Trust & Security overview
File: 16_Trust_and_Security.docx
SKRIB, INC.
Trust & Security
Last Updated: 5 June 2026
Skrib is built around the privacy and security of the people and organisations who use it. This page summarises Skrib’s security posture, our compliance certifications and roadmap, the artefacts available to customers performing due diligence, and how to report a security concern. The full operational detail lives in the Privacy Policy, the Data Processing Addendum, and the Subprocessor List.
Compliance and certifications
SOC 2 Type II — Status: In progress — target Q4 2026; Notes: Independent audit covering security, availability, and confidentiality. Customers may request the most recent report under NDA via the Compliance Reports Portal once available..
ISO/IEC 27001 — Status: Roadmap — target 2027; Notes: Information-security management system certification..
ISO/IEC 27701 — Status: Roadmap — target 2027; Notes: Privacy-information management system extension to ISO 27001..
GDPR / UK GDPR — Status: Compliant; Notes: Privacy Policy, DPA, and Subprocessor List published. EU and UK Article 27 representatives appointed..
Georgian DPP Law (No. 3144/2023) — Status: Compliant; Notes: Skrib’s primary regulatory framework; Skrib operates from Tbilisi and is supervised by the Personal Data Protection Service of Georgia..
EU Digital Services Act — Status: Compliant; Notes: Notice-and-action mechanism, statement-of-reasons workflow, internal complaint handling, DSA single point of contact in place..
EU AI Act — Status: Tracking; Notes: Skrib monitors phased application; Article 50 transparency obligations are addressed in the AI Terms..
EU-U.S. Data Privacy Framework — Status: Application planned; Notes: Skrib intends to certify under the EU-U.S. DPF, the UK Extension, and the Swiss-U.S. DPF. Certification will be reflected in the Privacy Policy and on this page once complete..
DMCA Designated Agent — Status: Registered; Notes: Filed with the United States Copyright Office under 17 U.S.C. § 512(c)(2). Contact details published in the DMCA Policy..
Security controls
Skrib implements and maintains technical and organisational measures designed to ensure a level of security appropriate to the risk, as required by Article 32 of the GDPR and analogous Data Protection Laws. The full description appears in Annex II of the Data Processing Addendum and (for enterprise customers) in Exhibit B to the Software Services Agreement. The summary below is published for prospective customers and security teams.
Encryption — Controls: TLS 1.2+ in transit. AES-256 (or equivalent) at rest for primary storage and backups. Cryptographic keys managed in dedicated key-management services..
Authentication — Controls: Customer-managed authentication via Skrib’s authentication provider. SSO/OIDC and SAML for enterprise plans. MFA required for administrative access..
Access controls — Controls: Role-based access control with least-privilege defaults. Production access via documented just-in-time workflow with audit logging..
Network and infrastructure — Controls: Cloud-hosted in tier-3 or higher data centres certified to ISO/IEC 27001 (or equivalent). Network segmentation, web-application firewalls, DDoS mitigation, continuous vulnerability scanning..
Logging and monitoring — Controls: Centralised audit logging of administrative actions, access to Customer data, and security-relevant events. ≥1-year retention. 24/7 alerting..
Backups and resilience — Controls: Daily encrypted backups retained ≥30 days. Multi-AZ deployment in primary hosting region (AWS eu-central-1, Frankfurt). Documented DR plan tested annually..
Incident response — Controls: Documented incident-response plan; defined roles, severity levels, escalation. 24/7 on-call. Personal Data Breach notification to Customers within 72 hours of confirmation..
Vendor governance — Controls: Documented vendor risk management. Security and privacy assessments before engagement. Public Subprocessor List with subscription form for change notifications..
Personnel — Controls: Background checks for personnel with production access (where permitted). Mandatory security and privacy training on hire and at least annually..
Independent assessment — Controls: Annual penetration testing by qualified independent third party. Continuous vulnerability scanning. Vulnerability disclosure programme at https://skrib.com/security/vdp..
Where Customer data is processed
Skrib’s primary platform data is hosted in the European Union on AWS infrastructure (Frankfurt, Germany — eu-central-1). Some sub-processors process limited categories of personal data outside the EEA, the United Kingdom, and Switzerland (including in the United States). For each cross-border processing arrangement, Skrib relies on a lawful transfer mechanism (an adequacy decision, the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or — once certified — the EU-U.S. Data Privacy Framework). The current Subprocessor List, with the location and transfer mechanism for each sub-processor, is at https://skrib.com/legal/subprocessors.
AI providers and content protection
Skrib uses OpenAI, Anthropic, and Google (Gemini) under enterprise or comparable API arrangements that contractually prohibit those providers from using user content submitted through Skrib to train the providers’ own foundation models. Skrib does not use user prompts, uploaded files, document content, or AI outputs to train Skrib’s own models. The detailed AI Terms are at https://skrib.com/legal/ai-terms; the public Responsible AI Statement is at https://skrib.com/responsible-ai.
Documents available for due diligence
Privacy Policy — https://skrib.com/legal/privacy
Cookie Policy — https://skrib.com/legal/cookies
Data Processing Addendum — https://skrib.com/legal/dpa
Subprocessor List — https://skrib.com/legal/subprocessors
AI Terms — https://skrib.com/legal/ai-terms
Acceptable Use Policy — https://skrib.com/legal/aup
Trust & Safety / Notice and Action — https://skrib.com/legal/notice-and-action
DMCA / IP Complaints Policy — https://skrib.com/legal/dmca
Vulnerability Disclosure Policy — https://skrib.com/security/vdp
Annual Transparency Report — https://skrib.com/trust/transparency
Retention schedule summary — https://skrib.com/trust/retention
Compliance Reports Portal (customer-gated) — https://compliance.skrib.com
Enterprise customers performing due diligence may request the most recent SOC 2 Type II executive summary (when available), penetration-test summary, security-questionnaire responses (CAIQ-Lite, SIG-Lite), and a counter-signed DPA via the Compliance Reports Portal at https://compliance.skrib.com or by contacting contact@skrib.com under reasonable confidentiality obligations.
Reporting a security concern
If you believe you have identified a security vulnerability, please report it through Skrib’s Vulnerability Disclosure Policy at https://skrib.com/security/vdp or to contact@skrib.com. The Policy describes the in-scope assets, reporting expectations, and the safe-harbour commitments that apply to good-faith research.
If you believe a security incident affecting your account or your data may be in progress, contact contact@skrib.com immediately and (for paying customers) your designated account contact at Skrib.
Transparency reporting
Skrib publishes an annual transparency report at https://skrib.com/trust/transparency summarising the volume and outcome of government and law-enforcement requests received in the prior calendar year, the operation of Skrib’s notice-and-action mechanism under the EU Digital Services Act, and other transparency information required by applicable law. The first report is due by 31 January 2027.
Contact
Security: contact@skrib.com | Trust: contact@skrib.com | Trust & Safety: contact@skrib.com | Privacy / DPO: contact@skrib.com | General legal: contact@skrib.com | DSA single point of contact: contact@skrib.com.