a clear false positive, the rule did not reproduce on re-scan, we retract the original report. The verify URL serves a public retraction notice. The proof-of-existence entry stays on the audit ledger (we do not fabricate history), but the signature material for the original report is scrubbed.
- Partial correction. If the report contained multiple findings and only one is disputed and confirmed as wrong, we reissue with that finding removed and the score recalculated.
- No action. If our re-scan reproduces the finding independently, we will explain the reproduction steps and close the case without changing the record. We will share the reproduction evidence with you.
What this channel is not
corrections@veracly.app is an accuracy-dispute channel, not a legal-services intake. A reissue or retraction from Veracly is not a substitute for the operator’s own legal review of any demand they have received based on the original report. Veracly accepts no liability for decisions made in reliance on a corrected or retracted report without independent legal advice.
We do not adjudicate disputes between the original requester and the site operator. Veracly’s obligation is to the accuracy of its own technical output, if the scan found what it says it found, the report stands.
For security vulnerabilities in Veracly’s own infrastructure, email security@veracly.app instead — that is a separate channel with a separate SLA.