Security First, Always
We built SkuldBot with security at its core, implementing defense-in-depth strategies and flexible deployment options to protect your most sensitive data.
Flexible, Secure Deployment
Your workflows execute, and your business data is processed and stored, within your own infrastructure or subscription in every tier. Skuld hosts only the control plane (Studio and Orchestrator management layer). Enterprise adds further controls, including full air-gap capability where required.
- Enterprise: air-gapped or fully isolated deployment options (AWS, Azure, GCP, bare-metal)
- Encryption key management options for Enterprise deployments
- Network isolation options for dedicated deployments
- Support for data residency requirements
Enterprise Deployment Targets
Workspace
Workspace
Workspace
Isolated, encrypted workspaces for Enterprise deployments
Security Features
Comprehensive security controls designed for regulated industries
Encryption
Data encrypted at rest (AES-256) and in transit (TLS 1.3), with key management aligned to your deployment model.
- AES-256 encryption at rest
- TLS 1.3 for all connections
- Encryption key management for Enterprise deployments
- Automatic key rotation support
Access Control
Fine-grained role-based access control with multi-factor authentication and SSO integration.
- Role-based access control (RBAC)
- Multi-factor authentication (MFA)
- SSO via SAML 2.0 / OIDC
- Least privilege principle
Audit Logging
Comprehensive audit trails for all data access, workflow execution, and system changes, captured in Evidence Pack records.
- All access logged with timestamps
- User action tracking
- Tamper-proof audit records
- Exportable audit trails
Infrastructure
Enterprise customers can deploy SkuldBot within their own private cloud or on-premise infrastructure.
- Hosted platform by default
- Enterprise: private cloud or on-premise on AWS, Azure, GCP, or bare-metal
- Network isolation options for dedicated deployments
- Support for data residency requirements
Data Protection
Built-in PII/PHI detection and protection with multiple de-identification methods.
- Automatic PII/PHI pattern and AI-based classification
- HIPAA Safe Harbor-aligned de-identification support
- Tokenization, pseudonymization & masking
- Field-level encryption
Threat Detection
Continuous monitoring and anomaly detection to identify and respond to threats.
- 24/7 security monitoring
- Anomaly detection
- Intrusion detection
- Automated alerting
Certifications & Compliance
We design our controls to align with major regulatory frameworks and industry standards
HIPAA
AlignedHIPAA-aligned safeguards for Protected Health Information
SOC 2
Designed ForControls designed for SOC 2 security, availability, and confidentiality criteria
GDPR
AlignedEU data protection regulation compliance controls
Security Practices
Secure Development
Security is integrated into our SDLC. All code undergoes security review, static analysis, and dependency scanning before deployment.
Vulnerability Management
Regular vulnerability scanning, penetration testing by third parties, and a responsible disclosure program ensure continuous security improvement.
Employee Security
Background checks, security training, and least-privilege access for all employees. Regular phishing simulations and security awareness programs.
Incident Response
Documented incident response procedures with defined roles and communication protocols. Regular tabletop exercises to ensure readiness.
Responsible Disclosure
We take security seriously and appreciate the security research community's efforts to help us improve. If you discover a security vulnerability, please report it responsibly.
Report vulnerabilities to:
security@skuldbot.comPlease include:
- • Description of the vulnerability
- • Steps to reproduce
- • Potential impact
- • Any suggested remediation
We aim to acknowledge reports promptly and provide status updates as we investigate and remediate issues.
Need More Information?
Request our security documentation or schedule a call with our security team to discuss your specific requirements.