# POL-024 — The site hosting the policy must itself be live and real

> Where consent is collected offline, the site hosting the policy pages must still be a live, authentic site rather than a shell built to hold them.

- **Rule ID:** POL-024
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `policy host site`
- **Severity:** BLOCKING — Breaking this rule gets the submission rejected outright.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the crawled website or policy page
- **Fix type:** Fix the website — no form edit clears it
- **Required by:** Aerialink, AWS
- **Applies:** Applies when consent was collected by paper form, QR code, point of sale, live verbal and IVR.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-024/

## Why this rule exists

An offline programme can be flawless on paper and still sink on the site nobody thought was being assessed, because the policy has to live somewhere and that somewhere gets crawled like any other brand site. A single-page host stood up to carry two documents looks exactly like the shell sites the authenticity screen exists to catch.

## How to fix it

Host the policy pages on the business's real website. Where there is none, publish a small but genuine site describing the business alongside the documents, rather than a bare page carrying only the policy text.

## Provider rejection codes

| Provider | Code | Resubmission allowed |
| --- | --- | --- |
| Bandwidth/DCA | `807` | yes |

## Notes

Tagged to the offline consent methods, which is where the catalog states it and where it bites: a web opt-in already puts the site itself under WEB-024, so this rule adds nothing there.
