Security & Data Protection
Last Updated: [17-08-2026]
At SKOPEHOLD, we understand that customers trust us with information about their websites, audit results, account information, and other data required to provide our services.
We take reasonable technical and organizational measures to protect this information and continuously improve the security of our platform.
This page explains our current approach to security and data protection.
1. Scope
This Security & Data Protection Policy applies to the SKOPEHOLD website, application, APIs, audit infrastructure, and related services.
It covers information processed as part of:
- user accounts;
- website audits;
- audit reports;
- website crawling and rendering;
- AI-assisted analysis;
- subscription management;
- customer support; and
- operation of the SKOPEHOLD platform.
2. Data We Process
Depending on how you use the Service, we may process:
- account information;
- name and email address;
- subscription and billing metadata;
- submitted website URLs;
- publicly accessible website content;
- HTML and page metadata;
- HTTP response information;
- technical website information;
- TLS/certificate information;
- audit results;
- scores and recommendations;
- generated reports;
- screenshots or rendered pages where applicable;
- usage and diagnostic information; and
- information submitted when contacting support.
We do not require customers to provide passwords, API keys, payment-card numbers, or other credentials as part of a normal website audit.
Customers should not intentionally submit such information through the Service.
3. Data in Transit
Connections to SKOPEHOLD are protected using HTTPS/TLS encryption.
This is intended to protect information while it travels between your browser, our application, and relevant infrastructure.
Where appropriate, communications between internal services are also protected using encrypted connections.
4. Data at Rest
We use appropriate security controls for information stored by the Service.
Where supported by our infrastructure providers, databases, object storage, backups, and other persistent storage are protected using encryption at rest.
Specific encryption technologies may vary depending on the infrastructure component and service provider.
5. Authentication and Account Security
We implement reasonable controls to protect user accounts and authentication systems.
Depending on the authentication method used by the Service, these controls may include:
- secure password handling;
- authentication tokens;
- session expiration;
- account verification;
- access controls;
- rate limiting; and
- monitoring of suspicious activity.
Customers are responsible for protecting their account credentials and should not share credentials with unauthorized individuals.
6. Access Controls
Access to production infrastructure and customer information is restricted based on operational requirements.
We aim to follow the principle of least privilege, meaning access is granted only when reasonably necessary to perform an authorized function.
Where appropriate, access to sensitive systems is logged and monitored.
7. Website Audit Infrastructure
Website auditing is performed through controlled application infrastructure.
Depending on the audit, our systems may:
- make HTTP/HTTPS requests;
- retrieve publicly accessible resources;
- render pages;
- follow links;
- inspect page structure;
- evaluate technical configuration;
- retrieve TLS/certificate information; and
- perform other automated checks.
We implement reasonable controls intended to prevent our infrastructure from being used for abusive or disruptive activity.
Customers must only submit websites they are authorized to audit.
8. Protection Against Abuse
We may implement technical controls such as:
- rate limits;
- request limits;
- concurrency limits;
- authentication requirements;
- usage quotas;
- URL validation;
- request filtering;
- abuse monitoring; and
- automated blocking.
These controls help protect both SKOPEHOLD and third-party websites from excessive or malicious traffic.
9. Artificial Intelligence
Some features of SKOPEHOLD may use artificial intelligence to generate:
- summaries;
- explanations;
- recommendations;
- classifications;
- insights; and
- other report content.
Where third-party AI providers are used, information may be transmitted to those providers as necessary to provide the relevant functionality.
We aim to limit information shared with AI providers to what is reasonably necessary for the feature being used.
We do not intentionally send passwords, payment-card information, authentication credentials, or API keys to AI providers as part of normal audit processing.
Customers should nevertheless avoid including confidential or sensitive information in publicly accessible website content being audited.
10. Third-Party Service Providers
We may use trusted third-party providers for:
- cloud infrastructure;
- databases;
- website crawling;
- browser rendering;
- AI processing;
- payment processing;
- email delivery;
- authentication;
- analytics;
- error monitoring;
- customer support; and
- security monitoring.
These providers may process information on our behalf where necessary to provide the Service.
Where appropriate, we seek contractual and technical safeguards designed to protect customer information.
11. Payment Security
Payment transactions may be processed by third-party payment providers.
We generally do not store complete payment-card numbers on [SaaS Name] infrastructure.
