Security
COMMITMENT
Security is not a feature we ship, it is a property of everything we build. We design for confidentiality, integrity, and availability from the start. This page describes what we do, what we are working toward, and how to reach us if you find a problem.
DATA ENCRYPTION
All data in transit is encrypted using TLS 1.2 or higher. Data at rest is encrypted using AES-256. Backups are encrypted with the same standard and stored separately from primary data. Encryption keys are managed through a dedicated key management service and rotated on a scheduled basis.
ACCESS CONTROLS
Access to production systems follows the principle of least privilege. Engineers are granted access to only the systems and data required for their specific role. All privileged access is logged and reviewed. Multi-factor authentication is enforced for all internal accounts. Remote access to infrastructure requires authenticated VPN.
Customer data is isolated at the application layer. No customer can access another customer's data. Task data shared with domain experts on our network is scoped to the specific task and subject to confidentiality obligations.
AUDIT LOGGING
All access to customer data and task outputs is logged with timestamps, actor identifiers, and action type. Logs are tamper-evident and retained for a minimum of 12 months. Anomalous access patterns trigger automated alerts reviewed by our team.
INCIDENT RESPONSE
We maintain an incident response plan that covers detection, containment, eradication, recovery, and post-incident review. In the event of a confirmed breach affecting your data, we will notify affected customers within 72 hours of discovery, consistent with applicable data protection requirements. Notification will include the nature of the incident, data affected, and steps taken to remediate.
THIRD-PARTY VENDORS
All third-party service providers with access to customer data are subject to data processing agreements. We assess vendor security posture before onboarding and review it periodically. We do not use vendors that cannot meet our minimum security requirements.
COMPLIANCE
We operate in accordance with applicable Indian data protection law. We are working toward formal compliance certifications as our platform scales. This section will be updated as certifications are achieved.
- SOC 2 Type II, planned
- ISO 27001, planned
- DPDP Act (India), in progress
RESPONSIBLE DISCLOSURE
If you discover a security vulnerability in our platform or infrastructure, we ask that you report it to us before disclosing it publicly. We commit to acknowledging your report within 2 business days, investigating promptly, and keeping you informed of our progress.
To report a vulnerability, contact us at security@scalekit.studio with a description of the issue, steps to reproduce, and potential impact. We do not pursue legal action against researchers who act in good faith and follow this process.
We do not currently operate a formal bug bounty programme, but we recognise impactful disclosures publicly with the researcher's consent.
CONTACT
For security-related questions or concerns:
security@scalekit.studio
Scalekit Studio Technologies Private Limited
Guwahati, Assam, India