Trust & Compliance

Security and transparency without fake badges.

AdjScope is an evolving SaaS platform. This page identifies controls that are currently implemented, areas being improved, and recognized frameworks used as references. Framework alignment is not the same as an independent audit or certification.

Workspace access controls

Implemented

Workspace and claim access rules are designed to limit customer data to authorized users and server-side service functions.

Server-authoritative billing

Implemented

Plan prices, claim-shell packs, seats, and Exam Prep entitlements are validated by backend functions rather than trusting browser-supplied prices.

Stripe event safeguards

Implemented

Stripe webhook signatures, TEST-mode locks during launch preparation, approved price checks, and idempotency records are used to reduce duplicate or unauthorized grants.

Cancellation without automatic deletion

Implemented

Scheduling cancellation stops future renewal while preserving historical account and claim records unless a separate lawful deletion process applies.

Checkout consent records

Implemented

Paid checkouts require affirmative acceptance of the current Terms, Privacy Policy, Cancellation & Refund Policy, and Service Limitations. The accepted policy versions are recorded.

Support intake

Implemented

Support requests are saved with issue context and browser/device information so technical problems can be investigated without requiring customers to diagnose them.

Accessibility review

Ongoing

AdjScope uses WCAG 2.2 Level AA as an accessibility target for interface and content improvements. Formal conformance has not been independently certified.

Security verification

Ongoing

AdjScope uses OWASP application-security guidance as a reference for ongoing review. This is not an OWASP certification.

Cybersecurity governance

Ongoing

AdjScope uses NIST Cybersecurity Framework 2.0 as a reference for identifying, protecting, detecting, responding to, recovering from, and governing cybersecurity risk.

Independent certification or audit

Future

Formal programs such as SOC 2 or ISO 27001 may be considered if customer demand and revenue justify the cost. AdjScope does not currently claim those certifications.

Reference frameworks

These are public standards and guidance used as references for design and review. AdjScope does not represent that NIST, OWASP, or W3C has certified or endorsed the platform.

Customer-facing policies