Skip to main content
PDF Tools · Integrations

PDF accessibility where your documents live

EqualWeb PDF Accessibility scans every PDF in the systems you already use, scores each document, shows what to fix first by legal exposure - and remediates in one click, without moving files and without breaking a single link.

No upload. No download. Direct file access.

  • 16 platforms & storages, one interface
  • In-place remediation - no link breaks
  • Free checks to start

Or explore the interactive plugin demo →

Free PDF Checker & AI Accessibility Remediation Installing is free - and every install includes free accessibility checks with a daily limit, no purchase and no credit card required. See scores and full reports for your documents; credits are needed only when you choose to remediate. See it in the interactive demo →
Pick your platform

Where do your documents live?

Installed plugins for content systems, an embedded app for commerce, and cloud connections for enterprise storage - the same capabilities everywhere.

Apps you install5-minute install

Cloud ConnectNothing to install

No uploads, no downloads - EqualWeb works on your PDFs right where they live. Sign in once and your PDFs appear in the EqualWeb dashboard - PDF Remediation → Cloud files - with the full pipeline: scores, reports, legal prioritization and one-click remediation. OAuth platforms connect in two clicks, SharePoint / Microsoft 365 uses a one-time admin consent, and S3-compatible storage connects with access keys you create. Step-by-step connection instructions are built into the dashboard.

Admin consentSharePoint / Microsoft 365Cloud Connect - one-time Microsoft admin consentPDF accessibility for SharePoint → OAuthGoogle Drive / WorkspaceCloud Connect - your Google sign-in, two clicksPDF accessibility for Google Drive →
OAuthOneDriveCloud Connect - your Microsoft sign-in, two clicks
OAuthDropboxCloud Connect - your Dropbox sign-in, two clicks
OAuthBoxCloud Connect - your Box sign-in, two clicksPDF accessibility for Box →
Access keysAWS S3Bucket-scoped access keys you create
Access keysCloudflare R2S3-compatible - API token scoped to the bucket
Access keysBackblaze B2S3-compatible - bucket-scoped app key
Access keysWasabiS3-compatible - access keys from the console
Access keysDigitalOcean SpacesS3-compatible - Spaces keys
Access keysGoogle Cloud StorageHMAC keys via S3 interoperability
One product, everywhere

Scan. Score. Prioritize. Remediate in place.

Full inventory, automatically

Every PDF in the system is discovered - media libraries, course files, cloud folders. Word, PowerPoint and Excel are detected too, for accessible conversion. Incremental scanning re-checks only what changed.

A score for every document

Each document is checked against 80+ PDF/UA and WCAG rules - tagging, title, alt text, tables, contrast, language - and gets a 0-100 score plus a detailed report with a plain-language explanation for every finding. Every report has a permanent link.

One-click AI remediation

Full structural tagging, reading order, alt text and metadata - applied automatically. The accessible file replaces the original at the same address, so no link anywhere ever breaks. The original is kept for one-click restore.

Legal prioritization

The unique part: instead of "78,000 files failed", the product answers "what must be fixed first?" - classifying every document by signals from your own system, with a full audit trail of the rules behind each classification.

Dashboards and an executive report

Score distribution, treated documents, categories, and a "high-priority not yet treated" KPI - plus a designed annual executive report (PDF) in one click, ready for the board or an audit.

Permissions and encrypted keys

Per-action permissions - who checks, who remediates, who manages settings - controlled by your platform's own roles. One key per install, validated on save and stored encrypted. Plugins update automatically.

Compliance triage

What must be fixed first?

Every document gets three scores - accessibility, legal priority and usage - and lands in one of four categories. You stay in control: tag folders and courses, override per file, and every classification shows the rules that produced it.

  • Fix firstRequired for serviceDocuments people need in order to receive service - forms, applications, essential guides.
  • High priorityPublished to the publicLinked from published content or shared publicly - visible legal exposure.
  • In scope if in useInternalCurrent-use is the legal line - internal documents in active use are covered too.
  • Pending your confirmationArchivePossibly out of scope - flagged for your review, never hidden automatically. Judgment rules are off by default; you enable and choose.
Minimum access, maximum transparency

How much access do we actually ask for?

No upload, no download, no manual copies - you never move a file. A document is processed automatically in the EqualWeb remediation cloud, the result returns to your platform in place, and the report keeps a permanent link. Your files are never stored with us; keys and credentials are stored encrypted (AES-256).

PlatformWhat we getWho approvesWhat we don't see
WordPress / Drupal / Moodle & Open LMSThe plugin runs inside your site - data stays with youYour site admin, at installNothing leaves except the file being checked
ShopifyFiles only (read/write_files)The merchant, at installProducts, orders, customers
SharePoint / Microsoft 365OAuth sign-in with a one-time admin consentYour Microsoft 365 admin, onceAnything outside the consent - revoke anytime in Microsoft Entra
Google Drive / OneDrive / Dropbox / BoxOnly what you grant on the OAuth consent screenYou, at sign-inNo passwords, no keys of ours - revoke anytime in your account
Canvas LMSLTI 1.3 with zero service scopes, plus a Canvas API token limited to courses, folders and PDF filesYour Canvas account adminRosters, grades and student data - never requested
S3-compatible storage (AWS, R2, B2, Wasabi, Spaces, GCS)An access key you create, scoped to the bucket you chooseYou, in your provider consoleAnything outside that bucket - revoke the key anytime
Access keys, step by step

Connect key-based storage

Key-based storage connects with an access-key pair you create in your provider's console - EqualWeb only needs read access to check documents (use a read/write key if you want remediated PDFs written back to the bucket). Paste the keys in the dashboard and hit Connect - every connection is tested before it is saved, and keys are stored encrypted (AES-256).

