Independently audited, certified, and built so your information stays yours.

ISO 27001 Compliant
SOC 2 Type II certification in progress.
Privacy principles
Three core commitments
Key principles for data governance
You own your data
The content, learner data, and frameworks you bring into Skillet remain yours.
You set retention
Control how long records persist and when they are deleted.
AI never trains on your data
Customer content is not used to train or improve third party AI models or our own.

Compliance Management by Drata
Certification Management and Continuous Monitoring
Identity
Single sign-on, the way you already do it
Skillet plugs into the identity provider you already trust.




A closed knowledge ecosystem
AI responses are grounded in approved sources you control. Approval flows can be integrated for multi-stakeholder signoff. Contextual infrastructure is isolated at the product level so that practice stays focused and accurate.
Bounded AI responses
AI replies are centered in the the approved content you've published to avoid referencing unapproved outside sources.
Tenant isolation
Your content and unique model context are logically isolated and never shared across customers or products.
Compliance Alerts
Potentially inappropriate claims and comments can be automatically detected and flagged for review.
MLR approval flows
Optional approval flows can be configured so medical, legal, and regulatory reviewers can sign off on key inputs.
Security & Partners
Protected, and prepared
Strong protections by default, partners held to the same bar, and a documented plan ready if anything ever goes wrong.
Encryption Standards
Your data is encrypted in transit and at rest using industry-standard protocols and key management.
Detailed specifications are available as part of our security documentation package.
Incident response & recovery
24/7 monitoring, documented playbooks, and on-call response protocols are in place.
Documented process includes detection and triage, containment, direct customer notification within contractual SLAs, recovery from validated backups, and a post-incident review.
Partners & subprocessors
Our subprocessors are bound by mutual commitments and Data Processing Agreements that mirror the obligations we make to you.
A list of active subprocessors is available to customers and prospects at any time.
ReGIONAL CERTIFICATIONS
We meet you wherever you operate.
Here are some examples, please contact us to discuss your specific geography.

EU/EEA. DPA available, SCCs in place, EU-hosted data residency option.

UK addendum to SCCs, ICO-aligned practices.

Brazil. Aligned data subject rights and transfer mechanisms.