Zylyn Documentation

Zylyn Portal — User Guide

The complete guide in one document — every chapter, in order.

Verified against the live portal · 12 September 2026 · zylyn.co/guides

Back to the browsable guide

Zylyn Portal — User Guide

Everything you need to run accessibility scans, read the results, and keep your site conformant.

Last verified against the live portal: 2026-09-12.

New here? Start with these three#

  1. Getting started — create your account, add your first site, run your first scan. About ten minutes.
  2. Reading your report — what Violations, Alerts, Passes and Incomplete mean, and which numbers actually matter.
  3. Credits and plans — what each action costs, so nothing surprises you.

Looking something up?#

Quick reference has every credit cost, every plan limit, the report buckets, severity order, AI fix statuses, and a "where do I find…" table — all on one scannable page. Bookmark that one.

Use the search box in the sidebar (or press ⌘K / Ctrl K) to jump straight to any section.

Guides#

GuideWhat it covers
Getting startedAccount, login, first site, first scan
The dashboardSite score, grade, trend chart, recent scans
Running scansSitewide, single page, re-audit, loose scans, scheduling
Reading your reportResult buckets, severity, WCAG references, affected elements
AI fix suggestionsHow they work, the four statuses, and why you must review them
Exporting and sharingPDF, CSV, email, logging defects
Checking PDFsPDF/UA-1 document conformance
Scanning pages behind a loginThe Zylyn browser extension
Teams and agenciesSeats, shared credits, client accounts, white-label
Enterprise & governanceAI prioritisation, role-based access, policy thresholds, scheduled reporting, manual audits, VPAT
Rollout planThe seven stages, a realistic first quarter, and why timing drives cost

Reference#

PageWhat it covers
Quick referenceEverything on one page — costs, plans, buckets, severities, statuses
Credits and plansEvery credit cost, every plan, worked examples
Screens and navigationEvery portal screen and what lives where
Troubleshooting and FAQCommon problems and blunt answers
Accessibility glossaryWCAG, ADA, PDF/UA and the rest, in plain English

What Zylyn does, in one paragraph#

Zylyn scans web pages against WCAG 2.2 — the international accessibility standard — and tells you what is broken, how serious it is, which exact element is at fault, and how to fix it. You can scan one page or a whole site, on demand or on a schedule, and track whether your score is improving over time. Automated scanning finds a meaningful share of problems but not all of them; see what scanning can and cannot find.

Two things worth knowing up front#

Everything is metered in credits. Scanning a page costs 1 credit, adding a site costs 10, and exports cost 1 each. A free account starts with 100 credits. See credits and plans before you start a large scan.

VPAT generation is not available yet. You will see "Sitewide VPAT — Soon" and a "Generate & view VPAT" button on reports. These are not live. If you need a VPAT or ACR today, contact the Zylyn team directly.

Getting started

Ten minutes from nothing to your first report.

1. Create your account#

Go to zylyn.co and click Log in in the top-right, then switch to the Register tab.

The login dialog. Use the Register tab for a new account, or sign in with Google or LinkedIn.
The login dialog. Use the Register tab for a new account, or sign in with Google or LinkedIn.

You need three things: full name, email, password. You can also use Continue with Google or Continue with LinkedIn instead.

There is no email confirmation step — you are signed in and taken straight to the portal.

Your new account starts with 100 free credits and room for one site.

2. Add your first site#

In the portal, click Add a site on the dashboard (or open the site selector in the top bar and choose Add site).

Adding a site. Enter the root URL — Zylyn finds the pages itself.
Adding a site. Enter the root URL — Zylyn finds the pages itself.

Enter the root URL, for example https://yoursite.com. You do not need to list individual pages.

Cost: 10 credits. This includes discovering your pages.

What happens next: Zylyn looks for your sitemap.xml and falls back to a shallow crawl if there isn't one, then builds a list of every page it found. You'll see the count immediately — a 51-page site takes a few seconds.

3. Run your first scan#

You have two sensible options.

Scan one page first (1 credit). Recommended. Open Pages, find your homepage, click Scan. You get a full report in about ten seconds and you've spent one credit finding out whether the output is useful to you.

Scan the whole site (1 credit per page). Open Pages and click Scan all pages. You'll get a confirmation showing exactly how many pages and credits are involved before anything is charged.

Scans run in the background. You can navigate away and come back.

4. Read the report#

Click any page in the Pages list to open its report. Start with reading your report — the short version is that Violations are real problems, Incomplete means "a human needs to check this", and the severity labels tell you what to fix first.

5. Decide what happens next#

  • Fix things yourself? Use AI fix suggestions to get corrected markup per finding, then hand it to whoever maintains your site.
  • Send it to a developer? Export to PDF or CSV.
  • Keep it from regressing? Turn on scheduled scanning.
  • Want expert help? Every report has a Request remediation help button.

Common first-run questions#

Does scanning change my website? No. Zylyn only reads your pages.

Do I need to install anything? Not for public pages. Only for pages behind a login.

Why is my score not 100? Almost no site scores 100 on a first scan. Zylyn's own site scores 92. See what a good score looks like.

The dashboard

Your site's accessibility health on one screen. Open it from Overview in the left sidebar.

The dashboard: average score, pages scanned, open issues, letter grade, trend chart, and recent scans.
The dashboard: average score, pages scanned, open issues, letter grade, trend chart, and recent scans.

The four numbers at the top#

NumberWhat it means
Average scoreMean score across every page that has been scanned, with the page count beside it
Pages scannedHow many of your discovered pages have actually been scanned — e.g. 44 / 51
Open issuesTotal unresolved findings across the site
Site score + gradeThe headline 0–100 score with a letter grade and label, e.g. 92 · B grade · GOOD

Watch the "pages scanned" ratio. If it reads 44 / 51, your average score only reflects those 44 pages. Seven pages have never been scanned and could be worse than the rest. A high score across a fraction of your site is not a clean bill of health.

What is a good score?#

Honestly: most sites land in the 70s and 80s on a first scan, and that is normal rather than alarming.

  • 90–100 — Good. Remaining issues are usually best-practice items rather than WCAG failures.
  • 75–89 — Typical. A handful of real problems, usually repeated across templates.
  • Below 75 — Worth prioritising. Likely includes contrast or labelling failures affecting every page.

