SkillAEO Security Practices

Current access, transport, retention, incident, and vulnerability-reporting practices for SkillAEO.
Aug 17, 2026

This page describes current product controls, not a certification or guarantee that incidents cannot occur.

Transport and hosting

Production traffic is served through Cloudflare over HTTPS. Service-to-service connections use encrypted transport where supported and configured. Cloudflare publishes its current security program and privacy documentation.

Access control

Account sessions protect private reports, billing, settings, and history. Server-side ownership checks restrict report and Skills Pack history to the owning user. Administrative pages require an authenticated session and enforce permissions at the page or API boundary. The anonymous audit is intentionally public and limited by rate, domain, and capacity controls.

Audit safety

Submitted URLs are normalized and checked before requests. The crawler is limited to public HTTP(S) content and must not be used to bypass authentication, reach private network addresses, or attack a site. Provider failures and invalid responses are recorded rather than replaced with simulated results.

Data retention and deletion

Plan history windows control how much report history the product promises to make available. The current codebase does not claim that every underlying row or provider copy is automatically deleted exactly when a plan window ends. Account holders can request deletion through support; legal, fraud-prevention, backup, and payment records may require separate retention.

Vulnerability and incident reporting

Report a suspected vulnerability privately to security@skillaeo.com. Do not access data you do not own, disrupt the service, or publish sensitive details before there is time to investigate. For an active privacy or account incident, contact support@skillaeo.com.

See Privacy Policy and Subprocessors.