Security and privacy aren’t a feature. They’re the product.
Skale is built, run and managed by cybersecurity professionals. We hold licences, visas, beneficial-owner records and government IDs on behalf of compliance teams — so every design decision starts from ‘how could this be abused, and how do we stop it.’ Security-by-design and data privacy live in the DNA of how the company is run, not on a policy page.
Our approach
Run by cybersecurity practitioners
Skale is founded and operated by people who do security for a living. Cybersecurity is our first priority and the protection of consumer and client personal data is right beside it — not a compliance checkbox, but the reason the platform is architected the way it is.
Security-first culture
Threat-modelling is part of every feature review, not an afterthought. We assume the platform will be attacked and design each capability — and each release — to fail closed.
Secure by design
Least-privilege, tenant isolation and full auditability are enforced at the database layer, not just the interface. New features inherit the same controls before they ship.
Privacy by default
We minimise the personal data we hold, encrypt the identifiers we must keep, and treat client PII — directors, UBOs, visa and ID data — as the most sensitive thing on the platform.
In place today
Controls that protect every record
These are live in the platform now — enforced structurally, on every workspace, every write and every read.
Encryption everywhere
AES-256 at rest and TLS 1.2+ in transit, with a second layer of application-level encryption over the most sensitive PII identifiers.
Tenant isolation (RLS)
Row-Level Security at the database means consultant A can never see consultant B’s clients — and inside a firm, only assigned staff can open a given client’s data.
Least-privilege access
Role-based access control, two-factor authentication (TOTP) and last-owner protection. Every role change is written to the audit trail.
Immutable audit trail
An append-only audit log on every business write, and a record of every read or export of personal data — the evidence trail a regulator asks for, always available.
Safe deletion & retention
Soft-delete with retention controls aligned to PDPL. Nothing personal is silently destroyed, and nothing is kept longer than it should be.
Resilience
Point-in-time recovery on the database and continuous monitoring, so a mistake or an incident is recoverable — not catastrophic.
AI, secured
Kai is safe by construction
Skale’s AI copilot handles regulated work, so it is built to the same security bar as the rest of the platform — arguably higher. Kai never acts on its own.
A human approves every action
Kai drafts, explains and proposes — it never sends, changes or deletes anything by itself. Every action is staged as a preview and released only when a permitted user approves it, graded by risk tier.
It can’t cross tenants
Kai runs inside the same Row-Level Security as every user, and a hard gate blocks any attempt to reach another workspace’s data. Instruction-like text hidden inside a record is treated as data to summarise — never as a command to obey.
No invented facts, fully audited
A provenance guard stops Kai quoting any legal or tax figure that isn’t from a sourced, published rule, and a draft-pack firewall blocks unverified dates. Every AI action writes to an append-only AI audit log, and an adversarial red-team test suite must pass before any wider rollout — behind a kill switch.
Data protection
Your clients’ personal data, protected in every market
Skale operates as a data processor / intermediary: your clients stay the controller of their people’s data, and we handle it only to run the service — under a data-processing agreement mirrored down to our own sub-processors.
Jurisdiction-aware by design
Data-protection alignment per market — UAE PDPL & ADGM DPR, Canada PIPEDA & Québec Law 25, Australia’s Privacy Act (APPs) and Singapore’s PDPA — with the right cross-border transfer safeguards and at-collection notice text clients can hand to data subjects.
Breach-ready to the strictest clock
One incident runbook built to the tightest deadline we face (72-hour / 3-day notification). As processor, we notify the client without undue delay so their regulator deadlines are met.
Sensitive data gated
Biometric, visa and health data sit behind explicit consent, encryption and a data-protection impact assessment — handled as special-category information, not ordinary fields.
Least data, purpose-limited
We collect the minimum needed, use it only for the compliance work it was shared for, and keep sub-processors on the same contractual leash we hold ourselves to.
Residency & operations
Where your data lives, and how we keep it up
Today all application, auth and storage run inside a single dedicated region, and data stays within that boundary. In-country residency for specific markets is on the roadmap below.
In-region
Data residency
single region; data stays in the boundary
99.95%
Uptime target
continuously monitored
30 min
Incident response
target on a confirmed incident
24 hrs
Customer notification
on a confirmed incident
Assurance
Independent assurance — in progress
We hold ourselves to recognised frameworks and are working toward third-party attestation. We won’t display a badge we haven’t earned, so these are shown as what they are.
SOC 2
In progress Building toward a SOC 2 Type II examination; the underlying controls — access, change management, monitoring — are already operating.
ISO 27001
In progress Implementing an information-security management system aligned to ISO 27001, with formal certification to follow.
UAE PDPL & ADGM DPR
Aligned Privacy-by-design architecture in place for our first and most mature market.
PIPEDA · Law 25 · APPs · PDPA · GDPR
Aligned as we launch Data-protection alignment tracked and evidenced per market, with an EU data-processing addendum available for EU-resident customers.
Roadmap · next 1–2 years
Security is never finished
What we’re actively building next. These are commitments, not vague intentions — tracked the same way as any other part of the product.
Independent penetration testing
Planned Regular third-party penetration tests and security assessments, with summary reports available to enterprise customers under NDA.
Enterprise SSO & provisioning
Planned SAML single sign-on and SCIM user provisioning / de-provisioning, so larger teams manage access from their own identity provider.
Data-residency options
Planned In-country hosting beyond today’s single region — Saudi Arabia and the EU first — so regulated clients can keep data in-country.
Responsible disclosure
Found a security issue? Tell us.
We practise responsible disclosure and would rather hear about a problem than not. Report anything security-related and we’ll work it with you.
contact@getskale.comSkale is pre-revenue and in pilot across its live markets; the demo uses simulated data and no real client accounts. The data-protection detail on this page is security and compliance engineering, not legal advice — clients remain responsible for their own regulatory obligations.