Security Policy
Security is core to SKYL. This page describes the technical and organisational controls that protect workspaces, accounts and Customer data.
This page is maintained by SKYL to answer common security questions. It reflects current practice and is not a certification.
1. Encryption
All traffic between users and SKYL is encrypted in transit using TLS 1.2 or higher. Data at rest — including database records and uploaded files — is encrypted using industry-standard algorithms managed by our cloud infrastructure providers.
2. Authentication
Users sign in with email and password, Google Sign-In or Apple Sign-In. Passwords are never stored in plain text — they are hashed with modern password-hashing algorithms and per-user salts. Session tokens are rotated and revocable.
3. Passwords
Password rules enforce a minimum length and reject known-compromised passwords where possible. Password resets require access to the verified email address on file.
4. Access controls
Every workspace enforces role-based access. Workspace Owners control who can view, edit or manage tasks, files and messages. Internally, SKYL personnel access production systems only when required and only through authenticated, audited pathways.
5. Cloud security
SKYL runs on managed cloud infrastructure with hardened, isolated environments, network segmentation, key management, and continuous patching. Production databases are not directly exposed to the public internet.
6. Backups
Databases are backed up on a regular schedule with encrypted, off-instance storage. Backup restores are tested periodically.
7. Monitoring and logging
SKYL uses application, infrastructure and error-monitoring tools to detect anomalies, failed sign-ins and unusual activity. Security logs are retained for a defined period for investigation.
8. Incident response
SKYL maintains an incident response process covering detection, containment, eradication, recovery and post-incident review. Where a personal data breach affects Customer data, SKYL will notify affected Customers without undue delay in line with the Data Processing Addendum.
9. Vulnerability management
Dependencies are monitored for known vulnerabilities. Critical fixes are prioritised and deployed on an accelerated timeline.
10. Responsible disclosure
If you believe you have found a security vulnerability in SKYL, please email contact@skyl.solutions with details and steps to reproduce. Please do not publicly disclose the issue until we have had a reasonable opportunity to investigate and remediate. We will not pursue legal action against researchers who follow this process in good faith.
11. Shared responsibility
SKYL secures the platform. Customers are responsible for choosing strong passwords or SSO, protecting their credentials, granting workspace access only to trusted collaborators, and reporting suspected account compromise promptly.
12. Contact
Security questions: contact@skyl.solutions.