All posts
Product update4 min readScodyX product team

A guided platform tour, and clearer trust labels

The platform page now walks through the six stages of a build, and every marketing page states which trust claims are evidenced and which are alignment-only.

Two changes went live today. The first is a guided tour on the platform page: six stages, from your first prompt to a shipped build, each with the concrete behaviour it performs and the limit that comes with it. The second is a trust-proof module that now appears on every marketing page.

The tour

Describe, choose an engine, build, preview, add data and auth, ship. You can step through each stage without leaving the page. We deliberately kept the copy narrow: each stage says what happens and then states where it stops.

Trust labels

The module splits our claims into two groups. Evidenced items are produced by checks that run against the live system and can be exported from your workspace — tenant isolation tests, the audit trail, the credit ledger, transport encryption. Alignment-only items describe how our controls map to a published standard.

Note: Alignment is not certification. We are not certified against ISO/IEC 27001 or 27701, and no SOC 2 report has been issued for ScodyX. If that changes, the label changes with it.

Where to look

  • Platform page: the guided tour sits directly under the hero.
  • Compliance page: the full control register with framework mappings.
  • Assurance page in your workspace: live isolation and diagnostics results.

Keep reading

What is evidenced, and what is only alignment

Evidenced items are produced by checks that run against the live system and can be exported. Alignment-only items describe how our practices map to a published standard — they are not certifications, audits or attestations by any third party.

Evidenced
Tenant isolation
Row-level security tests run against the live database and are reported in your workspace assurance page.
Evidenced
Audit trail & credit ledger
Every run, deploy and credit movement is recorded with a timestamp and request ID you can export.
Evidenced
Encryption in transit
HTTPS/TLS is enforced on all platform and generated-app endpoints, and probed on demand.
Alignment only
ISO/IEC 27001 & 27701
Our controls are mapped to these standards. We are not certified by an accredited body, and we do not claim to be.
Alignment only
SOC 2 Trust Services Criteria
Practices mapped to the criteria. No SOC 2 report has been issued for ScodyX.
Alignment only
WCAG 2.2 AA
We build to the guidelines and test key flows. No independent accessibility audit yet.

Full control register and framework mappings: Compliance & standards · Security overview