Trust & Security

Enterprise-grade security for the compliance platform.

Skale handles licences, visas and government IDs. Security and data protection are structural — built in from the first row, not bolted on.

Certifications

Where we are on the path

SOC 2 Type II

Independent third-party audit planned. Target Q3 2026.

ISO 27001

ISMS implementation underway. Certification target Q4 2026.

UAE PDPL

Privacy-by-design architecture in place; full compliance at production launch.

GDPR

Available for EU-resident customers under our EU data-processing addendum.

Saudi PDPL

On the roadmap for the KSA launch. Compliance target Q4 2026.
Controls

Built-in protection

Encryption at rest (AES-256)
Encryption in transit (TLS 1.2+)
Row-Level Security at the database layer
Role-based access control with audit trails
Two-factor authentication (TOTP)
An audit log on every business write
App-level encryption of PII identifiers
Soft-delete with retention controls (PDPL)
Residency

Where your data lives

In-region (UAE / Mumbai)Active

All data, auth and storage hosted in-region (ap-south-1). Nothing leaves the boundary.

Saudi ArabiaPlanned

In-region residency for the KSA launch.

EU residencyQ2 2027

For EU-resident customers.

Reliability

Operational commitments

99.95%
uptime SLA
target
30 min
incident response
24 hrs
customer notification
PITR
point-in-time recovery

Security questions? Email security@skaleuae.com.