Trust

Trust is architectural, not contractual.

This page is maintained by Skipr to describe how the sovereign control plane is architected for trust — the reference model, what evidence it produces, who holds the keys, and how to reach us about a security concern. It is not a certification.

Deployment model
Skipr is deployed inside the customer, operator, or national perimeter — the control plane runs on infrastructure the organization owns. There is no foreign control plane dependency for enforcement, and no operational dependency on Skipr as a vendor to keep the plane running. See /deployment for the reference architecture.
Keys & authority
Local keys and local approval chains. Policy is authored, signed, and enforced inside the customer perimeter; no policy or authorization decision requires egress to a Skipr-operated service.
Runtime authorization
Every request from a person, agent, or machine is evaluated per call — identity, device, jurisdiction, scope, TTL, and policy resolved before the action is allowed. Sessions and agent actions in flight can be killed, throttled, or revoked from the control plane.
Evidence model
The control plane produces attested, signed, jurisdiction-tagged evidence as a by-product of enforcement — not as a downstream logging concern. Evidence is generated inside the perimeter and is queryable there. See /platform.
Data residency
Data residency follows the deployment. Because the control plane runs inside the customer's chosen jurisdiction, request, decision, and evidence data remain in that jurisdiction by default.
Shared responsibility
Skipr provides the sovereign control plane and its modules (SecureConnect, AgentConnect, IntelConnect). The operating organization is responsible for the infrastructure it runs Skipr on, the identities it federates, the policies it authors, and the integrations it enables. Customer-specific compliance obligations remain with the customer.
Contact form data
The Sovereign Briefing form collects organization, name, role, email, and free-text context. Submissions are stored and routed to the Skipr team for response. Handled confidentially on request.
Reporting a security concern
Send security concerns and responsible-disclosure reports to security@skipr.network. For general contact, use info@skipr.network or the briefing form.
Certifications
Specific certifications (SOC 2, ISO 27001, and comparable regimes) are managed with each customer as part of the deployment engagement. Named certifications are not claimed on this page.
This page describes Skipr's architectural approach and platform capabilities. It is app-owned editable content, not independent verification.