PDF accessibility where your documents live
EqualWeb PDF Accessibility scans every PDF in the systems you already use, scores each document, shows what to fix first by legal exposure - and remediates in one click, without moving files and without breaking a single link.
No upload. No download. Direct file access.
- 16 platforms & storages, one interface
- In-place remediation - no link breaks
- Free checks to start
Where do your documents live?
Installed plugins for content systems, an embedded app for commerce, and cloud connections for enterprise storage - the same capabilities everywhere.
Apps you install5-minute install
Cloud ConnectNothing to install
No uploads, no downloads - EqualWeb works on your PDFs right where they live. Sign in once and your PDFs appear in the EqualWeb dashboard - PDF Remediation → Cloud files - with the full pipeline: scores, reports, legal prioritization and one-click remediation. OAuth platforms connect in two clicks, SharePoint / Microsoft 365 uses a one-time admin consent, and S3-compatible storage connects with access keys you create. Step-by-step connection instructions are built into the dashboard.
Scan. Score. Prioritize. Remediate in place.
Full inventory, automatically
Every PDF in the system is discovered - media libraries, course files, cloud folders. Word, PowerPoint and Excel are detected too, for accessible conversion. Incremental scanning re-checks only what changed.
A score for every document
Each document is checked against 80+ PDF/UA and WCAG rules - tagging, title, alt text, tables, contrast, language - and gets a 0-100 score plus a detailed report with a plain-language explanation for every finding. Every report has a permanent link.
One-click AI remediation
Full structural tagging, reading order, alt text and metadata - applied automatically. The accessible file replaces the original at the same address, so no link anywhere ever breaks. The original is kept for one-click restore.
Legal prioritization
The unique part: instead of "78,000 files failed", the product answers "what must be fixed first?" - classifying every document by signals from your own system, with a full audit trail of the rules behind each classification.
Dashboards and an executive report
Score distribution, treated documents, categories, and a "high-priority not yet treated" KPI - plus a designed annual executive report (PDF) in one click, ready for the board or an audit.
Permissions and encrypted keys
Per-action permissions - who checks, who remediates, who manages settings - controlled by your platform's own roles. One key per install, validated on save and stored encrypted. Plugins update automatically.
What must be fixed first?
Every document gets three scores - accessibility, legal priority and usage - and lands in one of four categories. You stay in control: tag folders and courses, override per file, and every classification shows the rules that produced it.
- Fix firstRequired for serviceDocuments people need in order to receive service - forms, applications, essential guides.
- High priorityPublished to the publicLinked from published content or shared publicly - visible legal exposure.
- In scope if in useInternalCurrent-use is the legal line - internal documents in active use are covered too.
- Pending your confirmationArchivePossibly out of scope - flagged for your review, never hidden automatically. Judgment rules are off by default; you enable and choose.
How much access do we actually ask for?
No upload, no download, no manual copies - you never move a file. A document is processed automatically in the EqualWeb remediation cloud, the result returns to your platform in place, and the report keeps a permanent link. Your files are never stored with us; keys and credentials are stored encrypted (AES-256).
| Platform | What we get | Who approves | What we don't see |
|---|---|---|---|
| WordPress / Drupal / Moodle & Open LMS | The plugin runs inside your site - data stays with you | Your site admin, at install | Nothing leaves except the file being checked |
| Shopify | Files only (read/write_files) | The merchant, at install | Products, orders, customers |
| SharePoint / Microsoft 365 | OAuth sign-in with a one-time admin consent | Your Microsoft 365 admin, once | Anything outside the consent - revoke anytime in Microsoft Entra |
| Google Drive / OneDrive / Dropbox / Box | Only what you grant on the OAuth consent screen | You, at sign-in | No passwords, no keys of ours - revoke anytime in your account |
| Canvas LMS | LTI 1.3 with zero service scopes, plus a Canvas API token limited to courses, folders and PDF files | Your Canvas account admin | Rosters, grades and student data - never requested |
| S3-compatible storage (AWS, R2, B2, Wasabi, Spaces, GCS) | An access key you create, scoped to the bucket you choose | You, in your provider console | Anything outside that bucket - revoke the key anytime |
Connect key-based storage
Key-based storage connects with an access-key pair you create in your provider's console - EqualWeb only needs read access to check documents (use a read/write key if you want remediated PDFs written back to the bucket). Paste the keys in the dashboard and hit Connect - every connection is tested before it is saved, and keys are stored encrypted (AES-256).
AWS S3
- In the AWS console, open IAM → Users and create a user for EqualWeb (no console access needed).
- Attach the AmazonS3ReadOnlyAccess policy - or a policy scoped to just your bucket.
- Open the user → Security credentials → Create access key (use case: Third-party service) and copy both values - the secret is shown only once.
In the dashboard: Region: the bucket's region (e.g. us-east-1) · Endpoint: leave empty.
Cloudflare R2
- In the Cloudflare dashboard, open R2 → Manage R2 API Tokens → Create API token.
- Permission: Object Read only, limited to your bucket. Create it and copy the Access Key ID and Secret Access Key.
- The same page shows your S3 endpoint; your account ID is also on the R2 overview page.
In the dashboard: Endpoint: https://<account-id>.r2.cloudflarestorage.com (required) · Region: leave empty.
Backblaze B2
- In the Backblaze console, open App Keys → Add a New Application Key - restrict it to your bucket, Read Only.
- Copy the keyID and applicationKey - the applicationKey is shown only once.
- The region is in the bucket's S3 endpoint on the Buckets page:
s3.us-west-004.backblazeb2.commeans regionus-west-004.
In the dashboard: Access Key ID: the keyID · Secret: the applicationKey · Region: from the bucket endpoint · Endpoint: leave empty.
Wasabi
- In the Wasabi console, open Access Keys → Create New Access Key - prefer a sub-user with a read-only policy.
- Copy the key and secret - the secret is shown only once.
In the dashboard: Region: the bucket's region (e.g. us-east-1) · Endpoint: leave empty.
DigitalOcean Spaces
- In the DigitalOcean control panel, open API → Spaces Keys → Generate New Key.
- Copy the key and secret - the secret is shown only once.
In the dashboard: Bucket: the Space name · Region: the Space's region slug (e.g. nyc3) · Endpoint: leave empty.
Google Cloud Storage
- In the Google Cloud console, open Cloud Storage → Settings → Interoperability.
- Create an HMAC key for a service account (recommended) and copy the Access key and Secret - the secret is shown only once.
- Grant that account access to the bucket: Buckets → your bucket → Permissions → Grant access, role Storage Object Viewer - the grant can take a few minutes to apply.
In the dashboard: Region: leave empty · Endpoint: leave empty (storage.googleapis.com is used automatically).
PDF Accessibility Integrations - common questions
What is EqualWeb PDF Accessibility?
Which platforms are supported?
Does remediation move or break my files?
How does legal prioritization work?
Do I need to upload or download files?
Can I try it for free?
See your documents' scores today
Free accessibility checks within a daily quota - see the scores and full reports before paying anything.