Platform

Security Compliance

Built for organizations where the security review comes before the first session. Here is what we do, what we don't, and what we hand your IT team on request.

Security by design

One environment per client

A dedicated, isolated database instance for each client. No data is shared across clients.

Read more

Production and test environments are physically separated; test environments use anonymized data only. Client content and personal data live in two distinct encrypted repositories.

Hosting in your region

European clients: AWS eu-west-1 (Ireland). US clients: AWS United States. Other regions on request.

Read more

Hosting infrastructure (AWS) certified ISO 27001, 27017, 27018 and SOC 1/2/3. Cross-region replication for redundancy and disaster recovery.

Encrypted everywhere

TLS in transit, encryption at rest, key management with AWS KMS.

Read more

Certificates are managed and monitored with automated expiry alerts. All access to data goes through the application: there is no direct database access.

Minimal data

Name, work email, practice results and audio recordings. No video, ever.

Read more

Recordings are stored apart from personal data and identified by alphanumeric codes with no direct link to the person. No client business data (sales, financial, formulas) is collected. No PCI, HIPAA, FERPA or FISMA regulated data.

Retention you control

Audio deleted after 30 or 60 days, your choice, even during the contract.

Read more

Personal data can be deleted on request at any time, for example when someone leaves the company. After contract termination, data is kept 30 days and then completely deleted. Data is anonymized automatically when retention periods expire.

Internal development only

No outsourcing, no third-party access to production or data.

Read more

Formal change management with testing, approval and rollback; security review on every change; no external APIs exposed.

Architecture and data protection

How client data moves

Two repositories, both encrypted: one for personal data, one for the scenario content you give us. When content needs an external AI service, Skillgym's segregation and qualification algorithms remove direct identifiers and brand-sensitive elements first, and the service receives a transactional identifier, never a name or an email. Every flow is logged.

External AI services

Speech-to-text, language models and avatar rendering run on enterprise APIs with contractual no-training clauses: nothing you or your people say is used to train anyone's model. Five of Skillgym's 120 proprietary algorithms exist only to enforce this segregation at every interaction point. The list of services and their retention terms is in the Data Processing Agreement.

Identity and access

  • Single sign-on

    SAML 2.0 federation with role mapping; single sign-out supported.

  • Two access tiers

    Standard users through SSO; administrators by formal request only, with MFA and VPN.

  • Least privilege

    One administrator holds privileged access to client data. Access is reviewed weekly.

  • Browser only

    HTTPS access from any device's browser; no mobile app or device-level authentication, by design.

Operational resilience

  • Recovery objectives

    Recovery time and recovery point objectives are defined in our provider agreements, monitored and tested. Figures available in the security documentation.

  • Backups and failover

    Regular backups with monthly integrity checks; cross-region replication; failover tested every six months.

  • Incident response

    Documented procedures with defined roles and escalation. Affected clients are notified within two business hours for critical incidents.

  • Logging and vulnerability management

    Centralized logs retained six months and protected from modification; risk-based remediation; penetration testing by qualified personnel; annual risk assessment.

Assurance and documentation

Everything your vendor-risk process needs, sent on request.

  • Security overview for vendor-risk assessments

  • Data Processing Agreement

  • Data-flow description

  • Subprocessor list with retention terms

  • Summary of third-party security assessments

  • Incident response and business-continuity summary

  • Answers to your security questionnaire

Review security with our team

Our technical team walks your IT and security functions through the architecture and the documentation.

System requirements

Supported devices, operating systems and browsers for running Skillgym.

View tech specs →