Skip to content
Skyie GlobalInfoTech
A quiet, empty corridor in Barbican Centre, London with brick walls and ceiling lights.
Security

Security is the architecture, not a policy PDF.

How Skyie Global secures its platform and products — UK data residency, envelope encryption, least-privilege access, secure engineering, monitoring and incident response.

We build software for organisations that are held to account for the data they hold. That makes security a design constraint on every product in the portfolio, not a programme that runs alongside them.

The pattern is the same across the estate: one hardened identity layer, one encrypted vault, one audit trail, and residency that is a property of the architecture rather than a setting somebody has to remember to switch on. What follows is what that means in practice — and what we can evidence if you ask.

01

Data residency & sovereignty

Customer data is hosted on UK soil and stays there. Residency is enforced by where the infrastructure is, not by a configuration flag — which is why it also covers the parts people forget.

  • UK-region hosting for application, database and object storage
  • Backups, logs and telemetry held in the same jurisdiction
  • Sub-processors selected and contracted on residency grounds
  • No routine transfer of customer data outside the UK
02

Encryption & key management

Data is encrypted in transit and at rest. Skyie Vault, the shared store every product reads from, uses envelope encryption so access is granted per file rather than copied wholesale.

  • TLS 1.2+ enforced on every public endpoint, HSTS with preload
  • Encryption at rest across databases, object storage and backups
  • Per-file data keys wrapped by a managed key hierarchy
  • Key material held in the UK; rotation documented and rehearsed
03

Identity & access control

One identity layer spans the portfolio. Access is least-privilege, time-bound where it can be, and recorded whether or not anyone is watching.

  • Multi-factor authentication on all administrative access
  • Role-based access control with documented joiner–mover–leaver process
  • Single sign-on available for customer organisations
  • Privileged actions logged to an append-only trail
04

Secure engineering

Security work happens in the pipeline, where it is cheap, rather than in a remediation project after an audit. Every change is reviewed, scanned and traceable to a person.

  • Peer review required on every change; protected main branches
  • Secret scanning in pre-commit hooks and in CI — builds fail on a hit
  • Dependency and container scanning with an SBOM per release
  • Threat modelling on new services; no secrets in client bundles
  • Runtime secrets injected from a managed store, never committed
05

Monitoring, logging & incident response

We would rather find our own problems. Systems are monitored continuously and incidents follow a documented response process with defined roles and communications.

  • Continuous availability and integrity monitoring via Glancio
  • Centralised, tamper-evident logging with retention set to obligation
  • Documented incident response plan with severity classification
  • Breach assessment and ICO notification path within 72 hours where the threshold is met
06

Vulnerability management & testing

Exposure is measured rather than assumed. Findings are triaged against real exploitability and tracked to closure on defined timelines.

  • Automated vulnerability scanning across code, dependencies and infrastructure
  • Independent penetration testing on material releases
  • Cloud configuration review against hardening baselines
  • Remediation SLAs by severity, tracked to evidence of closure
07

Resilience & continuity

Backups are only worth the last successful restore. We test recovery rather than trusting the schedule.

  • Automated, encrypted backups with defined retention
  • Restore testing on a documented cadence
  • Recovery time and recovery point objectives agreed per service
  • Business continuity planning aligned to ISO 22301 practice
08

Supplier & people security

Most breaches arrive through a third party or a person. Both are managed as first-class risks, with the sub-processor list published rather than hidden behind a request form.

  • Sub-processors assessed before use and published openly
  • Contractual data-protection terms with every processor
  • Background screening and confidentiality obligations for staff
  • Security awareness training with phishing simulation

Reporting a vulnerability

If you believe you have found a security issue in any Skyie Global product or on this website, tell us before you tell anyone else. We will acknowledge your report, keep you updated, and will not pursue researchers who act in good faith and give us reasonable time to fix the issue.

Assurance

The controls above are the ones we run ourselves. Our assurance practice runs the same tests on your estate — ISO 27001 gap analysis, ISMS internal audit, supplier audits and penetration testing, led by a certified ISO/IEC 27001 Lead Auditor.

Common questions

Questions we get asked.

Is Skyie Global ISO 27001 certified?

We operate to an ISO 27001-aligned control set and our assurance practice is led by a certified ISO/IEC 27001 Lead Auditor. We describe the company's own posture as aligned, not certified, because certification is issued by an accredited certification body and we will only claim it when a certificate is held and can be evidenced.

Where is our data held?

In the United Kingdom, including backups, logs and telemetry. Our sub-processor list sets out every third party involved, what they do and where they process data.

Can we run our own penetration test?

Yes. Customers on a suitable agreement can test their own tenancy with prior written scope and scheduling, so we can distinguish your test from a live incident.

Do you provide a security questionnaire response or evidence pack?

Yes. We maintain a current control and evidence pack, available under NDA, and Trustiey exists precisely so due diligence is a shared, living record rather than a fire drill.

How quickly do you notify us of a breach?

Our data processing terms commit us to notifying you without undue delay after becoming aware of a personal data breach, with the information you need to meet your own UK GDPR obligations.

Book a walkthrough

Built to be trusted before it is sold.

See how the portfolio carries your compliance obligations — in thirty focused minutes.