Cys Infotech

Smarter sites, safer businesses — no strings attached.

Free Tool

Where might your business have a compliance gap?

A free, plain-English self-check across four areas — answer what applies to your business, skip what doesn't. Nothing you enter leaves your browser. Free for any business, whether you're a Cys Infotech client or not.

Website Accessibility

Applies to every business with a website.

Not started
  • Meaningful images have descriptive alt text (not left blank or missing).
  • Body text is easy to read against its background — nothing you'd call hard to see.
  • Every button, link, and form field can be used with a keyboard alone, no mouse.
  • Page headings are in a logical order — one main heading, no skipped levels.

Card Payments

Applies if you ever take a customer's card, online or in person.

Not started
  • No one writes down, emails, or types a customer's full card number anywhere outside your card reader or payment processor.
  • Nobody stores a CVV/security code anywhere — no notebook, spreadsheet, CRM, or note.
  • Online payments go through a known processor (Stripe, Square, PayPal, or similar), not a custom form that touches raw card numbers.
  • Everyone with access to payment systems has their own login — not one shared password.

Patient / Health Information

Applies to dental, medical, med spa, and similar practices.

Not started
  • There’s a signed agreement (a BAA) with every vendor that touches patient info — scheduling tool, texting/email service, billing, IT support, cloud storage.
  • Patient information is never sent over plain, unencrypted email or text.
  • Staff have individual logins to systems holding patient records — not one shared password.
  • There's a written plan for what happens if a laptop or phone with patient data is lost or stolen.

General Data Privacy

Applies to any website that collects visitor information.

Not started
  • Your privacy policy actually describes what you collect and how it’s used — not just a generic template.
  • Your forms only ask for what you actually need, not extra fields collected "just in case."
  • You know where form submissions are stored and how long a third-party form service keeps them.

This is a self-check built from widely-known, general best practices — not a certified audit, and not legal advice. A clean result here doesn't mean you're PCI-DSS, HIPAA, WCAG, or GDPR compliant; that requires a qualified assessor or attorney reviewing your actual business. Nothing you answer here leaves your browser.