Security you can verify

These are the controls implemented by the product today, together with the boundaries administrators need to understand.

Capture is off by default

Device capture requires an explicit purpose, approved sources, and a user action before it starts.

Server-owned authorization

A device cannot approve itself. Organization administrators control roles and device capabilities.

Signed device events

Device graph events are signed with a per-device Ed25519 identity and checked before ingestion.

Scoped credential vault

Stored integration credentials use tenant- and purpose-bound AES-256-GCM envelopes with versioned keys.

Data handling

  • In transit: production clients use authenticated HTTPS or secure WebSocket transport.
  • At rest: integration secrets use authenticated encryption; graph events intentionally exclude passwords, tokens, raw file contents, and command-line arguments.
  • On device: capture files are permission-restricted, bounded, retention-limited, and only persisted after an explicit opt-in.
  • Access: organization roles, source-specific grants, and an audit trail determine who can read or change data.

Important boundaries

  • SkyKoi does not describe itself as SOC 2, ISO 27001, HIPAA, GDPR, or CCPA certified unless a current report or signed agreement specifically says so.
  • Credential-vault encryption is not zero-knowledge encryption: an authorized SkyKoi service can decrypt a credential when an approved integration needs it.
  • Raw keystroke capture, password-field capture, and undisclosed employee surveillance are not supported product defaults.
  • Customers remain responsible for notice, consent, labor-law review, retention settings, and lawful use in every jurisdiction where they deploy monitoring.

Need a security review?

Ask for the current control description, data flow, and deployment-specific terms.