Trust

Security at Skala

How we secure your real-time data flow, enforce network separation, and protect our global edge infrastructure.

Our Security Principles

Security isn't a feature—it's the core of how Skala operates. Here is how we safeguard millions of transactions.

Edge-Level Sandboxing

All event evaluation runs within isolated V8 runtimes globally. We never run arbitrary, unsandboxed scripts on our infrastructure, maintaining absolute customer data segregation.

Encryption Everywhere

Data is encrypted in transit using TLS 1.3/HTTPS, and telemetry logs stored within our distributed Cloudflare D1 databases are fully encrypted at rest using AES-256.

Least Privilege Access

Strict logical separation of environments (Staging vs Production) and multi-factor authentication (MFA) requirements for all core infrastructure operators.

Secure API Key Management

Generate, rotate, and immediately revoke API keys from your dashboard settings. We hash keys at rest, meaning they are never stored in cleartext.

Continuous Audits & Scanning

We perform automated daily vulnerability scans, dependency audits, and continuous static analysis (SAST) on our codebase to prevent supply chain exploits.

Responsible Disclosure

We run a private bug bounty program and welcome reports from security researchers. Disclose vulnerabilities responsibly to security@skala.varityweb.com.

Compliance & Regulatory Readiness

Skala is designed for GDPR and CCPA compliance, with data minimization, hash-only storage, and 90-day retention policies. We follow SOC 2 Type II architectural principles for cloud infrastructure.

GDPR & CCPA Ready