SkillOps Security Appendix And Data Processing Addendum
Last updated: July 10, 2026
This Security Appendix and Data Processing Addendum ("Appendix") describes security and data-processing commitments for SkillOps. It supplements the SkillOps Terms of Service or applicable Order Form. SkillOps is provided by Enchiridion Labs LLC, a California limited liability company.
1. Product And Data Scope
SkillOps is a business-to-business service for managing governed AI-agent skill content, approvals, publication state, managed MCP gateway delivery, audit trails, analytics, and billing state.
Customer Data may include:
- user names, work emails, roles, groups, and identity-provider identifiers;
- skill drafts, approved skill versions, Markdown content, supporting files, and package artifacts;
- comments, approvals, rejections, review requirements, owners, and workflow metadata;
- gateway tokens, OAuth metadata, MCP request metadata, run checkpoints, feedback, and usage analytics;
- audit events, billing metadata, subscription state, and invoice references; and
- support messages and operational diagnostics.
Unless expressly agreed in writing, Customer must not submit protected health information, payment-card data, bank-account data, government identifiers, highly sensitive personal data, export-controlled technical data, or regulated financial data to the Service.
2. Hosting And Infrastructure
The current production architecture uses Google Cloud Platform services, including Cloud Run, Cloud SQL for PostgreSQL, Cloud Storage-compatible object storage, Secret Manager, and related logging/monitoring services. Payments are processed by Stripe. Identity and SSO may use customer-configured identity providers and identity infrastructure.
SkillOps may update infrastructure providers or subprocessors as the Service evolves, provided that replacements maintain materially similar security protections.
3. Security Measures
SkillOps will maintain reasonable administrative, technical, and organizational measures designed to protect Customer Data, including the measures below.
Access Controls
- Tenant isolation for customer organizations, users, skills, package artifacts, gateway resources, and analytics.
- Role-based access controls for administrators, org owners, skill owners, reviewers, and members.
- Authentication through configured login providers and session controls.
- Gateway access through tokens or OAuth flows where enabled.
- Production secrets stored outside source control in managed secret storage.
- Access to production systems limited to personnel and service accounts with a business need.
Encryption And Transport Security
- TLS for web and API traffic.
- Cloud-provider encryption at rest for managed databases, object storage, logs, and secret storage where supported by the provider.
- Payment-card data handled by Stripe rather than stored directly by SkillOps.
Auditability
- Audit events for important lifecycle actions, including skill changes, approvals, publication state, billing state, SSO/auth events where available, and gateway usage.
- Versioned skill content and approval records designed to preserve a history of who approved what and when.
- Billing and webhook state stored idempotently to reduce duplicate or inconsistent processing.
Application Security
- Environment separation for local, staging, and production.
- Production guardrails for live Stripe mode, production resource names, production secrets, and webhook livemode handling.
- Deterministic package artifact storage for approved skills.
- Review requirements materialized as data before package build and publication.
- Logging and diagnostics for production operations.
Personnel And Operational Practices
- Access to sensitive systems limited by role and business need.
- Credentials and production secrets must not be committed to source control.
- Material production changes should be verified through deployment and read-only production checks before broader rollout.
- Security-impacting changes should receive appropriate review.
4. Customer Responsibilities
Customer is responsible for:
- managing authorized users, roles, and administrators;
- configuring SSO, identity-provider access, and gateway access securely;
- removing users who no longer need access;
- reviewing skill content before approval and publication;
- validating AI-agent outputs and automated workflow behavior;
- securing endpoints, AI-agent hosts, MCP clients, local shims, and customer environments;
- maintaining appropriate backups or exports of Customer Data needed outside the Service; and
- not submitting prohibited or regulated data unless expressly agreed in writing.
5. Security Incidents
A "Security Incident" means accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data in SkillOps systems that compromises the confidentiality, integrity, or availability of that Customer Data.
SkillOps will notify Customer without undue delay after confirming a Security Incident affecting Customer Data. Notices will include information reasonably available to SkillOps, which may include the nature of the incident, affected data, mitigation steps, and recommended customer actions.
SkillOps' notice or response to a Security Incident is not an admission of fault or liability. Customer is responsible for any legally required notices to its users, employees, customers, regulators, or other third parties unless otherwise agreed in writing.
6. Vulnerability Reporting
Security concerns should be sent to vh@vivekhaldar.com. Customers should not run intrusive testing, vulnerability scanning, denial-of-service testing, social engineering, or physical attacks against SkillOps systems without prior written authorization.
