Security & Trust

Skadi is a licensed CPA audit firm. We hold ourselves to the same standards we examine — with independence, evidence, and professional judgment at the core.

SOC 2 Type II
Compliant · CPA-issued

This page is maintained by Skadi, Inc. to summarize the security practices of our platform and firm. It describes controls currently in place; it is not itself a certification or independent attestation. For the current SOC 2 Type II report and other assurance documentation, contact security@skadi.ai.

Encryption everywhere

TLS 1.2+ in transit and AES-256 at rest for customer data, evidence, and workpapers. Managed KMS keys with automatic rotation.

Identity & access

SSO/SAML and OIDC for customer tenants. Role-based access control, MFA required for all Skadi personnel, and just-in-time elevation for production access.

Segregated environments

Production, staging, and audit workpaper environments are logically segregated with separate credentials, networks, and access approvers.

Continuous monitoring

Centralized audit logging, anomaly detection, endpoint protection, and vulnerability scanning across code, containers, and cloud.

Personnel controls

Background checks, confidentiality agreements, mandatory security and independence training, and annual acknowledgement of the AICPA Code of Professional Conduct.

Vendor & subprocessor management

Risk-tiered vendor reviews, SOC 2 / ISO 27001 evidence on file, and written data-processing terms with all subprocessors.

Incident response

Documented IR plan with defined severities, on-call rotation, tabletop exercises, and customer notification within contractually committed timeframes.

Business continuity

Multi-AZ infrastructure, tested backups, and documented RTO/RPO objectives reviewed at least annually.

CPA firm standards

As a licensed CPA audit firm, Skadi operates under obligations that go beyond typical SaaS security:

  • AICPA Code of Professional Conduct — integrity, objectivity, and due professional care apply to every engagement partner and staff member.
  • Independence (AICPA & SEC/PCAOB where applicable) — we do not accept engagements that impair independence, and we monitor prohibited services, financial interests, and relationships.
  • Peer review — the firm is enrolled in the AICPA Peer Review Program; our most recent peer review report is available on request.
  • Quality management (SQMS No. 1 & 2) — documented system for engagement acceptance, resources, information & communication, and monitoring & remediation.
  • Workpaper retention — audit documentation is retained per AICPA standards (generally seven years after report issuance) in access-controlled, tamper-evident storage.
  • Confidentiality (ET 1.700) — client information is not disclosed without consent or legal obligation.

Responsible disclosure

Report suspected vulnerabilities to security@skadi.ai. We acknowledge reports within one business day and will not pursue legal action for good-faith research that respects our scope.

Request our reports

SOC 2 Type II report, penetration-test summary, subprocessor list, and DPA are available under NDA. Contact security@skadi.ai.