Two caveats that matter more than the number:

  1. The score is not a legal compliance rating. It reflects what automated testing can measure. A high score does not mean you are ADA or WCAG compliant, and a low score does not mean you are being sued tomorrow.
  2. The score counts best-practice rules alongside genuine WCAG failures. A page can score in the 80s while having only one or two actual WCAG violations. Read the findings, not just the number. See reading your report.

Score over time#

The trend chart plots your rolling sitewide score. It becomes useful after a few weeks of scheduled scans — with a single scan there is nothing to trend.

Use it to answer one question: is this getting better or worse? A gradual decline usually means new pages are shipping with problems the rest of the site already fixed.

Recent scans#

The most recently scanned pages, each with score, issue count, and when it ran. Click any row to open the full report. View all takes you to the complete Pages list.

Buttons in the top bar#

  • Run new scan (1 credit) — scan any single URL, including one on another domain
  • Site selector — switch between sites, or add one
  • Install Zylyn extension — for pages behind a login
  • Sitewide VPAT — SOON — not available yet

Running scans

Five ways to scan, and when to use each.

The Pages list#

Pages in the sidebar lists every page Zylyn discovered on your site, with its score, issue count, trend, and when it was last scanned.

The Pages list. Each row shows score, issues, trend and last scan, with a Scan button per page.
The Pages list. Each row shows score, issues, trend and last scan, with a Scan button per page.

Pages that have never been scanned show — and read "Not scanned yet".

1. Scan a single page — 1 credit#

Click Scan on any row. Takes about ten seconds. Best for checking one fix or trying the product.

2. Scan the whole site — 1 credit per page#

Click Scan all pages at the top of the Pages list. You'll get a confirmation first:

Nothing is charged until you confirm. Scans run in the background — leave the page if you like.

3. Scan any URL on demand — 1 credit#

Run new scan in the top bar accepts any URL, including one on a domain you haven't added.

The Run new scan dialog. Paste any URL, or tick the box for pages behind a login.
The Run new scan dialog. Paste any URL, or tick the box for pages behind a login.

Tick This page is behind a login to route the scan through the browser extension instead.

4. Loose scans#

A scan of a URL you haven't added as a tracked site is called a loose scan and appears under Loose scans. Handy for spot-checking a page before committing a site.

When you later add that domain as a site, existing loose scans fold into it automatically.

5. Re-audit after a fix — 1 credit#

Open any report and click Re-audit. This is how you confirm a fix worked. The page keeps its history, so the trend column shows the improvement.

Schedule automatic re-scans#

Settings → Scanning. Choose Daily, Weekly, Monthly, or Manual (off) per site.

Scan scheduling, set per site. Manual is the default until you change it.
Scan scheduling, set per site. Manual is the default until you change it.

Scheduling is off by default — nothing recurring happens until you turn it on.

Cost: ~1 credit per page per run. Budget carefully:

Site sizeWeeklyDaily
50 pages~215 credits/mo~1,500 credits/mo
500 pages~2,150 credits/mo~15,000 credits/mo

Weekly is the right default for most sites. Daily only makes sense if you deploy constantly.

Scans pause automatically when credits run out rather than failing silently or overbilling.

Re-discovering pages — 2 credits#

Sitemaps shows how many URLs Zylyn found and the method used.

The Sitemaps screen. Sitemap-first with a shallow crawl fallback.
The Sitemaps screen. Sitemap-first with a shallow crawl fallback.

Click Re-discover pages after launching new sections so they enter monitoring. New pages are not picked up automatically between discoveries.

If a scan fails#

Failed scans are refunded automatically — you'll see a "Refund — Website scan" line in credit history. You don't need to ask.

Pages that are login-gated, JavaScript-only shells, or blocked by robots rules are the usual failures. Use the extension for the first case.

Reading your report

The most important page in this guide. Click any page in Pages to open its report.

A scan report: score, result buckets, severity breakdown, per-finding detail with the exact failing element.
A scan report: score, result buckets, severity breakdown, per-finding detail with the exact failing element.

The four result buckets#

BucketWhat it meansDo you act?
ViolationsDefinite problems. Zylyn is confident these break accessibility.Yes — this is your work list.
AlertsThings that are probably fine but worth a look.Review if you have time
PassesChecks your page passed.No — this is reassurance
IncompleteZylyn could not decide. Needs human judgement.Yes — have someone look

Do not ignore Incomplete. It does not mean "fine". It means the scanner hit something it cannot evaluate — text over a background image, a control whose purpose depends on context. These are often real problems that automation cannot confirm.

You may also see Partial coverage near the score. That flags that some content — typically third-party iframes — could not be scanned, and the report is for what Zylyn could reach.

Severity: what to fix first#

Four levels, and they are a genuine priority order:

SeverityMeaningPriority
CriticalBlocks people from using the page at allFix now
SeriousMajor barrier; many users affectedFix this sprint
ModerateReal but works around-ableBacklog
MinorPolishWhen convenient

Fix Critical and Serious first. They are both the largest real-world barriers and the findings that appear in legal complaints.

WCAG failures versus best practice#

This trips people up, so it's worth being precise.

Each finding is tagged either with a WCAG level and criterion (e.g. WCAG AA · 1.4.3) or with WCAG BEST PRACTICE.

  • A tagged criterion = a failure against the actual standard. This is what conformance and legal exposure are judged on.
  • BEST PRACTICE = a recommendation that improves accessibility but is not a WCAG failure. Examples: "Document should have one main landmark", "All page content should be contained by landmarks", "The skip-link target should exist and be focusable".

Both are worth fixing. But if someone asks "are we WCAG conformant?", only the tagged criteria answer that question — and a page can look alarming while having only one or two real failures. When reporting to a client or a board, count the WCAG-tagged findings, not the raw total.

Per-finding detail#

Expand any finding and you get:

  • Plain-English explanation of the rule, plus a Learn more link to the full documentation
  • Affected elements, each with its CSS selector and the actual markup from your page
  • The precise problem. Contrast findings include the measured ratio, both colours, font size and weight, and the required ratio — for example:

That is enough for a developer to fix without guessing. Hand them the selector and the numbers.

