A website for a support service is not a normal charity website with a helpline number added. Some of your visitors will be reading it in circumstances where being seen reading it is a risk. That single fact changes design decisions most agencies never think about, because most agencies have never had to. We built The Jessica Project, a site for a survivor-led domestic abuse charity. This article sets out what that work taught us any support service website needs.
A quick exit that actually works
Most domestic abuse and support sites have a quick exit button. Fewer have one that works under pressure. The test is not whether the button exists; it is what happens in the two seconds after someone presses it. A working quick exit leaves the site immediately for a neutral page, weather or news. It replaces the current page in the browser history, so the back button does not return. And it is reachable on every page, at every screen size, without scrolling. It also needs a keyboard shortcut, because a mouse movement across the screen takes longer than a keypress.
What no quick exit can do is erase browser history already recorded. The site should say so plainly, and link to guidance on safer browsing rather than imply a protection it cannot deliver. Honesty about limits is itself a safety feature.
Forms that do not keep what people send
A standard contact form stores every submission in the website's database, where it waits for the next security incident. For a support service, a message saying "I need help leaving" must not sit in a database at all. The safer pattern: the form delivers the message to a monitored inbox and stores nothing on the website. It costs nothing extra to build and removes an entire category of risk. Ask any agency proposing a form what happens to submissions after they are sent, and keep asking until the answer is specific.
Venues that stay private
Support groups meet somewhere, and that somewhere often cannot be public. Your events system needs to handle two kinds of event differently. Public fundraisers can carry full addresses. Support sessions are listed with a day, a time, and "venue shared when you get in touch". The mistake to design against is a well-meaning volunteer pasting the address into a listing because the events tool had a venue field. Make the safe path the default one and the mistake stops being possible.
Photographs, carefully
Photo policies for support services need two rules that brochure sites never think about. Nobody identifiable as a service user appears without written consent, informed and revocable. And photographs are stripped of hidden location data before publishing. A phone photo can carry the exact coordinates of where it was taken. For a refuge or a support group, that is an address leak in a JPEG. The second rule can be automated on the website itself, so it does not depend on anyone remembering.
Plain language, and help before scrolling
Someone in crisis does not read; they scan. The phone number, the crisis line, and "I need help now" belong at the top of every page, visible without scrolling on a phone. The emergency route (999) is named alongside the support route. Sentences stay short. Jargon stays out: "get support" reaches more people than "access our service provision pathway". If your community speaks several languages, translation is not a nice-to-have. The Jessica Project launched with its content available in six.
Accessibility is a safety feature here
Disabled women experience domestic abuse at higher rates than non-disabled women. For a support service, that means accessibility failures exclude exactly the people most likely to need the site. WCAG 2.2 AA is the standard to build to. "Tested with evidence" is the phrase to insist on: an audit trail of checks, not a vague assurance. Colour contrast, keyboard navigation, screen reader behaviour, and forms that work without a mouse all get verified, not assumed. We have written more about what WCAG actually means for a charity website.
Analytics restraint
Every tracking script on a support service website is a third party learning that a particular device visited a domestic abuse charity. That is a real cost. It buys you very little on a site whose success is measured in phone calls rather than page views. Run the minimum. Privacy-respecting analytics or none, no advertising pixels, no session recording, and a cookie banner that is honest because there is almost nothing to declare.
What this means if you are commissioning one
Put these requirements in your brief, in writing: working quick exit with history replacement, forms that store nothing, private venue handling, location data stripped from images, crisis contact visible without scrolling, WCAG 2.2 AA with evidence, and minimal tracking. An experienced agency will recognise the list. An inexperienced one will learn more from those seven lines than from any amount of "modern and engaging".
You can see all of this working on thejessicaproject.co.uk, and the case study explains the decisions behind it. If you run a support service and want a website that takes safety this seriously, book a free 20-minute call.