Security & trust
Operational trust is part of the product.
SKALV is designed so evidence provenance, organisation boundaries, authorisation and auditability remain part of the operating model. Security claims should be specific, current and verifiable.
Architecture and tenant isolation
Every operational record belongs to an organisation. Isolation is enforced in the database with row-level security rather than in application code alone, so a query that omits an organisation filter returns nothing instead of returning another organisation's data.
Authentication and authorisation
Access is role-based: superadmin, organisation administrator, analyst, operator and viewer. Roles are stored separately from user profiles and evaluated server-side, so a client cannot elevate itself by changing what it sends.
Connector security
Connector secrets never reach the browser. Inbound deliveries are signature-verified; outbound calls are HTTPS-only and validated against internal address ranges before each request. Failed deliveries are retained as dead letters with a safe reason.
Auditability
Operational and administrative actions are written to an append-only audit trail with actor, organisation, action and time. Audit entries are not editable from the application, and retention is configurable per organisation between 30 and 3650 days.
Data handling
SKALV is built to hold operational information, not personal case data. Customers control which sources are connected and what is sent. Evidence keeps its origin so it can be located, reviewed and removed on request.
Availability and recovery
The platform runs on managed European infrastructure with automated backups. We publish an availability page when we can back it with real measurement history — an uptime figure without evidence behind it is not a security control.
Responsible disclosure and certifications
Report a suspected vulnerability through the contact page and we will confirm receipt. SKALV holds no security certifications today. We will list them here when they are actually obtained, with issuer and date, and not before.
See SKALV with your own operational scenario.
Bring a real scenario — the sources you follow, the functions you cannot lose — and we will show where SKALV fits and where it does not.