Trust Center

Where your data lives, and who can reach it.

Sky is sold to operating leaders who have to answer to a security review. This page states what is actually deployed — and what we do not claim.

Residency and model use

Data stored in Ireland

All platform data is stored on AWS in eu-west-1. Nothing is stored outside the European Union.

Inference stays in the EU

Model inference runs on Amazon Bedrock. Requests start in eu-west-1 and may be served from another EU region through Bedrock's EU inference profiles. The IAM role that permits inference is scoped to eu-west-1.

We do not train on your data

Your business data and your conversations are never used to train models — ours or anyone else's.

AWS cannot use your content to improve its services

AWS AI services may retain customer content for service improvement, and may hold it outside the region you use, unless you opt out. We have opted out at the organization level, for every supported service and every account, current and future.

Isolation

A namespace per client

Each customer runs in a dedicated Kubernetes namespace with its own deployment, its own secrets, and its own continuous delivery application. Nothing is shared at the application layer.

A data stack per client

Each customer gets its own database stack, provisioned from its own configuration. Customer data is not co-mingled in a shared multi-tenant table.

Fully local deployment on request

Where a customer requires it, Sky can be deployed entirely inside their own perimeter.

Protection and recovery

Encrypted at rest and in transit

Database storage is encrypted. Object storage is encrypted, versioned, and blocked from public access. Traffic is served over TLS.

30 days of point-in-time recovery

Databases carry 30 days of point-in-time recovery, with deletion protection enabled so an instance cannot be dropped by accident.

Threat detection and an audit trail

GuardDuty runs continuously. API activity is recorded in CloudTrail and retained for 365 days in production. Metric filters raise alarms to an on-call topic.

What we do not claim

We hold no security certifications. Not SOC 2, not ISO 27001, not HIPAA. We are a small company and we would rather tell you that than imply an audit we have not passed.

What we offer instead is specific: a signed Data Processing Agreement, a named list of sub-processors, per-client isolation you can verify in a deployment review, and answers that cite their sources so your team can check them. If your procurement process requires a certification we do not hold, tell us early and we will say so plainly rather than waste your time.

Documents and contacts

  • Sub-processors — everyone who touches data on our behalf, and where they are.
  • Privacy Policy — what we collect across the site, the platform, and the mobile app.
  • Account and Data Deletion — who can delete what, and how long it takes.
  • Reporting a vulnerability — write to info@skyfirstlabs.com. We will acknowledge within 5 working days. Please give us a reasonable window to fix an issue before disclosing it.
  • Data Processing Agreement — signed with every customer. Request a copy at info@skyfirstlabs.com.