The documents that exist, what each one covers, and exactly how to get it.
Through our trust centre. No call needed.
| Document | What it covers | How to get it |
|---|---|---|
| SOC 2 Type II report | Independent audit of our controls across the Trust Service Criteria | Request through the trust centre. Shared under NDA. |
| ISO 27001 certificate | Our certified information security management system | Request through the trust centre. |
| Service Level Agreement | Uptime commitments, service credits and support response times per plan | Public: skycloak.io/sla |
| Data Processing Agreement and SCCs | GDPR processing terms, with Standard Contractual Clauses for international transfers | On request: contact us. |
| Sub-processor list | The providers that host and deliver the service, by region | On request: contact us. |
| Security overview and FAQ | Encryption, access control, hosting regions and incident response | Public: skycloak.io/security |
Go to trust.skycloak.io and request access to the documents you need.
The SOC 2 Type II report is shared under NDA.
Request the DPA, the SCCs or the sub-processor list through the contact page, and we send them directly.
This page is the short list for procurement. The full description of how we secure the service, including hosting regions, encryption and responsible disclosure, is on the security page.
Through our trust centre. No call needed.