7. Subprocessors
SkillOps may use subprocessors to provide hosting, storage, identity, payment, logging, monitoring, support, email, analytics, and other operational services.
The current subprocessor and service-provider list is also published at the SkillOps Subprocessor List. Launch providers are:
- Google Cloud Platform and Firebase Hosting: website and application hosting, compute, database, object storage, logs, and secrets.
- Stripe: payment processing, subscriptions, invoices, and Customer Portal. SkillOps does not store full card or bank details.
- Scalekit: SSO and identity routing.
- Google and Microsoft: customer-selected social or enterprise identity authentication.
- Google Workspace: business email used for support, privacy, security, legal, and billing communications.
Porkbun provides authoritative DNS and domain operations. It is listed for transparency but is not used to store Customer Data. Anthropic publishing is disabled in the launch environment and Anthropic is not a launch subprocessor.
Customer provides general written authorization for these subprocessors. SkillOps will provide at least 30 days' notice before adding or replacing a material subprocessor where reasonably practicable. Customer may object on reasonable data-protection grounds before the change takes effect; the parties will work in good faith on a commercially reasonable resolution.
SkillOps will remain responsible for subprocessors' processing of Customer Data to the extent required by applicable data-protection law and the agreement with Customer.
8. Data Processing Addendum
This section applies when SkillOps processes personal data in Customer Data on behalf of Customer and applicable data-protection law requires processor terms.
Roles
Customer is the controller, business, or equivalent role for Customer Data. SkillOps is the processor, service provider, contractor, or equivalent role for Customer Data. The parties acknowledge that SkillOps may also process limited account, billing, security, and operational data as an independent controller where permitted by law.
Subject Matter, Duration, Nature, And Purpose
The subject matter is SkillOps' provision of the Service. The duration is the term of the applicable subscription or Order Form plus any post-termination retention period. The nature and purpose of processing are to provide, secure, support, maintain, improve, and bill for the Service, and to comply with Customer instructions and applicable law.
Categories Of Data Subjects
Data subjects may include Customer's users, employees, contractors, reviewers, administrators, skill owners, support contacts, and individuals whose personal data appears in Customer-submitted skill content, comments, logs, or workflows.
Categories Of Personal Data
Personal data may include identifiers, contact information, account credentials or authentication metadata, professional information, usage data, audit records, workflow content, support content, and any other personal data Customer submits to the Service.
Processor Commitments
SkillOps will:
- process Customer Data according to Customer's documented instructions, these Terms, and applicable law;
- ensure personnel authorized to process Customer Data are bound by confidentiality obligations;
- maintain appropriate technical and organizational measures as described in this Appendix;
- use subprocessors under written obligations designed to protect Customer Data;
- assist Customer, taking into account the nature of processing and information available to SkillOps, with data-subject requests and data-protection obligations;
- notify Customer of confirmed Security Incidents as described above;
- at Customer's choice, delete or return Customer Data after termination as described in the Terms, Privacy Policy, or applicable Order Form, unless retention is required by law; and
- make information reasonably necessary to demonstrate compliance available to Customer, subject to confidentiality, security, and reasonable scope limits.
Customer Commitments
Customer will:
- provide lawful instructions;
- ensure it has all rights, notices, consents, and legal bases required for Customer Data;
- configure the Service in a manner appropriate for the sensitivity of Customer Data;
- respond to data-subject requests unless the request is directed to SkillOps and relates to SkillOps' independent controller processing; and
- not submit prohibited sensitive data unless agreed in writing.
International Transfers
The initial self-service offering is limited to United States business customers. Before intentionally offering the Service in a jurisdiction that requires an international-transfer mechanism, the parties will use legally recognized safeguards, such as standard contractual clauses, the UK addendum, or successor mechanisms, and will execute a separate transfer addendum if needed.
Audits
Customer may request reasonable information about SkillOps security and processing practices. Any audit must be limited to information reasonably needed to verify compliance, avoid disrupting the Service, protect other customers' data, and preserve SkillOps Confidential Information. Where available, third-party reports or written security responses may satisfy audit requests.
9. No Compliance Certification By Default
Unless expressly stated in an Order Form, SkillOps is not certified under SOC 2, ISO 27001, HIPAA, PCI DSS, FedRAMP, or similar frameworks. Customer is responsible for determining whether the Service meets Customer's regulatory, security, procurement, and compliance requirements.