Compliance

Compliant by architecture

Most platforms bolt compliance on at the end. Scrydon builds it in. Guardrails, policy-as-code authorisation, immutable audit logs, key control and document classification are part of the runtime — so the controls these frameworks demand are enforced as your AI and data actually run.

And because every control is observable, framework evidence packs map them back to the regulations, giving your risk, security and compliance teams something concrete to show.

Our own programme

We hold ourselves to the same standard

We ask customers to trust the controls we build, so we run our own compliance programme against the same yardsticks. Scrydon operates an information security management system aligned with ISO/IEC 27001 and an AI management system aligned with ISO/IEC 42001 — the first international standard for AI governance, and one very few vendors can point to.

We publish status, not promises. Certification claims will appear here only once external audits are complete — until then, this is exactly where the programme stands.

Policy framework: 40 policies approved and in force across the company.
Continuous control monitoring: Controls are monitored continuously in Vanta.
Internal audit: Underway.
External certification audits: The next milestone on the roadmap.