Compliance & go-live audit
Indaba — Site Audit Report
Live audit of every Indaba property: domain, HTTPS, forms & email delivery, and legal/compliance posture. Run against the real URLs on 12 Aug 2026. Paired with the reusable checklist in SITE_AUDIT.md.
✅ pass⚠️ needs attention⛔ blocker⏳ pending / propagatingn/a
1 · Status at a glance
Live ✓the EnS Case File
ens.indaba.one
Live over HTTPS, correct Works build, "not a law firm" disclaimer present. Gaps: privacy policy, consent capture, forms are demo-only.
Not live — 404getindaba.com
getindaba.com
Deployed to Netlify & domain attached, but apex + www return 404. Likely DNS/cert propagation or Vercel-CDN proxy intercepting.
404 — mismatchSix Isobel
cases.indaba.one
Registry marked "Live" but the domain returns 404. Confirm the CNAME and that the Netlify site claims the custom domain.
Live ✓Federation (FSC)
fsc.indaba.one
Live — gated NDA private preview (Sovereign Soil × Indaba, for Cornelius). Confirm exact Netlify name for the registry.
Phase 2Indaba App
app.indaba.one · *.indaba.one
Multi-tenant app + Supabase magic-link auth. Not built yet; wildcard DNS reserved.
Time-sensitiveDomain contact verification
indaba.one + getindaba.com
ICANN/Vercel contact verification due ~Aug 22. Unverified = both domains suspended, regardless of DNS.
2 · Action punch-list — what needs to get done
Two of these are clocks, not chores. The domain-contact verification (P1‑a) has a hard ~Aug 22 deadline, and a live site sending people to a 404 (P1‑b/c) costs trust every day it's up. Clear the P1s first.
P1 · deadlineVerify domain-contact info for both domains (≈Aug 22)Action the Vercel/ICANN "Verify Your Domain Contact Information" email (from noreply@registrar.vercel.com, Aug 8). Miss it → indaba.one AND getindaba.com temporarily suspend.
Danny · 5 min
P1 · liveFix getindaba.com 404In Netlify → getindaba site → Domain management, confirm getindaba.com shows a provisioned HTTPS cert (not just "attached"). In Vercel, confirm the apex A → 75.2.60.5 exists and the domain isn't being served by Vercel's own CDN over the Netlify records. Give DNS/cert up to ~30 min after saving, then re-test.
Danny + verify
P1 · liveFix cases.indaba.one 404Same class of issue as ens had. Confirm the cases CNAME points to the Isobel site's exact .netlify.app name, and that the Isobel Netlify site has cases.indaba.one added as a custom domain.
Danny + verify
P2 · pre-onboardTurn on the getindaba form notification + test itNetlify → getindaba → Forms → notifications → Email → add hello@convergenceai.ai + dannybismark@gmail.com. Then submit a real test and confirm the email lands.
Danny · 5 min
P2 · complianceAdd a privacy notice + consent capture to ens (sensitive data)EnS files hold medical/accident data. Add a short privacy policy (collect / store / never-sell / export-delete) and capture consent + the Client Service Agreement at first sign-in. Confirm HIPAA posture with counsel before real claimants (see §4).
Danny + counsel
P2 · deliverabilitySet up SPF + DKIM on the sending domainBefore the Savi/Esther welcome emails go out, configure SPF/DKIM for the @indaba.one / @convergenceai.ai sender, or the mail spam-files.
Danny
P2 · accessDecide Savi & Esther access methodReal magic-link login is Phase 2. Until then, choose: (a) send the live link + walkthrough as preview access, or (b) password-protect the site and share the password separately. Walkthrough is already live at ens.indaba.one/onboarding.html.
Danny decision
P3 · polishMeta descriptions + OG/social cardsAdd per-page meta descriptions and Open Graph image/title so links preview well when shared. Confirm favicon.
Claude can do
P3 · recordsClose registry gapsConfirm the exact Netlify site names for Six Isobel and FSC, and confirm what the "6th site" is. Then the registry + DNS table are fully filled.
