Last updated: September 23, 2026
This Security Addendum describes the technical and organizational measures that SkaleData, Inc. (“SkaleData”) implements and maintains for the SkaleData Control Plane. It is incorporated by reference into the Master Subscription Agreement(Section 4.3) and the Data Processing Addendum (Section 5.3), and it is the Security Addendum contemplated by Annex II of the Data Processing Addendum. Capitalized terms not defined here have the meanings given in those documents.
SkaleData may update this Security Addendum from time to time, provided that updates do not materially or substantially degrade SkaleData's security commitments. SkaleData will provide Customer with at least thirty (30) days' prior notice of any material change.
The Services follow a Bring Your Own Cloud architecture: Customer Data resides within the Data Plane under Customer's identity, networking, and encryption controls and is not stored within SkaleData's Control Plane infrastructure. Limited Customer content (such as DAG archives uploaded through the SkaleData command-line interface or API, terminal sessions, and application logs) transits the Control Plane only when Customer invokes the corresponding feature and is not stored beyond what is necessary to complete it, other than operational request metadata, such as request URLs and file names, retained in SkaleData's service logs for up to thirty (30) days. The Control Plane accesses the Data Plane exclusively through Customer-authorized delegated-access mechanisms (such as service account impersonation, IAM role assumption, or managed identity assignment), which Customer may revoke at any time. Customer retains control of cloud-provider identity and access management, networking, encryption keys, backups, and disaster recovery within the Data Plane.
Role-based access control with least-privilege principles for SkaleData personnel. Multi-factor authentication required for SkaleData personnel accessing production systems. Authentication and identity management for end users provided through a SOC 2-attested authentication Subprocessor. Periodic access reviews of SkaleData personnel.
Encryption of Customer Personal Data in transit using TLS 1.2 or higher. Encryption of Customer Personal Data at rest using AES-256 or equivalent. Network segmentation between production and non-production environments. Hosting in tier-1 cloud infrastructure providers with established security certifications (SOC 2, ISO 27001, or equivalent).
Code review process for changes to production systems. Dependency scanning and vulnerability management for third-party libraries. Source code repositories protected by access controls and branch-protection mechanisms. Secrets and credentials managed through dedicated secrets-management infrastructure.
Centralized, append-only audit logging of administrative actions on the Control Plane's cloud infrastructure, with those audit logs retained for a minimum of twelve (12) months. Monitoring and alerting on Control Plane availability and capacity.
Confidentiality obligations imposed on all personnel with access to Customer Personal Data. Security awareness training for personnel. Background screening for personnel with access to production systems, where permitted by applicable law.
Documented incident response procedures. Notification of Personal Data Breaches affecting Customer Personal Data without undue delay, as described in Section 8 of the Data Processing Addendum.
Regular backups of Control Plane data with retention sufficient to support recovery. Disaster recovery procedures designed to restore service in the event of infrastructure failure.
Due-diligence review of Subprocessors prior to engagement. Contractual requirements imposing security and confidentiality obligations on Subprocessors. Periodic review of Subprocessor security posture. The current list of Subprocessors is published at https://skaledata.com/legal/subprocessors.
To report a suspected vulnerability or security incident affecting the Services, contact SkaleData at legal@skaledata.com.