Your data, your control

Your data, your control

Independently audited, certified, and built so your information stays yours.

ISO 27001 Compliant

SOC 2 Type II certification in progress.

Privacy principles

Three core commitments

Key principles for data governance

You own your data

The content, learner data, and frameworks you bring into Skillet remain yours.

You set retention

Control how long records persist and when they are deleted.

AI never trains on your data

Customer content is not used to train or improve third party AI models or our own.

Compliance Management by Drata

Certification Management and Continuous Monitoring

Identity

Single sign-on, the way you already do it

Skillet plugs into the identity provider you already trust.

Okta
Microsoft Entra ID

Content Management & Compliance

Content Management & Compliance

A closed knowledge ecosystem

AI responses are grounded in approved sources you control. Approval flows can be integrated for multi-stakeholder signoff. Contextual infrastructure is isolated at the product level so that practice stays focused and accurate.

Bounded AI responses

AI replies are centered in the the approved content you've published to avoid referencing unapproved outside sources.

Tenant isolation

Your content and unique model context are logically isolated and never shared across customers or products.

Compliance Alerts

Potentially inappropriate claims and comments can be automatically detected and flagged for review.

MLR approval flows

Optional approval flows can be configured so medical, legal, and regulatory reviewers can sign off on key inputs.

Security & Partners

Protected, and prepared

Strong protections by default, partners held to the same bar, and a documented plan ready if anything ever goes wrong.

Encryption Standards

Your data is encrypted in transit and at rest using industry-standard protocols and key management.

Detailed specifications are available as part of our security documentation package.

Incident response & recovery

24/7 monitoring, documented playbooks, and on-call response protocols are in place.

Documented process includes detection and triage, containment, direct customer notification within contractual SLAs, recovery from validated backups, and a post-incident review.

Partners & subprocessors

Our subprocessors are bound by mutual commitments and Data Processing Agreements that mirror the obligations we make to you.

A list of active subprocessors is available to customers and prospects at any time.

ReGIONAL CERTIFICATIONS

We meet you wherever you operate.

Here are some examples, please contact us to discuss your specific geography.

GDPR

GDPR

EU/EEA. DPA available, SCCs in place, EU-hosted data residency option.

UK GDPR

UK GDPR

UK addendum to SCCs, ICO-aligned practices.

LGPD

LGPD

Brazil. Aligned data subject rights and transfer mechanisms.

Interested in learning more?

Contact us to initiate an IT review, or establish a DPA.

Contact us to initiate an IT review, or establish a DPA.