Where a finding affects many elements, the report shows the first five and tells you the total.

What automated scanning cannot find#

Be clear-eyed about this, because it determines how much assurance a clean report gives you.

Automated tools reliably cover roughly 20–40% of WCAG success criteria. They are excellent at mechanical checks — missing alt text, contrast ratios, unlabelled form fields, heading structure. They cannot assess:

  • Whether alt text is meaningful (alt="image123" passes; it helps nobody)
  • Whether keyboard focus order makes logical sense
  • Whether a screen reader announces a custom control usefully
  • Whether an error message actually tells the user how to recover
  • Whether your content is understandable

A 100/100 score does not mean your site is accessible. It means the machine-checkable part is clean. For conformance you can defend, you need manual testing with assistive technology — use Request remediation help on any report.

Actions available on a report#

ActionCostWhat it does
Re-audit1 creditRe-scan to verify a fix
Log defectFreeTrack the finding as a defect
Export PDF1 creditFormatted report — see exporting
Export CSV1 creditSpreadsheet of findings
Email1 creditSend the report
Generate AI fix suggestions2 credits per findingSee AI fix suggestions
Generate & view VPAT—Not available yet ("Soon")
Request remediation helpFreeContact the Zylyn team

AI fix suggestions

Zylyn can generate corrected markup for each finding, based on your page's actual elements rather than generic advice.

How to generate them#

Open a report and click Generate AI fix suggestions.

Cost: 2 credits per finding. Suggestions are cached, so findings that have been generated before are free — the button tells you before you click, e.g. "2 of 3 already available at no cost", and charges only for the rest.

Generation takes under a minute. Suggestions appear inside each finding as they complete.

The four statuses#

This is the part to understand, because the status tells you how much you can trust the suggestion.

StatusWhat it meansWhat to do
Applied / readyA safe, complete fix was produced and self-validatedReview, then apply
Needs your inputComplete except for a [PLACEHOLDER]Replace the placeholder with your own wording
Dev requiredNo safe automatic patch exists; options are listedHave a developer decide
DecideAutomated validation could not confirm the changeReview manually before applying

A worked example of Needs your input — an ARIA progressbar with no accessible name:

Zylyn cannot know what your progress bar measures. It writes the correct attribute and leaves the label to you. Do not ship the placeholder.

A worked example of Dev required — a contrast failure:

The suggestion is specific and correct, but the colour is a shared design token — changing it affects every element using it. That is a decision, not a patch.

Always review before applying#

The portal says this in three places, and it means it. These are AI-generated suggestions, not verified patches. Specifically:

  • A suggestion can be technically valid but wrong for your design (the contrast example above)
  • Adding an aria-label with the wrong wording is worse than no label — it misleads screen reader users confidently
  • Changing shared tokens or components has effects beyond the page you scanned

Treat a suggestion as a well-informed pull request from a contributor who has only seen one page of your site. Read it, understand it, then apply it.

What they're good for#

  • Turning findings into something actionable for someone who isn't an accessibility specialist
  • Speed on mechanical fixes — alt text, labels, ARIA attributes, heading levels
  • Teaching. Reading the suggestions is a fast way to learn why something failed

What they're not good for#

  • Structural problems (landmarks, focus order, page architecture)
  • Anything touching shared components or design tokens
  • Replacing manual testing — a fix that satisfies the scanner can still be unusable with a screen reader

Exporting and sharing

Getting findings out of the portal and to whoever will fix them.

Your options#

ActionCostBest for
Export PDF1 creditClients, managers, anyone who needs a document
Export CSV1 creditDevelopers; importing into Jira, Linear, or a spreadsheet
Email1 creditSending straight to a colleague
Log defectFreeTracking a finding inside Zylyn

All four are on every report.

Which format to use#

CSV for anyone who will fix things. One row per finding with the WCAG criterion, severity, selector, and description — paste it into your tracker and assign rows. This is the highest-leverage export.

PDF for anyone who will read rather than act. Formatted and readable, good for a client update or a compliance file. Bad as a work list: nobody wants to copy selectors out of a PDF.

Sharing with a client#

The honest framing matters here. If you hand a client a raw report, lead with:

  1. Which findings are actual WCAG failures, separated from best-practice items — see WCAG failures versus best practice. Reporting a total that mixes both overstates the problem.
  2. What the score does and doesn't mean. It is not a compliance certification.
  3. What still needs manual testing. Automated scanning covers 20–40% of WCAG criteria.

A client who is told "you have 23 issues and score 74%" panics. A client who is told "two real WCAG failures, both one-line template fixes, plus some structural improvements worth doing" acts.

Logging defects#

Log defect records a finding as tracked work inside Zylyn, at no credit cost. Useful when you want history in one place rather than exporting into an external tracker.

A note on privacy#

Reports contain fragments of your page markup, since that's what makes findings actionable. For public pages this is content anyone can view. For pages scanned via the browser extension, snippets can come from private screens — those reports are never given a public link and email addresses and long digit sequences are automatically redacted. Reports are still visible to everyone on your account, and to your managing agency if you have one.

Checking PDFs

PDFs are a common accessibility gap and a frequent source of complaints. Zylyn checks them against PDF/UA-1, the accessibility standard for PDF documents.

The PDF documents screen. Upload a file or paste a URL.
The PDF documents screen. Upload a file or paste a URL.

Why this matters#

Most site audits stop at HTML. But if your contracts, forms, menus, reports, or brochures are PDFs, a screen reader user may be locked out of the most important content you publish — and document accessibility is regularly cited in legal complaints and procurement reviews.

How to check one#

Open PDF documents in the sidebar, then Add a PDF to scan. You can upload a file or paste a URL.

Cost: 2 credits per page. Note per page of the document, not per document — a 20-page report costs 20 credits. Check your balance before submitting a long one.

