How scm.cc handles trust
Plain statements of what the product does, taken from its documented behavior. This page makes no certification, authorization or compliance claim.
Read-only connections
Source connections (cloud, code and database security tools) are read-only. Credentials are validated before anything is stored and encrypted at rest (AES-256-GCM).
Auditor access
An organization owner or admin can mint a read-only Auditor API token. Only a hash of the token is stored, every read is access-logged and visible to members, and a revoked token stops working immediately.
Evidence you can check
Monthly continuous-monitoring runs pin their inputs with tamper-evident hashes and can be replayed. Evidence coverage is reported as coverage, not as a compliance verdict.
Sourced references
The FedRAMP 20x indicator list is pinned to the official page and checked weekly for changes. Every indicator has its own page: all 46 Key Security Indicators.
Per-organization trust pages are published by each organization from its own account and are opt-in.