Compliance and Industry Standards
We don't hold security certifications of our own, and HIPAA has no official certification for software or developers. Our part is to build the technical safeguards into your application, choose independently audited providers, and sign the agreements that make responsibilities clear.
Most of the applications we build run on Vercel and Supabase, which are both hosted on AWS. Supabase maintains SOC 2 Type II compliance for its infrastructure. That certification belongs to the provider, not to Web Wizard Dev, but it means your data sits on independently audited infrastructure. Sensitive files are kept in private, encrypted storage behind server-side access checks and short-lived links.
Vercel publishes its own SOC 2 Type 2 attestation. Card payments go through a processor's hosted checkout, such as Stripe or Square, so card numbers never touch your servers or ours. Stripe is certified as a PCI Service Provider Level 1.
For health information we sign Business Associate Agreements (BAAs), and have signed them for union and health-fund clients. Our agreements include mutual confidentiality, and we're glad to sign your NDA before a project starts.
HIPAA also expects a BAA with each vendor that stores health data, such as the hosting or database provider, so we plan for those agreements during discovery.
Accessibility
We design and build to WCAG 2.2 Level AA, the current version of the Web Content Accessibility Guidelines. It includes WCAG 2.1 AA, the level the U.S. Department of Justice requires of state and local government websites, and the level HHS names for organizations that receive its funding.
Before launch we run automated Lighthouse checks across the site's main pages, and we test the home page and one or two other key pages by hand, using only a keyboard and zoomed in. Screen reader testing is available when your project needs it. On a union benefits fund's site we rebuilt, all 11 audited pages score 100 for Lighthouse accessibility.
An accessibility problem in our work is a bug, so it's covered by the free fixes after launch. We can also write an accessibility statement for your site. A few parts sit outside our control: a payment provider's checkout page, Google's reCAPTCHA, PDFs and videos you supply, and content your team adds after launch. We tell you which ones apply to your project.
Want to verify requirements?
If you're in a regulated industry, we can help you understand what standards matter and what controls are appropriate for your application.