The five stages of a document check#

#StageWhat happens
1PDF submittedUploaded individually, or pulled from a monitored library
2Accessibility analysisStructure, language, metadata, contrast and alternative text checked
3Tag validationSemantic tags verified for headings, lists, tables and form fields
4Reading orderLogical sequence confirmed against the visual layout
5Compliance reportFindings, severity and guidance issued as a dated record

What gets checked#

PDF/UA-1 conformance, which in practice means:

  • Tags — whether the document has a proper structure tree (the PDF equivalent of headings and landmarks)
  • Reading order — whether content is ordered logically for assistive technology
  • Alternative text on images and figures
  • Table structure — header cells properly associated with data cells
  • Document language and title metadata
  • Bookmarks for longer documents

The four failures that account for most of it#

FailureWhy it breaksFix
Untagged documentsA formatted PDF with no tag tree is unreadable in any meaningful order. The most common failure in enterprise document sets.Re-export from source with tags enabled
Scanned images of textArchived forms stored as flat images carry no text layer at allFlagged for OCR and re-issue
Fields without labelsInteractive PDFs where fields have no accessible name leave assistive technology users guessingAdd field names in the form editor
Tables without headersStatement and pricing tables lose all meaning without row and column header associationsMark header rows/columns in the tag tree

The most common problem#

A PDF exported straight from Word, Canva, or InDesign without accessibility settings enabled is usually untagged, and an untagged PDF is close to unusable with a screen reader.

The fix is generally not in Zylyn — it's in your source document:

  1. Use real heading styles in the source, not manually enlarged bold text
  2. Add alt text to every image before exporting
  3. Export using "Save as PDF" with document structure or accessibility tags enabled, not "Print to PDF"
  4. For an existing PDF with no source file, remediation means retagging in Acrobat Pro or similar — that's specialist work, and Request remediation help is the right route

Practical advice#

Don't scan every PDF you have. Start with the ones that matter: anything a customer must read to transact with you — application forms, price lists, terms, menus, statements. A decorative brochure matters less than the form someone needs to complete to become your customer.

Scanning pages behind a login

Zylyn's servers cannot reach pages that require a login — dashboards, account settings, checkout steps, member areas. The Zylyn browser extension solves this by running the scan inside your own browser, in a tab you're already signed in to.

This matters because the highest-value accessibility defects usually live behind the login. Marketing pages get designed carefully; account settings screens rarely do.

Installing it#

Click Install Zylyn extension in the portal's top bar, or find Zylyn Accessibility Scanner in the Chrome Web Store. Chrome only at present — no Firefox or Edge build.

Using it#

  1. Log in to the site you want to test, as you normally would
  2. Navigate to the page you want to scan
  3. Click the Zylyn icon, or right-click and choose Scan this page with Zylyn
  4. Pick which Zylyn account the result should be saved to
  5. Results upload to your portal and appear alongyour other reports

You can also tick This page is behind a login in the Run new scan dialog to register the page for extension scanning.

What it collects#

Worth knowing, since it runs on pages containing your data:

It collects, only when you click scan: the page URL and title, your browser's viewport size, the scan findings, short truncated HTML snippets (~150 characters) of failing elements, your Zylyn account and user ID, and the request's IP and user agent.

It does not collect: your browsing history, any page you didn't explicitly scan, cookies, passwords, authentication tokens, session data, text you typed into forms, screenshots, keystrokes, mouse movement, or in-extension analytics.

Your credentials never leave your browser. The extension reads the rendered page, not your session.

Privacy on private pages#

Because findings include markup, a snippet can contain content only you can see. Zylyn applies three safeguards:

  • Automatic redaction of email addresses and long digit sequences (account or card numbers) before storage. This is described as an automated safeguard, not a guarantee — it cannot catch every possible form of personal data.
  • Extension scans are never made public. Unlike public-page scans they get no shareable link, no screenshot, and are not sent to Zylyn's CRM.
  • Same-site frames only. Content embedded from other domains is counted but not scanned, and the report tells you when coverage was partial.

The extension requests access to the Zylyn API only — not to the sites you scan — and the accessibility engine is bundled at a pinned version, so it never downloads or executes remote code.

Scan responsibly#

  • Only scan systems you're authorised to access
  • Prefer a dedicated test account over your real one wherever possible, especially on anything containing customer data
  • Remember that scan reports are visible to everyone on your Zylyn account, and to your managing agency if your account is managed by one

Cost#

Extension scans are charged against the same credit balance as any other scan — 1 credit per page.

Teams and agencies

Sharing an account with colleagues, or running accessibility for a portfolio of clients.

Inviting colleagues#

Settings → Team. On the free and Individual Lite plans you'll see:

Team seats start at Individual Pro ($99/mo) — up to 5 members with a shared credit pool. See credits and plans.

How sharing works#

Everyone on an account shares:

  • The same sites and their scan history
  • One credit pool. A colleague running a 500-page scan spends credits you were saving. Agree a convention before you invite people.
  • All reports. There is no per-member visibility control — anyone on the account sees every report, including any scanned via the extension from private screens.

That last point is worth a moment's thought before inviting someone outside your immediate team.

Agency plans#

Agency tiers (from $199/mo) add two things that matter if accessibility is a service you sell:

White-label branding. Client-facing reports and the portal carry your logo and colours. Zylyn does not appear. Your clients see your brand.

Client accounts. Each client's sites are separated, so you can hand a client their own view without exposing your other clients' data, and manage the whole portfolio from one login.

PlanPriceSitesMembersCredits/mo
Agency · Lite$199/mo101515,000
Agency · Pro$299/mo202525,000
Agency · Max$599/mo405060,000

If your account is managed by an agency#

Be aware of one thing: your reports are visible to that agency. This is by design — they need to see findings to do the work — but it includes reports from pages scanned behind your login. If you scan a private screen containing customer data, your agency can see the captured markup snippets.

Use a test account for anything sensitive.

Practical advice for agencies#

Budget credits per client, not per month. Work out each client's page count × scan frequency before you price the retainer. A 500-page client scanned weekly is ~2,150 credits/month — a significant share of Agency Lite's 15,000 across ten clients.

Set schedules deliberately. Ten clients all on daily scanning will exhaust an Agency plan quickly. Weekly is almost always sufficient; reserve daily for clients deploying continuously.

Don't hand over raw scores. A client seeing "74% — POOR" will panic at something that may be two template fixes. Lead with the WCAG-tagged findings and what they cost to fix. See sharing with a client.

