Privacy Policy
Last updated: July 1, 2026
This Privacy Policy explains how Skadi, Inc. ("Skadi," "we," "us") collects, uses, and shares information when you use our website, audit platform, and related services (the "Services"). This page is maintained by Skadi to answer common privacy questions about our platform; it is not an independent legal opinion.
1. Information we collect
- Account data: name, work email, company, role, and authentication metadata.
- Audit evidence: control configurations, policies, screenshots, logs, tickets, and other artifacts you upload or connect via integrations (e.g., Drata, Vanta, GitHub, cloud providers).
- Usage data: pages viewed, features used, IP address, device and browser metadata, and diagnostic logs.
- Communications: messages sent to our team or through the in-app pre-evaluation chat.
2. How we use information
- Provide, operate, and secure the Services and perform the SOC 2 examination you engage us for.
- Generate audit workpapers, evidence indexes, and management letters for the licensed CPA of record.
- Improve product quality, reliability, and detection of control gaps.
- Communicate with you about your engagement, billing, and legal notices.
3. AI processing
AI models organize evidence, summarize findings, and flag potential control gaps. AI does not issue audit opinions. Every judgment and report is reviewed and signed by a licensed CPA. Customer evidence is not used to train third-party foundation models.
4. Sharing
We share information only:
- With subprocessors that host, secure, or transmit data on our behalf under written agreements.
- With the licensed CPA firm and engagement team responsible for your examination.
- When required by law, subpoena, or to protect rights, safety, or the integrity of the Services.
- In connection with a merger, acquisition, or asset sale, with notice to affected customers.
5. Data retention
Audit evidence and workpapers are retained for the period required by AICPA professional standards (generally seven years after report issuance). Account data is retained while your account is active and for a reasonable period thereafter to satisfy legal, tax, and accounting obligations.
6. Security
We maintain administrative, technical, and physical safeguards designed to protect customer data, including encryption in transit and at rest, least-privilege access, audit logging, and continuous monitoring. See our Security page for details.
7. Your choices and rights
Depending on your jurisdiction, you may have rights to access, correct, delete, port, or restrict processing of your personal information. Submit requests to security@skadi.ai. We honor verified requests within the timeframes required by applicable law (e.g., GDPR, CCPA/CPRA).
8. International transfers
Data may be processed in the United States and other jurisdictions where our subprocessors operate. Where required, we rely on Standard Contractual Clauses or equivalent transfer mechanisms.
9. Children
The Services are not directed to children under 16 and we do not knowingly collect their personal information.
10. Changes
We will post material changes to this policy on this page and update the "Last updated" date above.
11. Contact
Skadi, Inc. — security@skadi.ai
