Security at Skyber AI
This page describes how the product is built and operated today by Investech Skyber. It is a plain description of our architecture, not a certification claim — we hold no third-party audit or compliance certification at this stage, and we will say so here when that changes.
Authentication and sessions
- Every request to the product requires an authenticated session.
- Sessions are issued by the managed authentication service; passwords are never stored by the application.
- Server functions that touch your data re-verify the caller before reading or writing anything.
Authorization and data isolation
- Conversations, messages, personas, memories, files and billing rows are scoped to the owning account.
- Per-user access rules are enforced in the database itself, not only in application code, so a bug in the UI cannot expose another account's rows.
- Administrative capabilities are behind a separate role table checked server-side; they are never granted from client state.
Storage and encryption
- Application data is held in an encrypted managed database.
- Uploaded attachments are stored in a private bucket that is not publicly listable.
- Files are served through short-lived signed links rather than permanent public URLs.
- Traffic to and from the application is served over TLS.
Model providers and your keys
- You can choose the model per conversation, or connect your own OpenAI-compatible endpoint.
- Provider API keys you supply are stored server-side and are used only to make requests on your behalf; they are not returned to the browser.
- When you bring your own endpoint, prompt traffic goes to the provider you configured.
Payments
- Card data never reaches our servers. Web orders are processed by Paddle.com as Merchant of Record; Android purchases are processed by Google Play.
- Card payments handled through Stripe are processed on Stripe's infrastructure; the application stores only the resulting subscription state.
- Webhooks are signature-verified and processed idempotently before any entitlement changes.
Retention and deletion
- You can delete individual conversations, memories and personas at any time from the product.
- Deleting your account removes stored conversations, messages, personas, memories and uploaded files.
- Billing and audit records are retained where required for tax, accounting and fraud-prevention obligations.
Reporting a vulnerability
- If you believe you have found a security issue, contact us through the support page before disclosing it publicly.
- Please include reproduction steps and the affected URL. We will acknowledge and work with you on a fix.
See also the privacy policy for what we collect and why, and the documentation for how the system is put together.