Enterprise and governance features

Everything documented elsewhere in this guide was verified in the self-serve portal. This page covers the capabilities that come with Professional and Enterprise engagements, which are configured with your Zylyn contact rather than switched on from the billing screen.

The three engagement tiers#

Alongside the self-serve plans in credits and plans, Zylyn sells three engagement tiers for larger estates:

TierForIncludes
StarterA single site, proving the case internallyAutomated scanning for one property, 100+ WCAG 2.2 automated checks, monthly scan cadence, AI-prioritised issue queue, developer fix guidance, PDF and CSV export, score history
ProfessionalMulti-property estates with an active remediation programmeEverything in Starter, plus multiple properties and environments, browser extension for authenticated pages, weekly monitoring and regression alerts, PDF and document accessibility, historical trend reporting, role-based access for delivery teams, scheduled email reporting
EnterpriseRegulated organisations answerable to auditors and procurementEverything in Professional, plus expert manual audits, VPAT and conformance reports, managed remediation by Zylyn engineers, governance policies and thresholds, executive and board reporting, a named accessibility lead

Enterprise is priced per estate rather than per seat or per site.

AI prioritisation#

Rather than handing you a flat list of findings, the platform can rank them so the order of work is decided before it reaches a developer. Findings are ranked by:

  • User impact — how many people the barrier actually blocks
  • Legal exposure — how likely the finding is to appear in a complaint
  • Page value — traffic and commercial importance of the affected page
  • Repair effort — how much work the fix represents

The practical effect: a team of four learns which twelve issues matter this sprint instead of triaging several hundred.

Duplicate findings that repeat across templates are clustered, so one template-level defect appears as one item rather than once per page.

Where humans still decide: judgement calls on alternative text, cognitive load, assistive technology behaviour, and any formal conformance claim. See AI fix suggestions for the same principle applied to individual fixes.

Assignment and ownership#

Findings can carry an owner and a due date, so the queue behaves like a work tracker rather than a report. Severity maps onto standard priority fields, which means findings can be triaged into an existing sprint process without re-writing them.

Resolved findings are verified automatically on the next scan rather than closed on trust.

Role-based access#

Permissions can be scoped by role and by property, covering:

  • Executives — score, coverage and trend
  • Accessibility managers — the full programme
  • Developers — the ranked queue and the fix detail
  • External auditors — read access to the evidence trail

This matters if your account spans teams who should not all see everything. On the self-serve plans there is no per-member visibility control — every member of an account sees every report — so if segregation is a requirement, raise it during onboarding.

Estate management#

Properties can be grouped by brand, region or business unit, each with its own conformance target, owner and reporting cadence. Multi-property rollup gives one view across the group.

Useful when "our website" is really forty sites with different owners and different levels of maturity.

Policy thresholds and drift alerts#

Define the minimum score and the maximum critical-issue count a property is allowed to carry, then get alerted when either drifts past the line.

This is the difference between monitoring and governance: a threshold turns "the score went down" into an event someone owns.

Scheduled reporting#

Two cadences, delivered without anyone assembling a deck:

  • Weekly engineering digests — the ranked queue, what moved, what regressed
  • Monthly executive summaries — written in outcomes rather than error codes

What gets reported to whom#

AudienceReported
LeadershipAccessibility score by property, open issues against threshold, quarter-on-quarter trend, conformance posture per regulation, and the age of the oldest unresolved critical finding
Delivery teamsRanked queue with owner and due date, failing selector and criterion per finding, fix guidance, verification status on re-test, and regressions introduced by the most recent release

That last leadership metric — age of the oldest unresolved critical finding — is worth adopting whatever tier you are on. It is the single number that exposes a programme quietly stalling.

Manual audits#

Certified specialists test with assistive technology and record findings against the same criteria as the scanner, so manual results sit alongside automated ones rather than arriving as a separate PDF.

This is the part that covers what automation cannot reach — see what automated scanning cannot find.

VPAT and conformance reports#

Conformance documentation produced from live platform data and reviewed by an accessibility specialist before release, intended for RFP responses and security reviews.

Evidence retention#

Scan history, audit records and conformance claims are retained for the life of the account and are exportable at any time.

The point is defensibility: a conformance claim supported by a dated record of continuous testing is a stronger position than a single audit from two quarters ago.

Managed remediation#

Zylyn engineers fix findings in your codebase when your own team has no capacity. Fixes go into your source — no overlay, no runtime patching.

If you are considering this, note the practical questions in teams and agencies about code access and vetting.

Rollout plan

How accessibility programmes actually sequence, and what to expect at each stage. Useful whether you are on the free tier or running a governed estate.

Why timing is the whole argument#

Every accessibility defect has two prices: fixing it while the code is still in a sprint, and fixing it once a complaint, a regulator letter or a stalled procurement cycle has attached a deadline to it. The second price lands in an unplanned budget.

Found atRelative cost to remediate
Design and development1×
After release, in a backlog6×
Under a procurement deadline15×
Under legal settlement terms30×+

These are directional figures based on established defect-cost economics — they frame when to invest rather than quantify any particular estate. Treat them as an argument for sequencing, not as a forecast.

The seven stages#

Nobody starts with a governance programme. They start with one URL and a question.

#StageWhat happens
1Free scanOne URL, about ninety seconds, no commitment
2Accessibility reportA score, a severity breakdown and the failing criteria
3AI prioritisationThe queue ordered by impact, risk and effort
4Developer fixesGuided remediation, verified on re-test
5Manual auditSpecialist testing for what automation cannot judge
6Continuous monitoringOngoing scanning with alerts on regression
7Enterprise governancePolicies, owners, thresholds and board reporting

Each stage produces something useful on its own. You do not need to commit to stage 7 to benefit from stage 2.

A realistic first quarter#

Weeks 1–2 — establish the baseline#

Register your properties, run the first full scan across public and authenticated pages, and agree the conformance target (usually WCAG 2.2 AA).

Do not skip the authenticated pages. A public crawler stops at the login form, and if your statements, claims and onboarding flows sit past that point, an unauthenticated scan is testing your brochure and calling it your product. See scanning pages behind a login.

