Guides
Practical explainers on the accessibility requirements of the BFSG and on the technical signals we check, written for website owners rather than lawyers or engineers.
01 Accessibility & BFSG
The German Accessibility Strengthening Act (Barrierefreiheitsstärkungsgesetz, BFSG) has applied since 28 June 2025. These guides explain who is affected, which barriers matter and what to do about them, with dedicated pages for the industries that ask us most often.
Work out whether the BFSG applies to your website, which exemptions exist and what your next step should be.
The free instant check: test your website against WCAG 2.1 AA in seconds and see where it meets the requirements and where it does not.
The mandatory content of an accessibility statement, where it belongs on your site and a template structure you can adapt.
Shops are expressly covered by the BFSG. The typical barriers in checkout, filters and product pages, and how to check yours.
Online appointment booking can bring a practice website into scope. What that means and which barriers matter most.
Booking and ticketing services fall within scope. The typical barriers on a hotel site and how accommodation businesses can check theirs.
Contact forms, reference galleries and simple booking functions: what craft businesses with a website need to look at.
02 Technology
Two of the six dimensions in every scan, unpacked: what we look for, why it matters and how to fix the findings you get.
What each response header does, which ones your site should send and how to configure them correctly.
Cookies, trackers and third-party requests: which signals we read from a page and what they say about your privacy setup.
03 Security headers in depth
The header hub gives you the overview. These pages go one level deeper into the eight topics that take the most work to get right, each with the directives that matter, a copy-paste starting point and the questions we get asked most. Two more cover the part after go-live: noticing when a header or a policy changes without anyone deciding it should.
The strongest defence against cross-site scripting: which directives to set, how to roll a policy out in report-only mode and how to reach an enforcing policy without breaking your site.
Strict-Transport-Security explained: what max-age, includeSubDomains and preload actually do, and why the preload list is a decision you cannot quickly undo.
Secure, HttpOnly and SameSite: the cookie attributes that keep a session out of reach of scripts and cross-site requests, with the settings for a typical stack.
How an invisible overlay turns a visitor click into an action on your site, and the two headers that stop it: X-Frame-Options for older clients, frame-ancestors for everything else.
Which part of your URLs travels to other sites when a visitor clicks away: the five policy values that matter, what each one gives up and the one to set by default.
Switch off camera, microphone, geolocation and payment for your site and everything it embeds: the allow-list syntax, and why a feature you did not name is not a feature you turned off.
The records that stop someone sending mail in your name, and the one that keeps your DNS answers honest: what each does and the order to introduce them in.
The file that tells a researcher where to report a vulnerability. Two mandatory fields, ten minutes of work, and the difference between a private report and a public one.
A header that is right today can be gone after the next deploy. Three ways to notice: a cron job with curl, a check in your CI pipeline and a scheduled scan, with what each of them catches and misses.
How a policy changes quietly through deploys, plugins and CDN rules, and how to catch it: a header diff, violation reports through report-to, and what a scan comparison can and cannot show.
04 Server recipes
The topic guides explain what to set and why. These pages give you the finished block for your stack, line by line, with the mistakes that make a configuration look right and send nothing.
A complete server block to paste, what each add_header line does, and the inheritance rule that silently removes every header as soon as one location defines its own.
The .htaccess block to paste, why mod_headers has to be enabled first and what the difference between set and always means for your error pages.
Every header with a few lines and no plugin, in a place a theme update cannot remove, plus the one policy that will break your block editor.
The web.config block to paste, what each customHeaders entry does and why a web.config in a subfolder leaves you with the same header twice.
Every header from one configuration array and no extension, why the backend needs a policy of its own and which files never reach TYPO3 at all.
A response subscriber that covers the whole storefront, why the administration has to be excluded and what a strict policy does to your payment providers.
The one field where your directives survive, why editing the generated vhost file is pointless and what proxy mode changes about duplicates.
05 Tool
A guided form walks you through every mandatory field and produces a ready-to-adapt statement text block. The preview is free.
Run a free scan and get a plain-language report on accessibility, security, privacy, sustainability, SEO and performance.