EnterpriseSecurity review ready

Rolling ScodyX out across an organisation.

Tell us how your team works and what your security review needs. We answer with specifics about what the platform does today — we do not promise features we have not built, and we publish no customer logos or figures we cannot evidence.

Roles and seats

Owner, admin and member roles per workspace with plan-based seat limits, invitations, and per-member project isolation.

Tenant isolation

Workspace separation is enforced by database access policies, and covered by an automated isolation test suite you can run from the assurance dashboard.

Audit and evidence

Privileged actions are recorded in an audit log, and each build run can export an evidence bundle describing what changed and how it was verified.

Single sign-on

SSO configuration for organisation accounts, with organisation-level roles separate from platform operator roles.

Your data, your database

Point projects at your own database instead of the managed store; connection settings are validated before they save.

Documented controls

A published control register mapping our practices to ISO/IEC 27001 and 27701, SOC 2 criteria, GDPR and WCAG 2.2 — alignment only, with no certification claimed.

For due diligence, start with the control register, data processing terms and subprocessor list. We hold no accredited ISO or SOC 2 certificate and say so openly.

Talk to us

Fields marked * are required.

We use what you share only to reply about ScodyX. See the privacy notice.

What is evidenced, and what is only alignment

Evidenced items are produced by checks that run against the live system and can be exported. Alignment-only items describe how our practices map to a published standard — they are not certifications, audits or attestations by any third party.

Evidenced
Tenant isolation
Row-level security tests run against the live database and are reported in your workspace assurance page.
Evidenced
Audit trail & credit ledger
Every run, deploy and credit movement is recorded with a timestamp and request ID you can export.
Evidenced
Encryption in transit
HTTPS/TLS is enforced on all platform and generated-app endpoints, and probed on demand.
Alignment only
ISO/IEC 27001 & 27701
Our controls are mapped to these standards. We are not certified by an accredited body, and we do not claim to be.
Alignment only
SOC 2 Trust Services Criteria
Practices mapped to the criteria. No SOC 2 report has been issued for ScodyX.
Alignment only
WCAG 2.2 AA
We build to the guidelines and test key flows. No independent accessibility audit yet.

Full control register and framework mappings: Compliance & standards · Security overview