πŸ“‹ Compliance & Certifications

Our commitment to security standards and regulatory compliance

← Back to Home

πŸ“Š Current Compliance Status

Transparency First: We believe in honest disclosure about our compliance status. Below is our current state and roadmap for certifications and regulatory compliance.
πŸ‡ͺπŸ‡Ί
GDPR Compliance
Active

Full compliance with EU General Data Protection Regulation. Users have the right to access, correct, delete, and export their data.

πŸ‡ΊπŸ‡Έ
CCPA Compliance
Active

California Consumer Privacy Act compliant. California residents have enhanced privacy rights and control over their data.

πŸ”’
AES-256 Encryption
Active

Industry-standard encryption for all files at rest. Data in transit protected with TLS 1.3.

🏒
SOC 2 Type II
In Progress

Third-party audit of our security, availability, and confidentiality controls. Target completion: Q3 2026.

🌐
ISO 27001
Planned

International standard for information security management systems. Target completion: Q4 2026.

πŸ’³
PCI DSS
Via Stripe

Payment processing handled by Stripe (PCI Level 1 certified). We never store or handle credit card data directly.

πŸ—“οΈ Compliance Roadmap

January 2026 (Completed)
βœ… GDPR and CCPA compliance implemented
βœ… AES-256 encryption deployed
βœ… Automated malware scanning (VirusTotal)
βœ… Data retention and deletion policies established
Q2 2026 (April - June)
πŸ”œ Begin SOC 2 Type II audit preparation
πŸ”œ Security infrastructure hardening
πŸ”œ Enhanced logging and monitoring
πŸ”œ Formal incident response procedures
Q3 2026 (July - September)
πŸ”œ Complete SOC 2 Type II certification
πŸ”œ Third-party penetration testing
πŸ”œ Begin ISO 27001 preparation
Q4 2026 (October - December)
πŸ”œ ISO 27001 certification completion
πŸ”œ Annual security audit
πŸ”œ HIPAA compliance assessment (for healthcare customers)

πŸ›‘οΈ Security Standards We Follow

Data Protection

Privacy Standards

Operational Security

🌍 Jurisdiction & Data Residency

Company Information:
Legal Entity: SkillBreed LLC
Incorporation: Oakland Park, Florida, United States
Data Location: United States (DigitalOcean data centers)
Governing Law: Florida state law and U.S. federal law

All data stored in Vault is hosted on DigitalOcean infrastructure located in the United States. Data is subject to U.S. jurisdiction and legal processes.

International Data Transfers

For users outside the United States, data is transferred to and processed in the U.S. We implement appropriate safeguards:

πŸ“œ Third-Party Audits & Certifications

Current Status: SkillBreed Vault has not yet completed a third-party security audit. We are working toward SOC 2 Type II certification (target Q3 2026).

Why This Matters

Third-party audits provide independent verification of our security practices. While we follow industry best practices, we acknowledge that independent certification is important for enterprise trust.

Our Infrastructure Partners

We rely on certified infrastructure providers:

πŸ“ž Compliance & Legal Inquiries

Contact Information:
Legal Inquiries: legal@skillbreed.com
Security Issues: security@skillbreed.com
Privacy Requests: privacy@skillbreed.com
Response Time: Within 72 hours

Last Updated: January 29, 2026