Home

Security Overview

RIRWEB uses practical safeguards appropriate to a hosted accessibility operations platform. No system is perfectly secure.

Secure WordPress pairing

RIRWEB uses a one-time pairing code to connect the RIRWEB Accessibility Connector. Pairing codes expire, cannot be reused, and are bound to the intended website.

Read-only connector default

The connector is read-only by default. It can inventory the Media Library and retrieve documents for review. Document replacement is available only when an administrator explicitly enables that option in WordPress.

Encrypted credentials

Application Passwords and connector secrets are encrypted at rest when encryption is configured for the application. Shared secrets are not displayed in the administrator interface after pairing.

Revocable connections

A WordPress administrator can disconnect the connector at any time. RIRWEB administrators can also disconnect a website and invalidate stored credentials.

Proposal link expiration

Public proposal links can expire, be revoked, or require an access code. Accepted proposals remain associated with the locked proposal version.

Signed proposal version locking

Electronic acceptance records the signed proposal version. Later edits to templates or legal text do not rewrite historical acceptance records.

Protected admin access

Administrator functions require an authenticated RIRWEB account session.

Data minimization

RIRWEB collects website URLs, document metadata, and contact details needed to deliver requested audits, reports, and proposals.

Private document processing

Uploaded and retrieved documents are processed to support accessibility review and remediation workflows. They are not published as a public library.