SKYBER AI

Security at Skyber AI

This page describes how the product is built and operated today by Investech Skyber. It is a plain description of our architecture, not a certification claim — we hold no third-party audit or compliance certification at this stage, and we will say so here when that changes.

Authentication and sessions

  • Every request to the product requires an authenticated session.
  • Sessions are issued by the managed authentication service; passwords are never stored by the application.
  • Server functions that touch your data re-verify the caller before reading or writing anything.

Authorization and data isolation

  • Conversations, messages, personas, memories, files and billing rows are scoped to the owning account.
  • Per-user access rules are enforced in the database itself, not only in application code, so a bug in the UI cannot expose another account's rows.
  • Administrative capabilities are behind a separate role table checked server-side; they are never granted from client state.

Storage and encryption

  • Application data is held in an encrypted managed database.
  • Uploaded attachments are stored in a private bucket that is not publicly listable.
  • Files are served through short-lived signed links rather than permanent public URLs.
  • Traffic to and from the application is served over TLS.

Model providers and your keys

  • You can choose the model per conversation, or connect your own OpenAI-compatible endpoint.
  • Provider API keys you supply are stored server-side and are used only to make requests on your behalf; they are not returned to the browser.
  • When you bring your own endpoint, prompt traffic goes to the provider you configured.

Payments

  • Card data never reaches our servers. Web orders are processed by Paddle.com as Merchant of Record; Android purchases are processed by Google Play.
  • Card payments handled through Stripe are processed on Stripe's infrastructure; the application stores only the resulting subscription state.
  • Webhooks are signature-verified and processed idempotently before any entitlement changes.

Retention and deletion

  • You can delete individual conversations, memories and personas at any time from the product.
  • Deleting your account removes stored conversations, messages, personas, memories and uploaded files.
  • Billing and audit records are retained where required for tax, accounting and fraud-prevention obligations.

Reporting a vulnerability

  • If you believe you have found a security issue, contact us through the support page before disclosing it publicly.
  • Please include reproduction steps and the affected URL. We will acknowledge and work with you on a fix.

See also the privacy policy for what we collect and why, and the documentation for how the system is put together.