Security and compliance

Built for Organisations That Cannot Get This Wrong

Full detail on how SkillDrill protects your data, meets your GDPR obligations, and keeps AI use accountable to a person, not an algorithm.

Data Security

Data protection

We know security jargon can be confusing. Here is what we do to protect your data, explained simply, with the technical detail underneath for the people who want it.

Enterprise infrastructure

Built on the same cloud infrastructure trusted by banks, governments, and the NHS.

Tenant isolation

Every organisation's data is completely separated with unique encryption keys, on its own subdomain or custom domain

SSO & MFA

Microsoft Entra ID single sign-on, TOTP and email two-factor authentication

Strong access controls

Role-based access with per-route permission mapping, CSRF protection on all forms, and rate limiting on login and API endpoints

Server-side sessions

Sessions are held server-side in our encrypted database rather than in browser storage or flat session files on disk

AES-256-GCM encryption, with a separate, unique key for every organisation. One organisation's data cannot be exposed by another's.

Technical detail

Per-tenant keys are derived from a master key using HKDF. Each organisation has its own unique encryption key, meaning one organisation's data cannot be decrypted with another's key. Every organisation's records are also isolated by tenant-scoped database queries on every operation, so your people, skills, conversations and settings cannot be seen by any other organisation on the platform.

Encrypted in transit and at rest.

Technical detail

TLS 1.2+ on every connection, with HSTS enforced. Every name, email, skill, conversation and note is encrypted before it is stored, so even someone with direct access to our database would see scrambled data, not your information. AI conversations are encrypted with AES-256-GCM before storage and held server-side, so conversation history cannot be tampered with from the browser.

UK data residency. Your data stays in the UK.

Technical detail

Hosted on AWS eu-west-2 (London) with dedicated RDS database infrastructure. All backups remain within the same region. Enterprise-grade DDoS protection via AWS Shield and Cloudflare WAF at the edge. AWS infrastructure is ISO 27001 certified and SOC 2 audited.

Full audit trail of who accessed what, and when.

Technical detail

Every action is logged with a timestamp, the actor, and the target record, and the log is exportable for compliance reporting. The audit log is insert-only, enforced at the model layer, and IP addresses are anonymised after 90 days.

Compliance

GDPR and your obligations

SkillDrill processes personal data about your people. That makes you the controller and us the processor. Here is what that means in practice.

SkillDrill is built around ordinary personal data, not special category data. Skills, qualifications and experience do not carry the extra legal burden that health or biometric data does, which keeps your GDPR compliance simpler than it would be for many other workforce tools.

In practice

A Data Processing Agreement is available covering our role as your processor.

Request it via the contact page and we will send the standard wording for your procurement or legal team to review. Sub-processors are listed in the DPA, and we notify of changes 30 days in advance.

ICO registered.

Information Commissioner's Office data protection registration ZA046393. Consent is recorded per category with a timestamped history, so you can prove what was true on a given date.

Data retention and deletion controls sit in your hands. Delete a person's record, or your whole organisation's data, on request.

Per-tenant retention windows are configurable and the defaults are conservative. Scheduled jobs age old data off automatically, so deletion is an operation you perform inside the product, not an engineering ticket you raise with us.

When a data subject asks, you have an answer ready

The rights you owe your data subjects are operations you can perform inside the product.

Article 15

Right of access

Generate a complete subject access export in JSON or as a per-table CSV ZIP, covering staff records, profile responses, skills, audit log entries, AI usage events, and previous privacy requests.

Identity gate: exports require a verified privacy request. Verification is by email confirmation or recorded ID check, not just an admin clicking a button.

Article 16

Rectification

Corrections are recorded in a separate, append-only rectification log. The original value, the corrected value, who requested it, and who actioned it are all captured.

Why append-only: so a subject can prove their record was wrong, not just that it is right now.

Article 17

Right to erasure

Erasure cascades. Every linked record across profiles, AI conversation transcripts, notes, tags, and skills is removed or pseudonymised in a single operation, with a full audit trail of what happened.

What survives: only the audit log, with the subject's name replaced by "[erased]". You can prove the right was honoured without keeping the data.

Human in the Loop

Responsible AI, by design

AI inside SkillDrill has one job: to listen well and record accurately. Everything else stays with people.

SkillDrill never scores, ranks, or grades people. It records what someone told you about their own skills. Nothing more.

There is no hidden score, no ranking, and no league table. What you see in Skill Explorer is what people said about themselves.

No automated decisions are made about any individual. A human always makes the call.

Nothing in SkillDrill triggers an outcome for an individual on its own. Reports inform people; they do not replace them.

If a conversation raises a welfare or professional concern, it is routed straight to a named person in your organisation. AI does not act on it.

Concern Flagging is built for exactly this: flags are encrypted at rest, notification emails contain no personal details, and every access to welfare data is audit logged.

We do not train AI models on your data.

This applies in every provider configuration, including the default. Your conversations are your organisation's data, and they stay that way.

No Lock-in

Your AI, your choice

Connect Anthropic, OpenAI, Azure OpenAI, or self-host with Ollama for a fully air-gapped deployment. Organisations already running their own Azure tenancy can keep all AI processing inside infrastructure they already control and already trust, removing a common sub-processor concern entirely during procurement.

See how this works on the Product page

Anthropic

Managed API connection to Claude models, with your conversations encrypted before storage in your tenant.

OpenAI

Managed API connection to GPT models, under the same encryption and storage rules as every other provider.

Azure OpenAI

AI processing runs inside your own Azure tenancy, on infrastructure you already control and already trust.

Ollama

Self-hosted models for a fully air-gapped deployment. Nothing leaves your infrastructure at all.

Transparency

Working towards

We are transparent about where we are, not just where we've been.

Cyber Essentials Plus: in progress.

SOC 2: gap analysis underway ahead of US market entry.

Already in place

ICO Registered

Information Commissioner's Office data protection registration ZA046393

Cyber Essentials

UK government-backed scheme certifying our cyber security controls

GDPR Compliant

Full compliance with UK GDPR, EU GDPR, and the Data Protection Act 2018

UK Data Residency

All tenant data stored in UK data centres, with backups kept in the same region

Procurement

If you have a procurement questionnaire in front of you

Here is the short version. Hand this section to whoever is asking.

Where is data stored?
In the UK. AWS eu-west-2 (London), with backups kept in the same region.
Encryption at rest?
AES-256-GCM with per-tenant keys derived via HKDF-SHA256. Even our database administrators cannot read your data.
Encryption in transit?
TLS 1.2+ for every connection, including to third-party AI providers. HSTS enforced.
AI training on our data?
No. Never. Providers are configured not to retain or train on tenant data, and you can connect your own AI provider for full control.
Automated decisions about individuals?
None. SkillDrill records and organises information. A person in your organisation makes every decision about a person.
Sub-processors?
Listed in the DPA, with 30 days' notice of changes. Running AI inside your own Azure tenancy, or a self-hosted Ollama deployment, removes the AI sub-processor question entirely.
Subject access response time?
Self-service from inside the product, normally within minutes once identity is verified. Statutory limit is 30 days.
Data Processing Agreement?
Available on request. Ask via the contact page and we will send it over, with bespoke wording available for enterprise customers.

Frequently asked questions

No. Never.

Yes, using your own Azure tenancy, or a self-hosted Ollama deployment for a fully air-gapped setup.

No. SkillDrill records and organises information. Every decision about a person is made by a person in your organisation, not by SkillDrill.

In the UK.

Questions about security?

We are happy to discuss our security practices in detail. Get in touch for a technical deep-dive, or to put our paperwork in front of your DPO.