Standards
We hold this site to the standard we hold yours to. The build fails if it slips.
Every promise on this page is a gate in our pipeline, not a sticker. We won't ship a regression — and we won't show you a score we haven't earned.
The bar
Targets, enforced — not trophies on a shelf.
These are the thresholds every build clears before it ships, this site included. We deliberately don't paint them green: a number only counts when it's measured live, on the real domain.
The same bar applies to your work. Every project we ship inherits this pipeline — your build fails on the same gates ours does.


Posture
Privacy and security by construction.
Not a setting you switch on — the absence of the machinery that would compromise it.
Privacy & data
- Self-host everything — fonts, icons, assets, scripts. Visitors never talk to a third party.
- No cookies, no tracking — nothing to consent to, so no banner.
- EU infrastructure, data minimised, logs anonymised and short-lived.
- Privacy-first stats only — cookieless, no personal data — and only if asked.
Security
- HTTPS-only, HSTS, strict CSP (
default-src 'self'), modern headers. - Least-privilege access; dependencies audited and kept current.
- Backups with tested restores — a backup we've never restored isn't a backup.
- Coordinated disclosure via a published security.txt (upcoming) — found something? Email us.
Accessibility statement
We aim for WCAG 2.2 AA.
We want everyone to be able to use what we build. Accessibility here is a voluntary aim we hold ourselves to: this site targets WCAG 2.2 Level AA conformance, treated as a build requirement — not a finishing pass. The same standard applies to the software we deliver for clients. It's an aim, not a certification — we don't claim to have cleared every check on every page.
What we test
- Colour contrast — text and UI meet AA ratios in both light and dark themes (see the design system's contrast work).
- Full keyboard operability, visible focus states, and logical focus order.
- Semantic HTML and ARIA where needed; screen-reader passes on primary flows.
- Respect for
prefers-reduced-motionandprefers-color-scheme. - Target sizes and spacing that meet AA pointer guidance.
Known limits & feedback
No site is ever perfectly done. If you hit a barrier — anything that's hard to read, navigate or operate — tell us and we'll fix it. Email disko@binary-punks.com with the page and what got in your way; we aim to respond within a few working days.
The details
The files most sites never bother with.
Standards live in the corners. Here's the plumbing we're shipping with the production build — the kind of thing only people who care set up.
Upcoming. These ship with the production build (Phase 6) — they're not live yet. We list them here so you can hold us to shipping them; the details are where "attention to detail" stops being a slogan.
Scope honesty
What we don't do.
Knowing the edges of the workshop is part of trusting it. We'd rather say so than oversell.
Our AI is privacy-first by selection and deployment — chosen so your data isn't trained on or sold. We don't run our own models, and don't pretend to.
Not even the "friendly" kind — unless you explicitly ask for cookieless, privacy-first stats. The default is none.
No nag walls, no fake urgency, no roach-motel cancellations. If a tactic relies on tricking the user, it's out.
You get the source, the infra-as-code and the runbook. Nothing about your system is hostage to us.
Open commitments
What we're still improving.
A standard you can't see us working on is just marketing. Here's the live list.
The production build serves JetBrains Mono & Hanken Grotesk first-party via @nuxt/fonts — no font CDN — and the CI origin gate fails the build if any external origin slips in.
Lighthouse, SSL Labs and header checks run on every commit against the live domain — turning the targets above from honest placeholders into linked, earned results.
Ship the well-known files listed above, with a real disclosure contact and signing key.
The token system is calibrated so primary text and UI meet AA in both themes — tested in the design system.
Hold us to it.
Want your project built to this bar — gates and all? That's the only way we know how.
disko@binary-punks.com