Security Compliance
Built for organizations where the security review comes before the first session. Here is what we do, what we don't, and what we hand your IT team on request.
Security by design
One environment per client
A dedicated, isolated database instance for each client. No data is shared across clients.
Read more
Production and test environments are physically separated; test environments use anonymized data only. Client content and personal data live in two distinct encrypted repositories.
Hosting in your region
European clients: AWS eu-west-1 (Ireland). US clients: AWS United States. Other regions on request.
Read more
Hosting infrastructure (AWS) certified ISO 27001, 27017, 27018 and SOC 1/2/3. Cross-region replication for redundancy and disaster recovery.
Encrypted everywhere
TLS in transit, encryption at rest, key management with AWS KMS.
Read more
Certificates are managed and monitored with automated expiry alerts. All access to data goes through the application: there is no direct database access.
Minimal data
Name, work email, practice results and audio recordings. No video, ever.
Read more
Recordings are stored apart from personal data and identified by alphanumeric codes with no direct link to the person. No client business data (sales, financial, formulas) is collected. No PCI, HIPAA, FERPA or FISMA regulated data.
Retention you control
Audio deleted after 30 or 60 days, your choice, even during the contract.
Read more
Personal data can be deleted on request at any time, for example when someone leaves the company. After contract termination, data is kept 30 days and then completely deleted. Data is anonymized automatically when retention periods expire.
Internal development only
No outsourcing, no third-party access to production or data.
Read more
Formal change management with testing, approval and rollback; security review on every change; no external APIs exposed.
Architecture and data protection
How client data moves
Two repositories, both encrypted: one for personal data, one for the scenario content you give us. When content needs an external AI service, Skillgym's segregation and qualification algorithms remove direct identifiers and brand-sensitive elements first, and the service receives a transactional identifier, never a name or an email. Every flow is logged.
External AI services
Speech-to-text, language models and avatar rendering run on enterprise APIs with contractual no-training clauses: nothing you or your people say is used to train anyone's model. Five of Skillgym's 120 proprietary algorithms exist only to enforce this segregation at every interaction point. The list of services and their retention terms is in the Data Processing Agreement.
Identity and access
Single sign-on
SAML 2.0 federation with role mapping; single sign-out supported.
Two access tiers
Standard users through SSO; administrators by formal request only, with MFA and VPN.
Least privilege
One administrator holds privileged access to client data. Access is reviewed weekly.
Browser only
HTTPS access from any device's browser; no mobile app or device-level authentication, by design.
Operational resilience
Recovery objectives
Recovery time and recovery point objectives are defined in our provider agreements, monitored and tested. Figures available in the security documentation.
Backups and failover
Regular backups with monthly integrity checks; cross-region replication; failover tested every six months.
Incident response
Documented procedures with defined roles and escalation. Affected clients are notified within two business hours for critical incidents.
Logging and vulnerability management
Centralized logs retained six months and protected from modification; risk-based remediation; penetration testing by qualified personnel; annual risk assessment.
Assurance and documentation
Everything your vendor-risk process needs, sent on request.
Security overview for vendor-risk assessments
Data Processing Agreement
Data-flow description
Subprocessor list with retention terms
Summary of third-party security assessments
Incident response and business-continuity summary
Answers to your security questionnaire
Review security with our team
Our technical team walks your IT and security functions through the architecture and the documentation.
System requirements
Supported devices, operating systems and browsers for running Skillgym.