Weeks 3–12 — reduce the critical count#

Work the prioritised queue, clear blocking barriers first, and verify each fix automatically on re-scan. Score movement becomes visible within the first reporting cycle.

Expect the biggest early wins to be template-level: one fix to a shared header, footer or form component often clears the same finding across hundreds of pages.

Quarter 2 onward — hold the line#

Monitoring, thresholds and scheduled reporting keep the estate from drifting back, with audits and conformance documentation layered on as procurement requires them.

Accessibility is not a state you reach, it is a state you lose. A conformant page fails the week a marketing team ships an unlabelled form or a CMS update changes heading structure.

Where to start by role#

You are…Start with
A digital leaderA baseline report on your top ten properties, with risk framed in business terms
An accessibility managerThe platform as a replacement for the audit spreadsheet and the annual PDF
A procurement teamConformance documentation, security review materials and commercial terms
A developerOne page scan, then read the report guide and check the selectors

The measure that matters#

All the scores, charts and exports exist to answer one question:

A score is a proxy for that. When the two disagree, trust the task.

Quick reference

Everything on one page. If you only bookmark one page in this guide, bookmark this one.

Credit costs#

ActionCredits
Welcome bonus on signup+100 (one time)
Add a site (includes page discovery)10
Re-discover pages on a site2
Scan one page1
Scan all pages1 per page
Scheduled re-scan~1 per page, per run
Run new scan (any URL)1
Re-audit a page1
AI fix suggestions2 per finding (cached findings free)
PDF document check2 per page of the document
Export PDF1
Export CSV1
Email a report1
Log defectFree
Request remediation helpFree

Failed scans are refunded automatically. Scans pause when credits run out.

Plans at a glance#

PlanMonthlyYearlyCredits/moSitesMembers
Free$0$0100 one-time11
Individual · Lite$49$4901,50031
Individual · Pro$99$9903,00055
Agency · Lite$199$1,99015,0001015
Agency · Pro$299$2,99025,0002025
Agency · Max$599$5,99060,0004050

Yearly = 10× monthly (two months free). Agency tiers add white-label branding and client accounts.

Sizing your plan#

Multiply pages × scans per month, then add 10 per site you add.

Site sizeWeeklyMonthlyDaily
50 pages~215~50~1,500
100 pages~430~100~3,000
500 pages~2,150~500~15,000
1,000 pages~4,300~1,000~30,000
5,000 pages~21,500~5,000~150,000

Weekly is the right default. Daily above ~2,000 pages exceeds every published plan.

Report buckets#

BucketMeaningAct on it?
ViolationsConfirmed problemsYes — your work list
AlertsProbably fine, worth a glanceIf time allows
PassesChecks that passedNo
IncompleteScanner could not decideYes — needs a human

Severity order#

Fix top to bottom.

SeverityMeaningWhen
CriticalBlocks use of the page entirelyNow
SeriousMajor barrier, many usersThis sprint
ModerateReal but workableBacklog
MinorPolishWhen convenient

WCAG failure vs best practice#

Tag on the findingWhat it means
WCAG A / WCAG AA + criterion numberA real failure against the standard. Counts for conformance and legal exposure.
WCAG BEST PRACTICEA recommendation, not a WCAG failure. Worth fixing; doesn't affect conformance.

When reporting to a client or a board, count only the tagged criteria. The headline score includes best-practice rules and weights by affected elements, so it reads far worse than your actual conformance gap.

AI fix statuses#

StatusWhat to do
Applied / readyReview, then apply
Needs your inputReplace the [PLACEHOLDER] with your own wording
Dev requiredA developer must choose between the listed options
DecideAutomated validation failed — review manually

Never apply a suggestion unread. A wrong aria-label is worse than none.

Score bands#

ScoreRead
90–100Good. Mostly best-practice items left.
75–89Typical. A few real problems, usually template-level.
Below 75Prioritise. Likely contrast or labelling failures sitewide.

A score is not a compliance certification. Automated testing reaches roughly 20–40% of WCAG success criteria.

Where things live#

I want to…Go to
See overall healthOverview
Scan a page or the whole sitePages
Scan a URL on any domainRun new scan (top bar)
See scans not tied to a siteLoose scans
Check URL discoverySitemaps
Check a PDFPDF documents
See whether we're improvingScore trends
Set up recurring scansSettings → Scanning
See where credits wentSettings → Credit history
Change planSettings → Plan & billing
Invite a colleagueSettings → Team (needs Pro or Agency)

Scan scheduling options#

Settings → Scanning, per site: Daily, Weekly, Monthly, Manual (off). Default is Manual — nothing recurring happens until you change it.

Not available yet#

FeatureStatus
Sitewide VPATLabelled "Soon" — not implemented
Per-scan VPAT reportLabelled "Soon" — not implemented

VPATs and ACRs are produced as a service. Use Request remediation help or contact Zylyn.

Free plan limits#

  • 1 site, and no delete control in the portal. Choose your first site deliberately.
  • Loose scans of a second domain are blocked by the same limit.
  • 100 credits ≈ one site plus ~90 page scans.
  • If you see "Upgrade to Agency", note that Individual Lite ($49) already gives 3 sites.

Assistive technology Zylyn's reviewers use#

NVDA and JAWS (Windows screen readers), VoiceOver (Apple), keyboard-only navigation, high-contrast mode, and 400% zoom reflow.

Credits and plans

Everything in Zylyn is metered in credits. This page tells you exactly what things cost.

Settings → Credit history. Every transaction is itemised with a running balance.
Settings → Credit history. Every transaction is itemised with a running balance.

What each action costs#

ActionCredits
Welcome bonus on signup+100 (one time)
Add a site (includes page discovery)10
Re-discover pages on a site2
Scan one page1
Scan all pages1 per page
Scheduled re-scan~1 per page, per run
Run new scan (any URL)1
Re-audit a page1
AI fix suggestions2 per finding (cached findings free)
PDF document check2 per page of the document
Export PDF1
Export CSV1
Email a report1
Log defectFree
Request remediation helpFree

Two things in your favour:

  • Failed scans are refunded automatically. You'll see "Refund — Website scan" in credit history. You don't need to ask.
  • Scans pause when credits run out rather than failing silently or overbilling you.

