Skedlark
Security

Security & data handling

Последнее обновление 19 June 2026

An honest account of how Skedlark protects your data and your accounts: where it is hosted, how it is encrypted, the permission model that keeps an agent from acting without you, and what we have and have not certified.

Этот документ ведётся на английском языке.

01Our approach

Skedlark lets an AI agent act on your behalf across your social accounts, so security is not a feature bolted on the side — it is the product. This page is an honest account of what is true today, written before we hold any SOC 2 paperwork. We would rather tell you exactly what we do than display a badge we have not earned.

Two ideas run through everything below: keep the blast radius small (least data, least privilege, EU-only), and keep you in control (the agent proposes, you approve, and every action is logged).

02Hosting and data residency

Skedlark runs on Hetzner, in EU regions (Germany and Finland), orchestrated with Coolify. Your data stays in the EU. We chose EU-only hosting deliberately: it keeps us under one clear regulatory regime and avoids routing your data through jurisdictions you did not sign up for.

03Encryption

  • In transit: all traffic is served over TLS.
  • At rest: sensitive secrets, including the OAuth tokens that authorise posting to your accounts, are encrypted with AES-256-GCM. This is true today, not a roadmap item.
  • Secrets such as encryption keys and provider credentials are held in environment-scoped secret storage, never in source control.

04The agent permission model

This is the part most schedulers skip. An AI agent connected to Skedlark gets read and propose scopes only. It can read your analytics and draft posts; it cannot publish on its own.

  • Every draft lands in an approval queue. Nothing goes live until you approve it.
  • Every action — read, draft, schedule, publish — is written to a full audit trail you can review.
  • Your brand voice and positioning are locked by you. No agent can rewrite them.
  • Direct-publish, where an approved channel can post without a manual click, is off by default and only available on higher tiers when you deliberately turn it on.

The result is that even a misbehaving or compromised agent cannot silently post as you. The full breakdown is on the home page under 'What can the agent actually do?'.

05Authentication and access control

  • Connections to your social accounts use each platform's OAuth, so you grant and revoke access on the platform's terms and we never see your social passwords.
  • Internal access to production follows least privilege — people get the minimum access they need, and no more.
  • Administrative access is protected with two-factor authentication.

06Payment security

Payments are processed by Stripe, a PCI DSS Level 1 provider. We never see or store your full card number — Stripe handles card data directly, and we receive only a token and limited metadata for billing.

07Subprocessors

We use a deliberately short list of subprocessors, each under a data processing agreement. This list is kept in sync with the privacy policy:

  • Hetzner (via Coolify) — EU hosting of the application and database.
  • Stripe — payment processing.
  • Google — Analytics 4, only after you consent.
  • Our LLM provider — used to generate drafts at launch, processing only the content needed for the request.

08Data minimisation and retention

We collect the minimum we need to run the service. You can disconnect a social account at any time, which revokes the token; you can delete your data by asking us. Server logs are rotated on a rolling basis. Retention details are set out in the privacy policy.

09Responsible disclosure

If you find a security issue, tell us and we will work with you in good faith. Report vulnerabilities to hello@skedlark.com, and we publish a machine-readable contact at /.well-known/security.txt. We do not pursue legal action against researchers who act in good faith, avoid privacy violations and service disruption, and give us reasonable time to fix the issue before disclosure.

10Incident response

If a personal data breach occurs that is likely to affect you, we will notify the relevant supervisory authority within 72 hours where the law requires it, and we will tell affected users without undue delay. We would rather over-communicate than leave you guessing.

11Compliance roadmap

Skedlark is GDPR-native today — built around EU hosting, data minimisation, and your rights from day one, not retrofitted. SOC 2 Type I is planned for after launch. We will say so plainly until we have it, and we will never display a certification we do not hold.

Вопросы по этой странице? Пишите на hello@skedlark.com.

← На главную