Security & data handling

A plain description of how we handle hosting, encryption, and access today, and what's on our roadmap. We only describe controls we actually have in place.

Current controls

Hosting & data residency

SkillsetOps is hosted on commercial cloud infrastructure in the United States. Customer data is not stored or processed outside the US.

Encryption

All traffic to and from SkillsetOps is encrypted in transit (TLS 1.2+). Data at rest is encrypted using our cloud provider's storage-level encryption.

Identity & access

Accounts are provisioned by invitation, with multi-factor authentication available and role-based access separating learners from administrators. Administrative actions are logged.

Availability

The platform runs on redundant cloud infrastructure designed for high availability.

Accessibility

SkillsetOps is built to conform with WCAG 2.1 AA, including keyboard operability, captioned video, and readable transcripts.

Security practices

Our controls are designed in alignment with widely used commercial security practices for handling customer data, including access control, logging, and encryption as described above.

Incident response

We maintain an internal process for identifying, containing, and notifying affected customers of any security incident involving their data.

Roadmap

Formal third-party certifications and audits are not yet in place. Where we describe alignment with a security framework above, that reflects our own internal practices and is not a certification or independent assessment.

Questions about security?

We're happy to walk through our practices in more detail.