Website Compliance Report
Cornerstone Insurance is committed to accessibility, privacy, and security. This page provides a transparent summary of our compliance status.
Last verified: April 15, 2026
ADA Accessibility — WCAG 2.2 Level AA
Compliant
This website is designed and maintained to conform with the Web Content Accessibility Guidelines (WCAG) 2.2 Level AA, published by the W3C. Our compliance is verified through automated testing (Google Lighthouse, axe-core) and manual keyboard/screen-reader evaluation.
Features implemented:
- ✓ Skip-to-main-content navigation link
- ✓ Semantic HTML5 landmarks (header, nav, main, footer)
- ✓ Full keyboard navigation with visible focus indicators
- ✓ Color contrast ratios exceeding AA minimums (verified AAA)
- ✓
prefers-reduced-motionrespected (video autoplay disabled) - ✓ Descriptive alt text on all informational images
- ✓ Touch targets ≥24×24px on all interactive elements
- ✓ Responsive layout supporting 200% zoom without content loss
Full details: Accessibility Statement
Privacy Law Compliance
CCPA CCPA · CPRA · NJDPA Compliantmiddot; CPRA CCPA · CPRA · NJDPA Compliantmiddot; State Privacy Compliant
Our privacy practices comply with the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and the North Carolina state privacy framework and the South Carolina Insurance Data Security Act.
- ✓ We do not sell or share personal information
- ✓ Right to know, access, delete, correct, and opt out
- ✓ Specific data retention schedules (24 months / 7 years)
- ✓ Two opt-out methods available (email and phone)
- ✓ Authorized agent requests accepted
- ✓ Children’s privacy protected (COPPA-aware)
Full details: Privacy Policy
Cookie Consent & GDPR Readiness
GA4 Consent Mode v2 · GDPR-Ready
This website uses Google Analytics 4 with Consent Mode v2. Analytics cookies are blocked by default and only activated after you actively consent through our cookie banner. No tracking, advertising, or marketing cookies are used.
- ✓ Zero cookies set before user consent (verified via headless browser)
- ✓ Accept All / Reject Non-Essential symmetrical choice
- ✓ Global Privacy Control (GPC) signal auto-honored
- ✓ Preferences changeable anytime via footer “Cookie Settings”
- ✓ Complete cookie inventory published
Full details: Cookie Policy
Website Security
Grade A+ · TLS 1.3
This website implements industry-standard security headers and encryption to protect visitors and their data.
| Encryption | TLS 1.3 (AES-256-GCM) | ✓ |
| HSTS | Strict Transport Security with preload | ✓ |
| Content Security Policy | Restrictive CSP with explicit allow-list | ✓ |
| Clickjacking Protection | X-Frame-Options SAMEORIGIN | ✓ |
| MIME Sniffing | X-Content-Type-Options nosniff | ✓ |
| Privacy Controls | Referrer-Policy + Permissions-Policy | ✓ |
Legal & Compliance Documents
This compliance report reflects the state of cornerstone.idfs.ai as verified on April 15, 2026. Scores are generated by Google Lighthouse, pa11y/axe-core, and automated security-header analysis. Compliance is re-verified after every website update.
Website built and maintained by IdeaForge Studios