ISO/IEC 27001:2022
Information security management system controls (Annex A themes 5–8).
Practices mapped to Annex A. Not certified by an accredited body.
Compliance
We build and run ScodyX against the same frameworks large buyers assess us with. This page maps each control we operate to the clauses it speaks to, so a security review can be answered from evidence rather than adjectives. Last reviewed 23 August 2026.
Information security management system controls (Annex A themes 5–8).
Practices mapped to Annex A. Not certified by an accredited body.
Privacy information management extension — controller and processor duties.
Practices mapped. Not certified.
Cloud-specific security and protection of personal data in cloud services.
We inherit much of this from our managed hosting and database providers and map our own shared-responsibility half.
Security, availability, confidentiality and privacy criteria.
Controls designed against the criteria. No SOC 2 report has been issued.
Lawful basis, data subject rights, records, transfers, processor terms.
Operating obligations implemented in product: consent, export, erasure, DPA terms.
Notice, access, deletion and opt-out of sale or sharing.
We do not sell personal information. Access and deletion requests use the same in-product flow as GDPR requests.
Cardholder data handling.
Out of our environment by design: checkout and card data are handled by Paddle as reseller and Merchant of Record.
Web accessibility for the product interface.
Design target for new interface work; audited internally, not third-party certified.
Documented, repeatable change and release management.
Release gates, approvals and audit records follow the principle. No quality-management certification is claimed.
Every control below is implemented today. Controls marked live probe are checked by running the real code path against the running system; signed-in customers can run those checks themselves and export the result.
Governance & organisation
Platform staff roles are held in a dedicated register, separate from customer accounts. Access to the operator console is limited to named roles, and the console cannot be reached from a customer session.
ISO 27001 A.5.2, A.5.15 · SOC 2 CC1.3, CC6.1
Critical platform operations require a second authorised approver, and the super-owner role requires step-up self-verification before a critical action takes effect.
ISO 27001 A.5.3, A.8.32 · SOC 2 CC8.1 · ISO 9001 change control
Administrative actions, build runs, credit debits and deployments are recorded with actor, timestamp and request identifier. Audit rows are append-only for the roles that write them.
ISO 27001 A.8.15, A.8.16 · SOC 2 CC7.2 · GDPR Art. 30
Identity & access control
Credential storage, hashing and email verification are handled by our managed authentication provider. Sessions use short-lived access tokens with refresh, and sign-out revokes the session.
ISO 27001 A.5.16, A.5.17, A.8.5 · SOC 2 CC6.1
Business and Enterprise workspaces can require single sign-on and manage members and roles centrally, so joiners and leavers are handled in one place.
ISO 27001 A.5.16, A.5.18 · SOC 2 CC6.2, CC6.3
Data protection
Every workspace-scoped table is protected by row-level policies, so a caller outside a workspace receives no rows. An automated isolation suite attempts cross-tenant reads and writes and must fail closed.
ISO 27001 A.8.3, A.8.4 · SOC 2 CC6.1, C1.1 · ISO 27018
All product and API traffic is served over HTTPS/TLS. Database storage and backups are encrypted at rest by the managed hosting provider.
ISO 27001 A.8.24 · SOC 2 CC6.7 · ISO 27017
Provider tokens you add are stored as secrets, become write-only in the interface once saved, and are decrypted only inside server-side code for the duration of a run. They are never returned to the browser.
ISO 27001 A.5.17, A.8.24 · SOC 2 CC6.1
Secure operations
Generation requests and gateway calls carry a request identifier end to end, so a failure or a charge can be traced to the run that caused it without exposing prompt contents in logs.
ISO 27001 A.8.15, A.8.16 · SOC 2 CC7.1, CC7.2
Parity, regression and isolation suites run against the real code paths, and release candidates progress through documented gates rather than ad-hoc pushes.
ISO 27001 A.8.25, A.8.29, A.8.31 · SOC 2 CC8.1 · ISO 9001 change control
Credit grants and debits are ledgered with idempotency keys, so retries and provider fallbacks cannot double-charge a workspace, and every entry is auditable by the customer.
ISO 27001 A.8.15 · SOC 2 PI1.3, CC7.2
Privacy & data subject rights
Non-essential cookies are off until consent is given, categories are described by purpose, and each decision is recorded with a timestamp so it can be evidenced and withdrawn.
ISO 27701 7.2, 7.3 · GDPR Art. 6(1)(a), Art. 7 · ePrivacy
Signed-in users can export their workspace data and raise export or deletion requests in product, with a tracked status until the request is closed.
ISO 27701 7.3.2–7.3.9 · GDPR Art. 15–20 · CCPA §1798.100, §1798.105
Business and Enterprise workspaces are excluded from the improvement corpus. For other plans, retained signals are de-identified, screened for identifiers, and reviewed by a human before they change platform defaults.
ISO 27701 7.4.1, 7.4.5 · GDPR Art. 5(1)(c), Art. 25
Resilience & incident response
Confirmed incidents are contained, assessed for affected data and workspaces, then recorded with the corrective change. Where notification is legally required we notify the supervisory authority and affected customers.
ISO 27001 A.5.24–A.5.28 · SOC 2 CC7.3–CC7.5 · GDPR Art. 33, 34
Database backups are managed and encrypted by the hosting provider; project files and generated code can be exported by customers at any time so recovery is never dependent on us alone.
ISO 27001 A.8.13, A.5.29, A.5.30 · SOC 2 A1.2
Supplier & third-party management
Hosting, database, model, email and payment providers are listed publicly with purpose, data categories and region, and international transfers rely on the providers' standard contractual clauses.
ISO 27001 A.5.19–A.5.22 · ISO 27701 8.5.6 · GDPR Art. 28, Art. 44–49
Accessibility & inclusion
Interface work targets WCAG 2.2 AA: keyboard reachable controls, visible focus, semantic landmarks, labelled inputs and contrast checked against the active theme.
WCAG 2.2 AA · EN 301 549 · ISO 30071-1 principles
The data processing terms, the subprocessor register and the security overview are published rather than gated. If your review needs a completed questionnaire, a signed copy of the processing terms, or region-specific commitments, write to support@ischolarx.com and tell us which framework you are assessing against.
Evidenced items are produced by checks that run against the live system and can be exported. Alignment-only items describe how our practices map to a published standard — they are not certifications, audits or attestations by any third party.
Full control register and framework mappings: Compliance & standards · Security overview