skillflo
Why Studio Products Results Security
See it on your workflow See it →

Security

Security at Skillflo

Skillflo, Inc. · Updated 13 July 2026

Your candidates, guests, pricing, and deals are your edge. This page explains how we keep them private and under your control — concretely, without overclaiming.

1. Isolated by client

Each customer's environment is kept isolated. Your data is not mixed with another customer's, and nothing you put into Skillflo is visible to anyone outside your organization and the Skillflo staff who support you.

2. You control access

  • Role-based permissions decide who on your team can see and do what.
  • Multi-factor authentication is available and can be enforced for your organization; single sign-on is supported.
  • Audit logging records who saw or changed what, so access is reviewable.

3. Encryption

Data is encrypted in transit and at rest. Stored integration credentials receive an additional layer of application-level encryption, and access tokens for sign-in flows are hashed.

4. AI data controls

  • Models on your terms. Work can run on private or open models when the work requires it. Sensitive data does not have to go to outside AI providers.
  • No training on your data. We do not use customer or end-user data to train our general models. Third-party AI providers, where used, are subprocessors under contract, with no-training and zero- or limited-retention terms applied where available.
  • Data minimization. Where the work allows it, personal identifiers are redacted before content reaches scoring models — for example, resumes in Hire are stripped of name and contact details before AI screening.
  • Humans stay in charge. AI prepares the work; your team reviews the important decisions.

5. Retention and deletion

Retention follows your configuration and agreement. Product defaults are short — interview recordings on Hire default to 90 days, and interview-integrity signals delete automatically after 90 days. Verified deletion requests remove profiles, recordings, transcripts, and derived assessments. Details are in the Privacy Policy.

6. Subprocessors

Vetted providers run parts of the service — cloud hosting and storage, AI models, speech-to-text, email delivery, and in-product monitoring. Each is bound to confidentiality and security obligations. We share the named register with customers under the DPA: privacy@skillflo.ai.

7. Our security program

We run an internal security management program modeled on ISO 27001 and ISO 42001 practices — documented policies, risk registers, joiner-mover-leaver controls, and incident-response and continuity procedures — and we audit our public claims against our actual code and infrastructure. We do not yet hold formal certifications and will not claim them until we do.

8. Incidents and responsible disclosure

If a security incident affects your data, we notify affected customers without undue delay. If you believe you have found a vulnerability, email hello@skillflo.ai — we read every report and respond to genuine findings. We do not currently run a public bug-bounty program.

9. What we ask of you

Security is shared. You manage your users and their roles, enforce MFA where your policy requires it, obtain the consents your law requires from candidates and meeting participants, and decide what data enters the services. The Terms of Service set this out.

10. Contact

Security questions and vulnerability reports: hello@skillflo.ai
Privacy and data requests: privacy@skillflo.ai
Skillflo, Inc.

Product-level security detail lives with each product — for example the SkillfloHire security page and its whitepaper. See also the Privacy Policy and Terms of Service.

skillflo

Applied AI for the businesses
powered by people.

Products

Hire Learn Echo

Studio

Forward-deployed builds Where we work

Company

Why Skillflo Who we are Security Results Contact
© 2026 Skillflo products · studio Privacy · Terms