# Conformance — Robert DeLanghe

> A live, computed conformance report — not a badge. The build folds its own evidence (the gates that ran, the artifacts it signs) through lone's web-build conformance model. The strong claim is withheld unless every required criterion is met; anything not yet assessed says so, plainly.

**Claim:** Partial conformance: automated DOM checks clean; WCAG 2.2 AA (manual audit) not supplied; OWASP ASVS Level 2 not supplied; Core Web Vitals (p75) not supplied; runtime reliability not supplied.

**Summary:** 22 met · 1 unmet · 14 not-assessed · 37 total.

Machine-readable: [/api/v1/conformance.json](https://robertdelanghe.dev/api/v1/conformance.json) · signed chain: [/provenance](https://robertdelanghe.dev/provenance.md)

## html
- **HTML author requirements** (`html.dom-author-requirements`) — ✓ met: lone static checks clean (no findings) — [api/v1/conformance.json](https://robertdelanghe.dev/api/v1/conformance.json)
- **Nu HTML Checker errors** (`html.validator-clean`) — ✓ met: 0 validator errors — [workflow: conformance.yml](https://github.com/bdelanghe/site/actions/workflows/conformance.yml)

## accessibility
- **WAI-ARIA author requirements** (`a11y.aria-author`) — ✓ met: lone static checks clean (no findings) — [api/v1/conformance.json](https://robertdelanghe.dev/api/v1/conformance.json)
- **WCAG 2.2 AA (automated subset)** (`a11y.wcag22-aa-auto`) — ✓ met: lone static checks clean (no findings) — [api/v1/conformance.json](https://robertdelanghe.dev/api/v1/conformance.json)
- **axe serious/critical violations** (`a11y.axe-serious-critical`) — ✓ met: 0 serious/critical violations — [workflow: axe.yml](https://github.com/bdelanghe/site/actions/workflows/axe.yml)
- **WCAG 2.2 AA (manual audit)** (`a11y.wcag22-aa-manual`) — — not-assessed: no manual WCAG 2.2 AA audit supplied — [provenance](https://robertdelanghe.dev/provenance)
- **WCAG 2.2 AAA (selected)** (`a11y.wcag22-aaa-selected`) — — not-assessed _(recommended)_: no AAA attestation supplied (optional) — [provenance](https://robertdelanghe.dev/provenance)
- **Agent heuristic accessibility review** (`a11y.agent-heuristic-review`) — ✓ met _(recommended)_: agent heuristic pass clean — 7 page(s), 0 warning(s). AGENT/STATIC HEURISTIC — NOT AT-user testing; a11y.wcag22-aa-manual stays not-assessed. — [workflow: a11y-heuristic.yml](https://github.com/bdelanghe/site/actions/workflows/a11y-heuristic.yml)

## design
- **Palette contrast (design tokens)** (`design.palette-contrast`) — ✓ met _(recommended)_: color tokens CVD-safe, APCA baseline, non-text contrast ok — [bdelanghe/brand: tokens/token-a11y.json](https://github.com/bdelanghe/brand/blob/main/tokens/token-a11y.json)
- **Typography tokens** (`design.typography`) — ✓ met _(recommended)_: type tokens meet line-height, spacing, size, and weight bars — [bdelanghe/brand: tokens/token-a11y.json](https://github.com/bdelanghe/brand/blob/main/tokens/token-a11y.json)
- **Target size (interactive tokens)** (`design.target-size`) — — not-assessed _(recommended)_: no target-size report supplied — [bdelanghe/brand: tokens/token-a11y.json](https://github.com/bdelanghe/brand/blob/main/tokens/token-a11y.json)
- **Effective contrast under opacity** (`design.opacity-contrast`) — — not-assessed _(recommended)_: no opacity-contrast report supplied — [bdelanghe/brand: tokens/token-a11y.json](https://github.com/bdelanghe/brand/blob/main/tokens/token-a11y.json)
- **Token likeness hygiene** (`design.token-likeness`) — ✓ met _(recommended)_: categorical tokens distinct; no redundant tokens — [bdelanghe/brand: tokens/token-a11y.json](https://github.com/bdelanghe/brand/blob/main/tokens/token-a11y.json)

## security
- **OWASP ASVS Level 2** (`security.asvs`) — — not-assessed: no OWASP ASVS attestation supplied — [provenance](https://robertdelanghe.dev/provenance)
- **known critical/high vulns** (`security.no-critical-vulns`) — ✓ met: 0 known critical/high vulns — [workflow: brand-checks.yml](https://github.com/bdelanghe/site/actions/workflows/brand-checks.yml)
- **HSTS preload** (`security.hsts-preload`) — — not-assessed _(recommended)_: no HSTS preload status supplied — [provenance](https://robertdelanghe.dev/provenance)