Credit history#

Settings → Credit history itemises every transaction with a running balance — operation, change, and resulting balance. If a number looks wrong, this is where you check.

Plans#

Settings → Plan & billing. Individual and Agency tiers, monthly or yearly.
Settings → Plan & billing. Individual and Agency tiers, monthly or yearly.

Individual#

PlanMonthlyYearlyCredits/moSitesMembers
Free$0$0100 one-time11
Lite$49$4901,50031
Pro$99$9903,00055 (shared pool)

Agency#

All Agency plans include white-label branding and client accounts.

PlanMonthlyYearlyCredits/moSitesMembers
Lite$199$1,99015,0001015
Pro$299$2,99025,0002025
Max$599$5,99060,0004050

Yearly billing is 10× the monthly price across every tier — two months free, about 17% off.

Larger estates: Starter, Professional and Enterprise#

The plans above are the self-serve tiers you can subscribe to from the billing screen. For multi-property estates, governed programmes and regulated organisations, Zylyn also sells three engagement tiers — Starter, Professional and Enterprise — which add manual audits, VPAT production, governance thresholds, role-based access and a named accessibility lead. Enterprise is priced per estate.

See enterprise and governance features. If your requirements include role-based permissions, policy thresholds or formal conformance documentation, that is the route — those are not switches on a self-serve plan.

Which plan do I need?#

Work it out from pages × scan frequency, not from the number of sites.

Your situationCredits/monthPlan
One 50-page site, weekly~215Lite ($49)
One 500-page site, weekly~2,150Pro ($99)
One 500-page site, daily~15,000Agency Lite ($199)
700-page store, weekly~3,010Agency Lite — just over Pro's cap
5,000-page site, weekly~21,500Agency Pro ($299)
5,000-page site, daily~150,000Exceeds Agency Max — talk to Zylyn

Two traps to avoid:

Daily scanning is expensive. It's offered at every tier, but on anything above ~2,000 pages it will exhaust even Agency Max. Weekly is the sensible default.

Site count can bite before credits do. If you manage twelve small client sites, you need Agency Lite for the site limit, even though twelve small sites use few credits.

Free plan limits worth knowing#

  • One site, and no way to remove it once added. Choose your first site deliberately.
  • Loose scans of a second domain are blocked by the same one-site limit.
  • 100 credits is enough to add one site and scan ~90 pages — enough to baseline a small site, not a large one.

Managing your subscription#

Settings → Plan & billing → Manage billing. Subscribe, change plan, or update payment details.

Screens and navigation

Where everything lives.

Sidebar#

MONITOR#

ScreenWhat it's for
OverviewDashboard — score, grade, trend, recent scans
PagesEvery discovered page; scan individually or all at once
SitemapsURL discovery, count, and re-discovery
PDF documentsPDF/UA-1 checks
Score trendsRolling score plus top-performing and needs-improvement rankings

WORKSPACE#

ScreenWhat it's for
SettingsCredit history, Scanning, Team, Plan & billing, Account

Also#

ScreenWhat it's for
Loose scansScans not attached to a tracked site

Top bar#

ControlWhat it does
Site selectorSwitch sites, or add one (10 credits)
Install Zylyn extensionBrowser extension for login-gated pages
Run new scanScan any URL (1 credit)
NotificationsAlerts
Account menuYour profile and logout
Sitewide VPAT — SOONNot available yet

Settings tabs#

TabContents
Credit historyItemised transactions with running balance
ScanningPer-site schedule: Daily / Weekly / Monthly / Manual (off)
TeamMember invitations — requires Pro or Agency
Plan & billingCurrent plan, all tiers, Manage billing
AccountName, email, logout

Your credit balance and an Upgrade plan link, visible on every screen. Worth glancing at before a large scan.

Not yet available#

Two VPAT surfaces appear in the product but are labelled "Soon" and do not work:

  • Sitewide VPAT on the Pages screen
  • Generate & view VPAT on individual reports

If you need a VPAT or Accessibility Conformance Report today, contact the Zylyn team — it's produced as a service, not self-serve.

Troubleshooting and FAQ

Blunt answers to the things that actually go wrong.

Scanning#

"You've reached your plan's limit of 1 site."#

You're on the free plan, which allows one tracked site — and the portal has no way to remove a site once added. This message also appears when you try a loose scan of a different domain, which is easy to mistake for a bug. You need a paid plan to scan a second domain. Note the message says "Upgrade to Agency", but Individual Lite at $49/mo already allows 3 sites — you don't need an Agency plan.

A scan failed.#

It was refunded automatically — check Settings → Credit history for a "Refund — Website scan" line. Usual causes: the page needs a login (use the extension), it's a JavaScript-only shell with no server-rendered content, or robots rules block it.

My scan is stuck / nothing is happening.#

Scans run in the background and a large site queues them. Navigate away and come back — progress shows as x / y on the dashboard. A 51-page site finishes in a couple of minutes.

New pages aren't being scanned.#

Discovery isn't continuous. Go to Sitemaps → Re-discover pages (2 credits) after launching new sections.

Contrast findings changed between scans and I didn't change anything.#

This is expected and worth understanding. Contrast checks depend on what actually rendered — viewport width, lazy-loaded content, and background images all affect the result. Contrast counts are the least reproducible metric in automated accessibility testing. Trust the trend, not a single run.

Scores#

Why isn't my score 100?#

Almost no site scores 100 on a first scan. Zylyn's own site scores 92. See what is a good score.

My score dropped and I didn't change anything.#

Check pages scanned on the dashboard. If more pages have been scanned since you last looked, the average now includes pages that were previously unmeasured. A score over 44 of 51 pages isn't comparable to one over 51 of 51.

My score says POOR but there seem to be only a couple of real problems.#

Both can be true. The score counts best-practice rules alongside genuine WCAG failures, and weights by how many elements are affected — so one best-practice rule firing on every div drags the number down hard. Count the WCAG-tagged findings to see your actual conformance gap. Don't set a remediation budget from the headline percentage.

Does a high score mean I'm ADA or WCAG compliant?#

No. It means the machine-checkable part is clean. Automated testing reaches roughly 20–40% of WCAG success criteria. Conformance you can defend needs manual testing with assistive technology.