AWS S3
  1. In the AWS console, open IAM → Users and create a user for EqualWeb (no console access needed).
  2. Attach the AmazonS3ReadOnlyAccess policy - or a policy scoped to just your bucket.
  3. Open the user → Security credentialsCreate access key (use case: Third-party service) and copy both values - the secret is shown only once.

In the dashboard: Region: the bucket's region (e.g. us-east-1) · Endpoint: leave empty.

Cloudflare R2
  1. In the Cloudflare dashboard, open R2 → Manage R2 API TokensCreate API token.
  2. Permission: Object Read only, limited to your bucket. Create it and copy the Access Key ID and Secret Access Key.
  3. The same page shows your S3 endpoint; your account ID is also on the R2 overview page.

In the dashboard: Endpoint: https://<account-id>.r2.cloudflarestorage.com (required) · Region: leave empty.

Backblaze B2
  1. In the Backblaze console, open App KeysAdd a New Application Key - restrict it to your bucket, Read Only.
  2. Copy the keyID and applicationKey - the applicationKey is shown only once.
  3. The region is in the bucket's S3 endpoint on the Buckets page: s3.us-west-004.backblazeb2.com means region us-west-004.

In the dashboard: Access Key ID: the keyID · Secret: the applicationKey · Region: from the bucket endpoint · Endpoint: leave empty.

Wasabi
  1. In the Wasabi console, open Access KeysCreate New Access Key - prefer a sub-user with a read-only policy.
  2. Copy the key and secret - the secret is shown only once.

In the dashboard: Region: the bucket's region (e.g. us-east-1) · Endpoint: leave empty.

DigitalOcean Spaces
  1. In the DigitalOcean control panel, open API → Spaces KeysGenerate New Key.
  2. Copy the key and secret - the secret is shown only once.

In the dashboard: Bucket: the Space name · Region: the Space's region slug (e.g. nyc3) · Endpoint: leave empty.

Google Cloud Storage
  1. In the Google Cloud console, open Cloud Storage → Settings → Interoperability.
  2. Create an HMAC key for a service account (recommended) and copy the Access key and Secret - the secret is shown only once.
  3. Grant that account access to the bucket: Buckets → your bucket → Permissions → Grant access, role Storage Object Viewer - the grant can take a few minutes to apply.

In the dashboard: Region: leave empty · Endpoint: leave empty (storage.googleapis.com is used automatically).

FAQ

PDF Accessibility Integrations - common questions

What is EqualWeb PDF Accessibility?
EqualWeb PDF Accessibility scans all the PDF documents in the systems your organization already works in - WordPress, Drupal, Moodle, Shopify and Canvas LMS as installed apps, and SharePoint, Google Drive, OneDrive, Dropbox, Box and S3-compatible cloud storage through Cloud Connect - gives every document an accessibility score and a detailed report, prioritizes what to fix first by legal exposure, and remediates automatically in one click, in place.
Which platforms are supported?
Two families. Apps you install: WordPress, Drupal and Moodle (including Open LMS, which runs on Moodle) as plugins, Shopify as an embedded app, and Canvas LMS as an LTI 1.3 app registered in your Canvas admin (early access). Cloud Connect, with nothing to install: SharePoint / Microsoft 365 (one-time admin consent), Google Drive / Workspace, OneDrive, Dropbox and Box via OAuth sign-in, and S3-compatible storage - AWS S3, Cloudflare R2, Backblaze B2, Wasabi, DigitalOcean Spaces and Google Cloud Storage - via access keys. Cloud files appear in the EqualWeb dashboard with the full pipeline.
Does remediation move or break my files?
No. Remediation replaces the file in place - the accessible version lives at the same address, with the same file ID and the same sharing. Every existing link on your site, in emails or in learning materials keeps working, and the original is kept for one-click restore.
How does legal prioritization work?
Instead of a wall of failed files, every document is classified using signals from your own system - is it linked from published content, shared publicly, or sitting in an archive folder? Four categories result: required for service (fix first), public (high), internal (in scope if in use), and archive (possibly out of scope - pending your confirmation). Every classification shows the exact rules that produced it.
Do I need to upload or download files?
No. Direct file access through your own sign-in - nothing is uploaded by hand, nothing is downloaded back. The file is remediated in place, and the accessible version lands exactly where the original was.
Can I try it for free?
Yes. Accessibility checks are free within a daily quota, so you can see scores and full reports for your documents before paying anything. Remediation is a paid action, controlled by your own permission settings.
Start free

See your documents' scores today

Free accessibility checks within a daily quota - see the scores and full reports before paying anything.

Talk to a specialistBook a meeting