Danny
3 · Per-site detail
the EnS Case File
ens.indaba.one · Indaba Works Live ✓
- ✓
Resolves & loads over HTTPS
- ✓
Correct Works build — nav "INDABA·Works", welcome hero present
- ✓
Disclaimer present: "…not a law firm and do not provide legal advice."
- ✓
Onboarding walkthrough live at /onboarding.html (14 slides)
- ✓
Optimized build — no inline base64 (images externalized)
- !
No dedicated privacy policy page (only inline security language)
- !
No consent / CSA capture yet (Phase 2 sign-in)
- !
Forms are demo-only (onsubmit=return false) — no capture/email yet
- !
No meta description detected
getindaba.com
getindaba.com · Platform / brand Not live — 404
- ✓
Deployed to Netlify as getindaba.netlify.app; domain attached in Netlify
- ✓
Optimized build (base64-free); early-access form wired correctly (Netlify Forms + hidden form-name + honeypot)
- ✓
www CNAME corrected to bare host getindaba.netlify.app
- ✕
Apex + www return 404 — not serving the site
- ⏳
HTTPS cert: Netlify still showed http:// — cert likely not provisioned
- !
Form notification not confirmed set in Netlify (leads captured silently until then)
Most likely cause of the 404: either DNS/cert still propagating (retest in ~30 min) or Vercel's CDN is answering the domain before Netlify does. Since ens.indaba.one works the same way, this is fixable — verify Netlify shows a green HTTPS cert for the domain and the apex A record isn't overridden by Vercel CDN.
Six Isobel
cases.indaba.one · Indaba Cases 404 — mismatch
- ✕
Domain returns 404 in audit
- !
Registry says "Live" — reconcile
- –
Confirm CNAME + Netlify custom-domain claim + exact Netlify name
Federation (FSC)
fsc.indaba.one Live ✓
- ✓
Live — gated NDA private preview
- ✓
Convergence AI / Indaba branding present
- –
Confirm exact Netlify name for registry
4 · Compliance & legal posture
- ✓
"Not a law firm / no legal advice" disclaimer — present on ens; confirm on getindaba once live and on cases/fsc
- ✓
Service described as case-organization & coordination, not legal services
- ✓
Trademark usage: Indaba GPS™, Convergence AI LLC referenced
- !
Privacy notice/policy — needed as a real, linkable page (collect / store / never-sell / export & delete rights)
- !
Consent / Client Service Agreement — capture at first login (pro-bono terms + participation consent)
- !
HIPAA posture — document & confirm with counsel (see box)
- –
Cookie/consent handling — only if analytics/tracking is added later
HIPAA, in plain terms. HIPAA binds "covered entities" (providers, plans, clearinghouses) and their business associates. Indaba, where the individual uploads their own records, is generally not itself a covered entity — but obligations can attach if Indaba handles medical data on behalf of a covered entity (e.g., a clinic or an attorney acting as a business associate), which triggers a BAA + the Security Rule. Because EnS files hold accident/medical data, treat it as sensitive PHI-like data regardless: encryption at rest and in transit, access controls, audit logging, minimum-necessary sharing, and a clear privacy notice. Confirm the specific arrangement with counsel before onboarding real claimants. This is general information, not legal advice.
5 · The standard we audit against
Every site is checked across eight areas. Full checklist lives in SITE_AUDIT.md; this is the summary.
- A
Build & deploy readiness — correct build, right edition, no base64, links, backup-first
- B
Domain & DNS — records correct, domain claimed in Netlify, contact verified, no proxy conflict
- C
HTTPS / security — cert, forced HTTPS, no mixed content
- D
Forms & email — wiring, notification set, end-to-end test, SPF/DKIM
- E
Compliance & legal — disclaimer, privacy, consent/CSA, HIPAA posture, trademarks
- F
Access & onboarding — access method, principals provisioned, walkthrough, welcome comms
- G
Content & SEO/meta — titles, meta description, OG cards, contact path
- H
Backups & records — latest backup logged, registry current, audit dated