SECURITY

Security you can actually understand

A straightforward look at how Skydive protects your data and your credentials.

Get Started

What we protect, and how

Access controls you set per agent

Every agent has a visibility setting that determines who can reach it and how data flows in and out. You choose the right level for each agent.

  • Private: only you can see and use the agent.
  • Internal: any validated member of your workspace can use it.
  • External: the agent can be reached by people outside your workspace, for agents you build to face customers or the public.

Isolated, single-tenant sandboxes

Your data runs inside an isolated sandbox. Access is restricted at the network layer to validated requests, so nothing reaches your sandbox that is not supposed to. Each workspace's data lives in its own separately tenanted space.

Encrypted credential storage

Your credentials are held in dedicated secret storage and protected with standard best encryption practices, in rest and in transit.

Audit logs

Track and analyze all team member and agent activity across Skydive.

Penetration testing

Skydive conducts regular penetration testing with third-party experts. We also have automated static analysis checks and dependency scanning across our codebase and agent codebases.

Compliance

Skydive is SOC 2 Type I certified. We also comply with the Google API Services User Data Policy and have passed a Cloud Application Security Assessment (CASA) Assurance Level 1 (AL1) audit.

AICPA SOC for Service Organizations

Questions about security?

Reach us at security@skydive.com.

Get Started