← Back to home
Trust

Security at Skybridge

Last updated: 24 August 2026

Skybridge is the customer environment included with bounded AI production systems delivered and operated by Compsia. Because those systems can work with real business tools, a person stays in control of every outbound action covered by the contracted approval policy. This page describes the controls used across the current operating environment; the exact system boundary is documented for each customer implementation.

01Human approval by design

This is the control the whole product is built around. Agents can read your connected tools and prepare work, but outbound actions — sending an email, posting a message, updating a record in a connected system — wait for a person's explicit approval before anything is executed. The agent drafts; you decide.

We consider this a non-negotiable part of the product, not a feature toggle. It is what makes an AI agent auditable: every action that touched the outside world traces back to a human decision.

02EU hosting & data residency

The Skybridge application and its databases run in the European Union: compute is hosted with Scaleway in France (Paris), and our database and authentication layer runs on Supabase in EU regions. Some specialized providers (for example AI model providers) are located outside the EU — the full list, with purpose and region for each, is published in our privacy policy, and transfers rely on appropriate safeguards such as Standard Contractual Clauses.

03Workspace isolation

Every workspace is separated at the database layer. One workspace's content, conversations, connections and agents are never accessible to another workspace — including for organizations running several workspaces side by side.

04Least-data architecture

When an agent works on a connected source, we store distilled knowledge and references — summaries, key facts, links back to the original — rather than copies of your files. Raw file contents are read on your instruction, used for the task at hand, and are not logged. The less of your data we hold, the less there is to protect.

05Encryption

06Secrets & connections

Connections to your tools are brokered by our connector partner Maton using OAuth wherever the provider supports it — we never ask for your passwords. API keys and connection tokens are write-only: once saved, they are never displayed again and are never sent to the browser. You can disconnect any application at any time, and access is scoped per workspace and per agent.

07AI processing

Prompts and context are processed by our AI model providers under commercial API terms: your workspace content, conversations and connected-service data are not used to train models — neither ours nor theirs. Details are in the privacy policy.

08Operations & monitoring

09How we build & ship

10Compliance posture

GDPR: for workspace content, our customer is the data controller and we act as processor; our privacy policy documents subprocessors, retention and data-subject rights. A data processing agreement is available on request.

Control evidence: action approvals, environment separation, least-data design, monitoring and release controls are documented for security reviews and customer questionnaires.

11Reporting a vulnerability

If you believe you have found a security vulnerability in Skybridge, please email security@compsia.com with enough detail to reproduce the issue. We commit to acknowledging your report quickly, keeping you informed, and not pursuing action against good-faith research. Please do not access data that isn't yours or degrade the service while testing.

Skybridge is operated by OPS-CO Solutions. Questions about our security practices, or need a security questionnaire filled in? Email security@compsia.com.