oddly

Trust center

oddly · estate cloudflare+github · updated 2026-09-27

Serving on trust.oddly.example with a managed certificate.

Posture is computed continuously from live substrate evidence; unevidenced controls score zero and say so.

Certifications

ISO/IEC 27001:2022

Self-attested

Self-attested against Annex A. Evidence is produced continuously by the governed-action substrate; an external audit has not yet been undertaken.

SOC 2 (Trust Services Criteria)

In progress

Controls mapped to the Common Criteria and evidenced from the substrate. A Type II observation window has not yet been completed.

Security posture

FrameworkPostureCoverage
ISO/IEC 27001:2022 Annex A
12% 15/93 evidenced (16%)
SOC 2 Trust Services Criteria (2017 with 2022 points of focus)
14% 12/61 evidenced (20%)

Live receipts

Every control carries the moment it was last verified against live state, not a badge a document asserts. This surface publishes what the engine verified, and when.

0 verified · 27 stale · 0 diverged · 0 unknown · 127 not covered

ControlStateFreshnessSource
iso27001-2022 A.5.15 Stale evidence 59 days old config_read
iso27001-2022 A.5.18 Stale evidence 59 days old config_read
iso27001-2022 A.5.24 Stale evidence 59 days old config_read
iso27001-2022 A.5.26 Stale evidence 59 days old config_read
iso27001-2022 A.8.13 Stale evidence 59 days old config_read
iso27001-2022 A.8.15 Stale evidence 59 days old log_row
iso27001-2022 A.8.16 Stale evidence 59 days old log_row
iso27001-2022 A.8.2 Stale evidence 59 days old config_read
iso27001-2022 A.8.28 Stale evidence 59 days old ci_run
iso27001-2022 A.8.29 Stale evidence 59 days old ci_run
iso27001-2022 A.8.3 Stale evidence 59 days old config_read
iso27001-2022 A.8.31 Stale evidence 59 days old config_read
iso27001-2022 A.8.32 Stale evidence 59 days old config_read
iso27001-2022 A.8.6 Stale evidence 59 days old log_row
iso27001-2022 A.8.8 Stale evidence 59 days old ci_run
soc2-tsc A1.1 Stale evidence 59 days old log_row
soc2-tsc A1.2 Stale evidence 59 days old config_read
soc2-tsc CC4.1 Stale evidence 59 days old log_row
soc2-tsc CC4.2 Stale evidence 59 days old log_row
soc2-tsc CC5.2 Stale evidence 59 days old config_read
soc2-tsc CC6.1 Stale evidence 59 days old config_read
soc2-tsc CC6.3 Stale evidence 59 days old config_read
soc2-tsc CC7.1 Stale evidence 59 days old ci_run
soc2-tsc CC7.2 Stale evidence 59 days old log_row
soc2-tsc CC7.4 Stale evidence 59 days old config_read
soc2-tsc CC7.5 Stale evidence 59 days old config_read
soc2-tsc CC8.1 Stale evidence 59 days old config_read

127 control(s) have no evidence source connected. They are published as gaps, not hidden.

Sub-processors

Every sub-processor across all products. Sub-processors are scoped per product: a customer viewing this page through their own engagement sees only the ones that process their data.

Sub-processorProductsJurisdictionData and DPAClauses and provenance
Edge application platform
Application hosting, edge compute, and the primary datastore.
All products Global (edge network)
Global edge network
operational-metadata, account-records
DPA signed
iso27001-2022 A.5.19 iso27001-2022 A.5.20 iso27001-2022 A.5.21 soc2-tsc CC9.2 iso42001-2023 A.10.3
Derived from observed egress (platform binding inventory), last seen 2026-08-12.
Source control and CI provider
Version control, code review, and continuous integration.
All products United States
United States
source-code, build-metadata
DPA signed
iso27001-2022 A.5.19 iso27001-2022 A.5.20 iso27001-2022 A.5.21 soc2-tsc CC9.2 iso42001-2023 A.10.3
Declared in the sub-processor register (sub-processor register).

Sub-processor changes

DateChangeDetail
2026-06-01 Added Edge application platform was added as a sub-processor for every product, processing operational-metadata, account-records.
GDPR Art 28(2): the controller is informed of the intended change and may object. Objection window closes 2026-07-01.
2026-06-01 Added Source control and CI provider was added as a sub-processor for every product, processing source-code, build-metadata.
GDPR Art 28(2): the controller is informed of the intended change and may object. Objection window closes 2026-07-01.

Under NDA

The detailed control ledger and evidence pack are available under NDA. Request access with a verified email; access is granted by approval and expires automatically.

Granted access expires 14 days after it is issued.

Request detailed access

Agent authority

Which agents may decide what, on what evidence, granted by whom, and what revokes it. Generated from the register the running code consults.

View the authority table

Posture is computed from live evidence by a deterministic engine. No estimate, no default-green.

Verified by oddly