Trust & Security

Security and privacy aren’t a feature. They’re the product.

Skale is built, run and managed by cybersecurity professionals. We hold licences, visas, beneficial-owner records and government IDs on behalf of compliance teams — so every design decision starts from ‘how could this be abused, and how do we stop it.’ Security-by-design and data privacy live in the DNA of how the company is run, not on a policy page.

Our approach

Run by cybersecurity practitioners

Skale is founded and operated by people who do security for a living. Cybersecurity is our first priority and the protection of consumer and client personal data is right beside it — not a compliance checkbox, but the reason the platform is architected the way it is.

Security-first culture

Threat-modelling is part of every feature review, not an afterthought. We assume the platform will be attacked and design each capability — and each release — to fail closed.

Secure by design

Least-privilege, tenant isolation and full auditability are enforced at the database layer, not just the interface. New features inherit the same controls before they ship.

Privacy by default

We minimise the personal data we hold, encrypt the identifiers we must keep, and treat client PII — directors, UBOs, visa and ID data — as the most sensitive thing on the platform.
In place today

Controls that protect every record

These are live in the platform now — enforced structurally, on every workspace, every write and every read.

Encryption everywhere

AES-256 at rest and TLS 1.2+ in transit, with a second layer of application-level encryption over the most sensitive PII identifiers.

Tenant isolation (RLS)

Row-Level Security at the database means consultant A can never see consultant B’s clients — and inside a firm, only assigned staff can open a given client’s data.

Least-privilege access

Role-based access control, two-factor authentication (TOTP) and last-owner protection. Every role change is written to the audit trail.

Immutable audit trail

An append-only audit log on every business write, and a record of every read or export of personal data — the evidence trail a regulator asks for, always available.

Safe deletion & retention

Soft-delete with retention controls aligned to PDPL. Nothing personal is silently destroyed, and nothing is kept longer than it should be.

Resilience

Point-in-time recovery on the database and continuous monitoring, so a mistake or an incident is recoverable — not catastrophic.
AI, secured

Kai is safe by construction

Skale’s AI copilot handles regulated work, so it is built to the same security bar as the rest of the platform — arguably higher. Kai never acts on its own.

A human approves every action

Kai drafts, explains and proposes — it never sends, changes or deletes anything by itself. Every action is staged as a preview and released only when a permitted user approves it, graded by risk tier.

It can’t cross tenants

Kai runs inside the same Row-Level Security as every user, and a hard gate blocks any attempt to reach another workspace’s data. Instruction-like text hidden inside a record is treated as data to summarise — never as a command to obey.

No invented facts, fully audited

A provenance guard stops Kai quoting any legal or tax figure that isn’t from a sourced, published rule, and a draft-pack firewall blocks unverified dates. Every AI action writes to an append-only AI audit log, and an adversarial red-team test suite must pass before any wider rollout — behind a kill switch.
Data protection

Your clients’ personal data, protected in every market

Skale operates as a data processor / intermediary: your clients stay the controller of their people’s data, and we handle it only to run the service — under a data-processing agreement mirrored down to our own sub-processors.

Jurisdiction-aware by design

Data-protection alignment per market — UAE PDPL & ADGM DPR, Canada PIPEDA & Québec Law 25, Australia’s Privacy Act (APPs) and Singapore’s PDPA — with the right cross-border transfer safeguards and at-collection notice text clients can hand to data subjects.

Breach-ready to the strictest clock

One incident runbook built to the tightest deadline we face (72-hour / 3-day notification). As processor, we notify the client without undue delay so their regulator deadlines are met.

Sensitive data gated

Biometric, visa and health data sit behind explicit consent, encryption and a data-protection impact assessment — handled as special-category information, not ordinary fields.

Least data, purpose-limited

We collect the minimum needed, use it only for the compliance work it was shared for, and keep sub-processors on the same contractual leash we hold ourselves to.
Residency & operations

Where your data lives, and how we keep it up

Today all application, auth and storage run inside a single dedicated region, and data stays within that boundary. In-country residency for specific markets is on the roadmap below.

In-region
Data residency
single region; data stays in the boundary
99.95%
Uptime target
continuously monitored
30 min
Incident response
target on a confirmed incident
24 hrs
Customer notification
on a confirmed incident
Assurance

Independent assurance — in progress

We hold ourselves to recognised frameworks and are working toward third-party attestation. We won’t display a badge we haven’t earned, so these are shown as what they are.

SOC 2

In progress Building toward a SOC 2 Type II examination; the underlying controls — access, change management, monitoring — are already operating.

ISO 27001

In progress Implementing an information-security management system aligned to ISO 27001, with formal certification to follow.

UAE PDPL & ADGM DPR

Aligned Privacy-by-design architecture in place for our first and most mature market.

PIPEDA · Law 25 · APPs · PDPA · GDPR

Aligned as we launch Data-protection alignment tracked and evidenced per market, with an EU data-processing addendum available for EU-resident customers.
Roadmap · next 1–2 years

Security is never finished

What we’re actively building next. These are commitments, not vague intentions — tracked the same way as any other part of the product.

Independent penetration testing

Planned Regular third-party penetration tests and security assessments, with summary reports available to enterprise customers under NDA.

Enterprise SSO & provisioning

Planned SAML single sign-on and SCIM user provisioning / de-provisioning, so larger teams manage access from their own identity provider.

Data-residency options

Planned In-country hosting beyond today’s single region — Saudi Arabia and the EU first — so regulated clients can keep data in-country.
Responsible disclosure

Found a security issue? Tell us.

We practise responsible disclosure and would rather hear about a problem than not. Report anything security-related and we’ll work it with you.

contact@getskale.com
Skale is pre-revenue and in pilot across its live markets; the demo uses simulated data and no real client accounts. The data-protection detail on this page is security and compliance engineering, not legal advice — clients remain responsible for their own regulatory obligations.