Credits#

Where did my credits go?#

Settings → Credit history itemises every transaction with a running balance.

I ran out mid-scan.#

Scans pause automatically. Top up or upgrade and re-run — you aren't charged for what didn't run.

Why did an export cost a credit?#

Exports are metered at 1 credit each (PDF, CSV, email). Export once and share the file.

Do unused credits roll over?#

Not stated in the portal. Ask Zylyn before relying on it.

AI fix suggestions#

A suggestion contains [PLACEHOLDER].#

That's the Needs your input status — the fix is structurally complete but needs wording only you can supply, like what a progress bar measures. Replace it; don't ship the placeholder.

It says "Dev required" — is the suggestion wrong?#

No, it means no safe automatic patch exists. Typically the change touches a shared design token or component, so applying it affects more than the page you scanned. A developer should decide.

Can I apply suggestions automatically?#

No, and you shouldn't want to. They're AI-generated and require review. A wrong aria-label is worse than none — it misleads screen reader users confidently.

Reports and VPAT#

The VPAT button doesn't work.#

Correct — both Sitewide VPAT and Generate & view VPAT are labelled "Soon" and aren't implemented. VPATs and ACRs are produced as a service today. Use Request remediation help or contact Zylyn.

What's the difference between Violations and Incomplete?#

Violations are confirmed problems. Incomplete means the scanner couldn't decide and a human needs to look — it does not mean "fine". See the four result buckets.

What does "Partial coverage" mean?#

Some content — usually third-party iframes — couldn't be scanned. The report covers what Zylyn could reach.

Account and access#

Can I remove a site? Not through the portal. Contact Zylyn.

Can I invite a colleague? Not on Free or Individual Lite. Team seats start at Individual Pro.

Who can see my reports? Everyone on your account — there's no per-member visibility control — and your managing agency if you have one. This includes reports from pages scanned behind a login.

I never got a confirmation email. There isn't one. Registration signs you straight in.

I forgot my password. Use Forgot password? in the login dialog.

Getting help#

Request remediation help on any report contacts Zylyn's accessibility team. For account or billing issues, use the contact route on zylyn.co.

Accessibility glossary

The terms you'll meet in the portal, in plain English.

WCAG — Web Content Accessibility Guidelines. The international standard for accessible web content, published by the W3C. Version 2.2 is current. Almost every accessibility law in the world points at WCAG for its technical requirements.

Conformance levels: A, AA, AAA — three tiers of strictness. AA is the practical target and the level referenced by most laws and by Zylyn's scans. AAA is aspirational and rarely required wholesale.

Success criterion — a single numbered requirement within WCAG, like 1.4.3 Contrast (Minimum). When a finding is tagged WCAG AA · 1.4.3, that's the specific rule being failed.

POUR — the four WCAG principles: content must be Perceivable, Operable, Understandable and Robust.

Best practice — in Zylyn, a finding tagged WCAG BEST PRACTICE is a recommendation that improves accessibility but is not a WCAG failure. Worth fixing; doesn't count against conformance.

ADA — Americans with Disabilities Act (US, 1990). Civil rights law applied to websites through litigation rather than a fixed technical deadline. Courts generally treat WCAG AA as the benchmark.

Section 508 — US federal law requiring accessible technology in federal agencies and their suppliers. Drives the VPAT requirement in government procurement.

EAA — European Accessibility Act. Enforceable since 28 June 2025 for products and services placed on the EU market.

EN 301 549 — the European technical standard behind the EAA. Its digital core is WCAG.

AODA — Accessibility for Ontarians with Disabilities Act (Ontario, Canada).

Unruh Act — California civil rights law often used alongside the ADA in web accessibility claims.

VPAT / ACR — a Voluntary Product Accessibility Template is the blank form; a completed one is an Accessibility Conformance Report. Government and enterprise buyers often require one before evaluating a product. Not currently self-serve in Zylyn.

PDF/UA — the accessibility standard for PDF documents. See checking PDFs.

Screen reader — software that reads page content aloud for blind and low-vision users. The common ones are NVDA and JAWS on Windows and VoiceOver on Apple devices.

Assistive technology (AT) — the umbrella term: screen readers, magnifiers, switch devices, voice control, braille displays.

Alt text — the text alternative on an image, read aloud in place of the picture. Decorative images should have empty alt text so screen readers skip them; informative images need a real description.

Contrast ratio — the measured difference between text and background colour. WCAG AA requires 4.5:1 for normal text and 3:1 for large text. Zylyn reports the measured ratio and both colour values.

Landmark — a structural region of a page (main, nav, header, footer) that lets screen reader users jump straight to the part they want.

Skip link — a link at the very top of a page, often visible only on keyboard focus, that jumps past the navigation to the main content.

Focus order — the sequence in which elements receive focus as you press Tab. It should follow the visual reading order.

Focus indicator — the visible outline showing which element is focused. Removing it (a common CSS "tidy-up") makes a site unusable by keyboard.

ARIA — Accessible Rich Internet Applications: extra HTML attributes that describe custom components to assistive technology. Powerful and easy to get wrong — incorrect ARIA is worse than none.

Accessible name — the label assistive technology announces for a control. A button containing only an icon has no accessible name unless you add one.

Sources

This guide was written from direct observation of the live Zylyn portal on 2026-09-12, signed in to a real account. Nothing here is taken from marketing copy or a roadmap.

Screens verified#

ScreenRouteScreenshot
Login / Register dialogzylyn.coview
Dashboard / Overview/portalview
Pages list/portal/pagesview
Score trends/portal/trendsview
PDF documents/portal/pdfview
Sitemaps/portal/sitemapsview
Settings — Credit history/portal/settingsview
Settings — Scanning/portal/settingsview
Settings — Plan & billing/portal/settings#billingview
Scan report (with findings)/portal/scans/128440view
Run new scan dialog—view
Add a site dialog—view

Also verified without a screenshot: Loose scans (/portal/loose), Settings — Team (gated behind a paid plan), Settings — Account.

Zylyn Portal User Guide · verified 12 September 2026 · the browsable version lives at zylyn.co/guides.