SQOS Gold is TokenAtlas's internal quality and trust standard used to evaluate product truthfulness, security practices, transparency, and production readiness.
Not an external certification. SQOS Gold is defined, applied and maintained by TokenAtlas. It is not issued, reviewed or accredited by any third party, standards body, government agency or audit firm, and it is not a SOC 2, ISO or other compliance certification.
We publish this page because the honest version of a quality standard is the one you can check. Everything below describes practices that already exist in the product — what we verify, how we verify it, and where the boundaries of the product are.
A. Product truthfulness
Every public product claim is read back against the shipped implementation. Where marketing language described behaviour the product does not perform, the language was removed rather than the behaviour promised.
TokenAtlas models AI costs from the workload inputs you provide — volumes, prompt sizes and assumptions priced against our maintained pricing catalog.
Claims of live monitoring, provider usage ingestion, alerting, automatic traffic routing, public API and provider account access were removed from public pages.
Pillar and product pages carry an explicit boundary statement describing what TokenAtlas does not do.
Wording is reviewed again after any significant content or feature change.
B. Security and data boundaries
The boundaries below are the ones documented on our Security page and enforced in the application. Nothing beyond them is claimed here.
No provider API keys are required, requested or stored.
No provider account connections.
No live provider usage ingestion.
No prompt storage.
Authenticated areas of the product are protected and unauthenticated visitors are redirected to sign in.
Row Level Security is enabled on application tables with explicit access policies.
Server-side input validation and rate limiting are applied to public submission paths.
C. Pricing truthfulness
Paid-plan feature lists are checked against the plan configuration and the authorization logic that enforces it, so nothing is sold that is not shipped.
Each advertised plan feature maps to a real plan flag or limit used by the application.
Capabilities that do not exist — including API access and webhooks — are disabled in configuration and are not marketed as plan features.
Pricing UI, upgrade copy, FAQ, settings and authorization are compared with one another during review.
D. Illustrative content policy
TokenAtlas publishes example scenarios to explain cost modelling. They are presented as examples, never as verified customer outcomes.
Case studies are labelled as illustrative examples in the page, the title and the structured data.
Fictional example companies are never presented as real customers.
No fabricated testimonials, quotes, customer logos or endorsements are published.
Each illustrative case study carries the same capability-boundary disclosure as the rest of the site.
E. Structured data and SEO integrity
Structured data describes the page as a reader sees it. Markup is never used to claim something the page or the product does not support.
Every public page has a single self-referencing canonical URL.
FAQ structured data mirrors FAQ content that is visible on the page.
No Review, AggregateRating, customer or certification schema is published anywhere on the site.
Breadcrumb markup matches the visible breadcrumb trail.
Structured data is updated whenever product capabilities or page content change.
F. Production validation
Before a release is considered SQOS-ready, the live site is checked directly rather than assumed to match the repository.
Production is confirmed to be serving the latest validated build.
Public route health is sampled across the site.
Authenticated routes are confirmed to redirect unauthenticated visitors to sign in.
Row Level Security and table policies are re-checked.
The contact form is verified to validate input, rate limit submissions and persist real messages.
Security headers and the Content Security Policy are read from live responses.
Structured data is parsed and canonical URLs are checked page by page.
The release proceeds only when no blocking finding remains.
G. Continuous review
SQOS is a repeated internal process, not a one-off event. It runs again whenever the product, pricing or public content changes materially.
Source audits across routes, components and server functions.
Production validation against the live site.
Reconciliation of public claims with the implemented product.
Pricing and plan-configuration checks.
Security review of headers, authorization, validation and rate limiting.
Regression checks after major changes.
Current status
SQOS Gold readiness: Pass with improvements. The most recent internal review found no blocking product-truthfulness, pricing, authentication, authorization or security finding. Remaining items are documentation and presentation refinements, which we work through in the normal release cycle.
Last internal review: 2026-08-28. This page is updated when the standard or the outcome changes.