Skip to content

Certifications, attestations, and security controls

This page states SkillFoundry's security posture plainly — what is certified, what is in progress, the controls that are actually implemented, and how to obtain the reports your vendor-risk team needs.

Read the status honestly

Certifications are point-in-time and program-dependent. Rather than print a logo, this page describes the control environment (which is verifiable from the platform) and directs you to your account team for the current report status — including whether a SOC 2 report is Type I or Type II and the exact period it covers. Do not treat a roadmap item as an obtained certificate.

Attestation status

Framework Status How to obtain
SOC 2 (Security, Availability, Confidentiality) Report status and reporting period confirmed per-deal Request the current report under NDA from security@skillfoundry.dev
ISO/IEC 27001 (ISMS) Certificate status confirmed per-deal Request the current certificate + Statement of Applicability under NDA
GDPR / UK GDPR Program in place — DPA, SCCs, DSAR tooling, DPIA support See DPA, Data retention and erasure
CCPA / CPRA Service-provider terms available See DPA
Penetration test Third-party testing program Request latest summary under NDA

If a framework above is at "in progress" for your evaluation date, your account team will tell you the target milestone and share the current bridge evidence (control descriptions, prior test summaries, this documentation) so your risk assessment is not blocked.

The control environment (implemented today)

These controls are implemented in the platform and operations and map directly to SOC 2 Trust Services Criteria and ISO 27001 Annex A domains.

Access control and authentication

  • Hosted identity provider with email/password, social login, and enterprise SAML SSO and SCIM provisioning for organizations (see Organization administration). MFA is handled in the sign-in flow.
  • Role-based access control — Candidate, Interviewer, Organization Admin, Platform Admin — with organization boundaries enforced on data access. Reviewer access to candidate data is scoped to the reviewer's organization.
  • API authentication via bearer tokens and scoped API keys for the public API (see API overview).

Encryption

  • In transit: production enforces HTTPS/TLS; HSTS (max-age=31536000; includeSubDomains; preload), upgrade-insecure-requests, and block-all-mixed-content are set. The production configuration refuses to start if the frontend URL is not HTTPS or the database connection is not SSL/TLS.
  • At rest: database storage encryption plus application-level Fernet encryption of stored secrets/tokens (integration credentials), gated by a required ENCRYPTION_KEY in production.
  • Secret hygiene: production startup validation rejects weak/short/common secret keys and requires distinct signing and encryption keys.

Network and application hardening

Enforced by middleware on every request:

  • Security headers — strict CSP, X-Content-Type-Options: nosniff, X-Frame-Options: DENY, frame-ancestors 'none', Referrer-Policy, cross-origin isolation policies, and a restrictive Permissions-Policy that disables camera, microphone, geolocation, USB, and sensors.
  • CSRF protection via double-submit token on state-changing requests.
  • Input sanitization & request-size limits, with detection and blocking of SQL-injection, XSS, path-traversal, and command-injection patterns in URLs, headers, and bodies, plus dangerous file-upload/binary-signature rejection.
  • Rate limiting — distributed (Redis) with per-endpoint tiers (auth, api, upload, admin, webhook), burst protection, and per-IP/per-user/global ceilings, with an in-memory fallback so limiting never fully fails open.
  • Automated abuse response — repeat offenders and severe attacks are added to an IP blocklist; security events and metrics are recorded for monitoring.

Logging and monitoring

  • Application audit log of business actions (7-year retention) — see Access and audit logging.
  • Request/security telemetry with per-endpoint and per-status metrics, auth-failure / access-denied / rate-limited counters, and request IDs for traceability.
  • Error and performance monitoring via Sentry (tracing middleware) in production.

Resilience: backups and disaster recovery

  • Automated backups — scheduled full (daily) and incremental (4-hourly) backups, compressed and written to object storage.
  • Integrity-verified — every backup carries MD5 + SHA-256 checksums, is verified after upload, and undergoes periodic deep verification (including referential-integrity checks); deduplication avoids redundant copies.
  • Cross-region replication to a secondary region for disaster recovery.
  • Defined RTO/RPO — backup metadata records a Recovery Time Objective of 4 hours and Recovery Point Objective of 1 hour; a DR test routine exercises restore (dry-run), cross-region access, and measures actual RTO/RPO.
  • Point-in-time recovery and pre-restore safety snapshots before any restore.
  • Bounded retention — backups are kept for up to 90 days and then pruned (no longer-lived weekly or monthly copies); pending deletions are applied again if a backup is ever restored. Backup-health scoring/alerting flags overdue or failing backups.

Data protection and privacy engineering

  • Data minimization by design in behavioral telemetry — "activity, not content," with sanitization of emails, tokens, IPs, and home paths before upload, and workspace scoping in the IDE extension (see Behavioral monitoring privacy model).
  • Anonymization / pseudonymization utilities for de-identifying data on the retention path.
  • Privacy Impact Assessment (PIA/DPIA) tooling that scores processing risk, flags high-risk factors (automated decision-making, profiling, sensitive data, third-party sharing), and produces recommendations — used to support the DPIA in Behavioral monitoring privacy model.
  • Breach severity assessment with automatic 72-hour GDPR notification-deadline calculation (see Data retention and erasure).

Sub-processors

SkillFoundry uses a limited set of sub-processors (e.g. cloud hosting/object storage, the hosted identity provider, payment processing, error monitoring, and AI model providers used for stakeholder simulation and narrative generation). The current, itemized list — with each sub-processor's purpose, data categories, and region — is maintained as a living document and provided with the DPA. Customers can subscribe to advance notice of sub-processor changes and have a contractual objection window.

AI model providers

Where AI-assisted report narratives or the simulated Customer/TPM personas are used, summaries of behavioral results and conversation text — not your candidate's raw source code — are processed by the model provider. Providers are bound by the DPA and do not train foundation models on your data under the enterprise terms. Confirm the specific provider and configuration for your plan with your account team.

How to run your vendor risk assessment

  1. Sign the mutual NDA.
  2. Request the SOC 2 report / ISO 27001 certificate, sub-processor list, and latest penetration-test summary.
  3. Request completed CAIQ / SIG questionnaire responses if your process requires them.
  4. Sign the DPA (with SCCs for EU/UK transfers).
  5. Subscribe to sub-processor change notifications.