ConformWatchBot
If you found this address in your server logs, this page explains what was visiting your site, why, and how to stop it.
ConformWatchBot/1.0 (+https://conformwatch.com/scanner)
What this is
ConformWatch runs automated accessibility scans of websites — checking them against the Web Content Accessibility Guidelines, levels A and AA, using the open-source axe-core engine. We do this on the instruction of the web agency or business that manages the site.
So if you are seeing our user-agent, someone responsible for your site asked us to check it. That is usually the agency that built or maintains it. If that does not sound like anything you have agreed to, we would genuinely like to hear from you — the address is below, and we will tell you who instructed the scan.
How it behaves
One page at a time, with a gap between each
Requests are sequential, never parallel, with a randomised pause of one to two seconds between pages. A scan is deliberately slower than it could be. It is not a load test and it will not appear as a traffic spike.
Public pages only
It fetches pages that any visitor could reach. It handles no logins, stores no credentials, and has no mechanism for reaching anything behind a sign-in.
No screenshots
The scanner reads the page structure — elements, attributes, computed colours — and keeps short snippets of the markup that failed a check. It captures no images of your pages.
No cookie banners, no consent given on anyone's behalf
It does not click through cookie notices, dismiss overlays, or accept terms. If a banner covers the page, the scan reports what it can see with the banner in place.
A small sample, not a full crawl
A scan reads the sitemap and picks a representative set of pages — usually around 25 — across the different page types on the site. It does not walk every URL you have.
robots.txt
We should be straight about this one. Scans run with the authority of whoever manages the site, so robots.txt disallow rules are not applied by default. The reasoning is that a rule written to keep search engines out of a checkout flow would also keep an accessibility check out of it, and the checkout is exactly where these problems matter most.
That default can be changed. The instructing agency can ask us to respect robots.txt, or to leave particular URLs out of every scan, and we will set it up. Neither is a switch in a dashboard yet — you ask, and it is configured by hand. That is true of a good deal of ConformWatch at the moment, and we would rather say so than imply otherwise.
How to stop it
Email [email protected] from an address at the site's own domain, or ask your agency to tell us. Scanning stops. We will not ask you to justify it, and we will not route you through anybody.
You can also block the user-agent above at your edge or in your own robots.txt, and it will be blocked. We would still rather you emailed, so that whoever is paying for the monitoring finds out it has stopped from us rather than from a gap in next month's report.
What we keep
A scan stores the results of the checks and short snippets of the markup that failed them. What that means for personal data, how long any of it is kept, and who it is shared with are set out in our privacy policy rather than summarised loosely here.