## performance
- **Core Web Vitals (p75)** (`performance.core-web-vitals`) — — not-assessed: no Core Web Vitals field data supplied — [provenance](https://robertdelanghe.dev/provenance)

## compatibility
- **Baseline Widely Available** (`compatibility.baseline`) — ✓ met: Baseline Widely Available — [workflow: conformance.yml](https://github.com/bdelanghe/site/actions/workflows/conformance.yml)

## reliability
- **runtime reliability** (`reliability.runtime`) — — not-assessed: no runtime reliability report supplied — [provenance](https://robertdelanghe.dev/provenance)

## semantic
- **JSON-LD 1.1 + SHACL conformance** (`semantic.jsonld-shacl`) — ✓ met: JSON-LD 1.1 conforms to SHACL shapes (0 violating blocks) — [workflow: shacl.yml](https://github.com/bdelanghe/site/actions/workflows/shacl.yml)
- **CommonMark conformance** (`semantic.commonmark`) — — not-assessed: no CommonMark report supplied — [workflow: seo.yml](https://github.com/bdelanghe/site/actions/workflows/seo.yml)
- **AI-readability** (`semantic.ai-readability`) — ✓ met _(recommended)_: llms.txt present, links resolve, Markdown siblings exposed — [llms.txt](https://robertdelanghe.dev/llms.txt)
- **OpenAPI 3.2 + JSON Schema 2020-12** (`semantic.openapi`) — — not-assessed _(recommended)_: no OpenAPI report supplied (only applies if an API is published) — [provenance](https://robertdelanghe.dev/provenance)
- **Atom feed (RFC 4287)** (`semantic.feeds`) — ✓ met _(recommended)_: Atom feed valid (RFC 4287) — [feed.xml](https://robertdelanghe.dev/feed.xml)

## seo
- **Technical SEO** (`seo.technical`) — ✓ met: canonical/titles/robots/sitemap clean, 0 broken internal links — [sitemap.xml](https://robertdelanghe.dev/sitemap.xml)

## integrity
- **SLSA provenance + in-toto** (`integrity.slsa-provenance`) — ✓ met: SLSA/in-toto provenance present, signed, and verified — [attestation.intoto.json](https://robertdelanghe.dev/attestation.intoto.json)
- **Reproducible build** (`integrity.reproducible-build`) — ✓ met: build is byte-reproducible — [bdelanghe/site: flake.lock](https://github.com/bdelanghe/site/blob/main/flake.lock)
- **SPDX SBOM** (`integrity.sbom`) — ✓ met: SPDX SBOM present, valid, complete, and signed — [sbom.spdx.json](https://robertdelanghe.dev/sbom.spdx.json)
- **Content digests (RFC 9530)** (`integrity.content-digests`) — ✓ met _(recommended)_: Repr-Digest headers present (RFC 9530) — [provenance](https://robertdelanghe.dev/provenance)
- **Signed release manifest** (`integrity.signed-release-manifest`) — ✓ met: release manifest present and signed — [site.sha256](https://robertdelanghe.dev/site.sha256)
- **IPFS CID recorded** (`integrity.ipfs-cid`) — ✓ met _(recommended)_: IPFS CID recorded — [provenance.json](https://robertdelanghe.dev/provenance.json)
- **HTTP correctness (RFC 9110)** (`integrity.http-rfc9110`) — — not-assessed _(recommended)_: no RFC 9110 HTTP report supplied (optional) — [provenance](https://robertdelanghe.dev/provenance)
- **OpenSSF Scorecard** (`integrity.scorecard`) — — not-assessed _(recommended)_: no OpenSSF Scorecard result supplied — [provenance](https://robertdelanghe.dev/provenance)
- **SLSA build level** (`integrity.slsa-level`) — — not-assessed _(recommended)_: no SLSA build level supplied — [provenance](https://robertdelanghe.dev/provenance)

## cognitive
- **Interface-complexity budget (W3C COGA-derived)** (`cognitive.complexity-budget`) — ✓ met _(recommended)_: lone static checks clean (no findings) — [api/v1/conformance.json](https://robertdelanghe.dev/api/v1/conformance.json)
- **COGA Obj-5: Focus budget (attention proxy)** (`cognitive.focus-budget`) — ✗ unmet _(recommended)_: not-yet-met: readingGrade threshold exceeded, avgSentenceLength threshold exceeded, jargonDensity threshold exceeded. AGENT/STATIC PROXY for COGA Obj-5 — NOT COGA usability testing with cognitive disabilities. Do NOT mass-rewrite content — editorial is the maintainer's call; gate reports honestly. — [workflow: a11y-heuristic.yml](https://github.com/bdelanghe/site/actions/workflows/a11y-heuristic.yml)
- **COGA usability testing** (`cognitive.coga-usability-testing`) — — not-assessed _(recommended)_: no COGA usability testing supplied (optional) — [provenance](https://robertdelanghe.dev/provenance)