Payment information is handled by the applicable payment provider according to its own security practices, terms, and privacy policy.
12. Data Retention
We retain information only for as long as reasonably necessary for the purposes described in our Privacy Policy, unless a longer retention period is required by law.
Audit results and generated reports may be retained to provide audit history and allow users to access previous reports.
Our intended retention period for completed audit data is:
[90 days]
Account, billing, and transaction records may be retained for longer where required for legal, tax, accounting, fraud-prevention, or dispute-resolution purposes.
13. Data Deletion
Users may request deletion of eligible account and audit information by contacting:
Where technically and legally feasible, we will delete or anonymize eligible information.
Certain information may be retained where necessary for:
- legal compliance;
- financial records;
- fraud prevention;
- security;
- dispute resolution;
- enforcement of agreements; or
- legitimate operational purposes.
14. Backups
We may maintain backups to support business continuity and disaster recovery.
Deleted information may therefore remain temporarily within backup systems until those backups are rotated or securely deleted according to our retention procedures.
15. Monitoring and Logging
We may maintain application, infrastructure, security, and audit logs for purposes including:
- troubleshooting;
- security monitoring;
- fraud detection;
- abuse prevention;
- performance monitoring;
- incident investigation; and
- service improvement.
Access to logs is restricted based on operational requirements.
16. Security Testing and Vulnerability Management
We aim to identify and address security vulnerabilities through reasonable development and operational practices.
Depending on the maturity and scale of the platform, these may include:
- dependency updates;
- vulnerability scanning;
- code review;
- infrastructure monitoring;
- security configuration reviews;
- logging;
- incident investigation; and
- remediation of identified vulnerabilities.
Security practices may evolve as the Service grows.
17. Security Incidents
If we become aware of a security incident affecting customer information, we will take reasonable steps to:
- investigate the incident;
- contain the issue;
- assess potential impact;
- remediate the underlying issue;
- preserve relevant evidence where appropriate; and
- notify affected parties or authorities where required by applicable law.
18. Responsible Disclosure
If you believe you have identified a security vulnerability in SKOPEHOLD, please report it responsibly.
Security Email: security@example.com
Please include:
- a description of the vulnerability;
- the affected feature or endpoint;
- steps required to reproduce the issue;
- potential impact; and
- any relevant technical information.
Please do not:
- access or modify another user's data;
- intentionally disrupt the Service;
- perform denial-of-service testing;
- exfiltrate data;
- conduct destructive testing; or
- publicly disclose the vulnerability before we have had a reasonable opportunity to investigate.
We will review legitimate security reports and make reasonable efforts to respond.
19. Employee and Contractor Access
Where personnel require access to customer or production information, access is intended to be limited to what is reasonably necessary for their role.
Where applicable, personnel and contractors are expected to maintain confidentiality and follow relevant security procedures.
20. Physical and Infrastructure Security
Our infrastructure may be hosted using third-party cloud and infrastructure providers.
Physical security of underlying data centers is generally managed by those infrastructure providers.
We rely on the security controls and certifications of those providers where applicable.
21. International Data Processing
Because SKOPEHOLD serves customers globally, information may be processed or stored in countries other than the country in which you reside.
Where required by applicable law, appropriate safeguards will be used for international transfers.
22. Security Limitations
While we take reasonable measures to protect the Service, no internet-connected system can be guaranteed to be completely secure.
We therefore cannot guarantee that:
- unauthorized access will never occur;
- the Service will always be available;
- all vulnerabilities will be detected;
- all attacks will be prevented; or
- information will never be compromised.
23. Customer Responsibilities
Customers are responsible for:
- maintaining secure account credentials;
- restricting access to their accounts;
- only submitting authorized websites;
- not submitting passwords or secrets;
- following our Acceptable Use Policy;
- keeping their own systems secure; and
- promptly notifying us of suspected unauthorized account activity.
24. Security Updates
As SKOPEHOLD evolves, our security practices may change.
This page may be updated periodically to reflect material changes in our security architecture, infrastructure, providers, or processes.
The "Last Updated" date will be updated when material changes are made.
25. Contact
For security-related questions:
Security: support@skopehold.com
For privacy-related requests:
Privacy: privacy@skopehold.com
For general support:
Support: support@skopehold.com
