Editorial

Notes from the people building ScodyX

Three kinds of writing: product updates when something ships, engineering notes on how the platform works internally, and compliance clarifications that answer the billing, privacy and standards questions we get asked most.

Product update

What shipped, what changed, and what it means for your workspace.

Engineering note

How the build loop, sandbox and engine routing actually work under the hood.

Compliance & FAQ

Plain-language clarifications on security, privacy, billing and standards.

What is evidenced, and what is only alignment

Evidenced items are produced by checks that run against the live system and can be exported. Alignment-only items describe how our practices map to a published standard — they are not certifications, audits or attestations by any third party.

Evidenced
Tenant isolation
Row-level security tests run against the live database and are reported in your workspace assurance page.
Evidenced
Audit trail & credit ledger
Every run, deploy and credit movement is recorded with a timestamp and request ID you can export.
Evidenced
Encryption in transit
HTTPS/TLS is enforced on all platform and generated-app endpoints, and probed on demand.
Alignment only
ISO/IEC 27001 & 27701
Our controls are mapped to these standards. We are not certified by an accredited body, and we do not claim to be.
Alignment only
SOC 2 Trust Services Criteria
Practices mapped to the criteria. No SOC 2 report has been issued for ScodyX.
Alignment only
WCAG 2.2 AA
We build to the guidelines and test key flows. No independent accessibility audit yet.

Full control register and framework mappings: Compliance & standards · Security overview