Skykit Trust Center
Security, Compliance, Privacy
Explore how Skykit protects your data with enterprise-grade security, industry certifications, and transparent operational practices—all built to keep your organization safe, secure, and informed.
Our 360-Degree Security Model
We protect your network from every angle. Our security lifecycle ensures that threats are mitigated during development, deployment, and ongoing operation.
1. Security by Design
We embed security into every stage of development to eliminate vulnerabilities before they emerge.
- Secure Development Lifecycle (SDL)
- Rigorous Code Reviews & Testing (SAST/DAST)
- Vetted 3rd-Party Components
2. Secure Architecture
Built on a fortified foundation ensuring your data is protected at rest, in transit, and at the edge.
- Hardened Firmware, Operating System & Media Players Devices
- End-to-End Encryption (AES-256 / TLS)
- GCP Best Practices (Isolated VPCs)
3. Proactive Security Services
Security isn't a one-time effort. We maintain continuous vigilance against emerging threats.
- 24/7 Monitoring & Threat Intelligence
- Regular Penetration Testing by leading independent security firms
- SOC2 Type 2 Compliant & Compliance Audits
Security Controls & Specifications
Compliance
We adhere to rigorous independent audit standards to ensure your data is safe and available.
Infrastructure Security
Built on Google Cloud Platform (GCP) for hyperscale security and resilience.
Device Hardening
Purpose-built firmware that eliminates common Android attack vectors at the edge.
Product Security & Access
Strict logical isolation and identity management for every tenant.
Reliability & DR
Designed for 24/7 uptime with rigorous disaster recovery protocols and SLAs.
Shared Responsibility Model
Security is a partnership. We define clear boundaries so you know exactly what we handle.
Skykit's Responsibility
- Physical Security: Data center security (via GCP) and hardware manufacturing integrity.
- Platform Security: Cloud infrastructure, vulnerability management, and API protection.
- Device Firmware: OS hardening, removing bloatware, and delivering OTA updates.
- Encryption: Ensuring data is encrypted in transit and at rest.
Customer's Responsibility
- Access Control: Managing user accounts, enforcing strong passwords, and offboarding.
- Physical Device: Preventing unauthorized physical tampering with screens or players on-site.
- Content Governance: Ensuring uploaded content complies with internal policies.
- Network: Whitelisting Skykit domains on local firewalls.
FAQ
Where does Skykit store my data?
Skykit stores your data primarily on Google Cloud Platform (GCP) across US Regions & Zones, ensuring high availability. Backups are performed at least daily and stored on Google Cloud Storage fixed media. Approved storage locations for confidential data include Skykit laptops, Google Drive, and GitHub.
How does Skykit protect my data?
Skykit protects your data through multiple security measures: Data separation through logical tenant isolation, encryption in transit (TLS/HTTPS) and at rest (AES-256), strict role-based access control, multi-factor authentication for sensitive systems, DDoS protection via Google Cloud Armor, Web Application Firewalls in blocking mode, and comprehensive logging/monitoring.
Does Skykit sell my data?
No. At Skykit, we are committed to protecting your privacy. We do not sell, rent, or trade your personal information or customer data to third parties. Your data is used solely to provide and improve our services.
How long does Skykit retain my data?
Skykit follows a formal Change Management Policy for all production system changes. We utilize an agile development process where every change requires documentation, security review, testing (automated and manual), and leadership approval prior to deployment. We maintain strict separation between development, staging, and production environments, and all deployments include defined back-out procedures to ensure system stability.
How can I request data deletion?
For data deletion requests, contact Skykit support directly at support@skykit.com. Data subject requests may be reviewed by legal counsel before processing.
Does Skykit use customer data to train Artificial Intelligence (AI) models?
No. Skykit does not use customer content or data to train public Artificial Intelligence (AI) or Machine Learning (ML) models. Your data remains confidential and isolated within your tenant.
How does Skykit handle hardware end-of-life and disposal?
Skykit follows strict decommissioning procedures for hardware. All devices returned to Skykit (RMA or end-of-life) undergo a secure data wiping process to remove all customer configurations and credentials before being recycled or disposed of in accordance with environmental regulations.
Compliance Reports & Resources
SOC 2 Type 2 Report
Independent audit report covering Security, Availability, and Confidentiality.
Security Overview 2026
Comprehensive guide to policies, architecture, and controls.
Penetration Test Summary
Attestation letter from independent security firms regarding our latest cloud and hardware penetration tests.
Device Security Whitepaper
Technical deep-dive into Android firmware and hardening specs.