Security

Enterprise Intelligence Requires Enterprise Trust.

Skuiddy is designed to connect knowledge across cloud environments, applications, data platforms, identity systems, development tools, AI services, and business technologies. That responsibility requires security to be part of the platform architecture — not an afterthought.

Least Privilege
Tenant Isolation
Defense in Depth
Traceability
Customer Control

Read-Only Discovery by Design

Skuiddy Smart Sensors are designed to use read-only or minimally required access whenever supported by the connected platform.

Smart Sensors discover authorized information and contribute knowledge to the Organizational Twin. They are not intended to modify, delete, reconfigure, or deploy resources in customer environments unless a future capability is explicitly enabled and separately authorized.

Customers remain in control of:

  • Which Smart Sensors are connected
  • Which accounts and environments are accessible
  • Which permissions are granted
  • Which discovery capabilities are enabled
  • When integrations are disconnected

Least-Privilege Access

Skuiddy follows the principle of least privilege.

Smart Sensors should receive only the permissions required for their configured discovery scope.

Where supported, Skuiddy encourages:

  • Read-only roles
  • Scoped API permissions
  • Limited service accounts
  • Short-lived credentials
  • Role assumption
  • Permission review
  • Credential rotation

Broader permissions may increase discovery coverage but should be evaluated against organizational security requirements.

Secure Credential Handling

Skuiddy is designed to avoid storing sensitive integration credentials directly in ordinary application records.

Depending on deployment and integration requirements, credentials may be managed through approved secrets-management services and referenced through secure identifiers.

Security practices may include:

  • Encrypted secrets storage
  • Restricted secrets access
  • Credential rotation
  • Environment separation
  • Access logging
  • Secret-reference architecture

Credentials should never be included in Organizational Twin metadata, discovery results, application logs, or user-facing exports.

Encryption

Skuiddy is designed to protect information using encryption:

  • In transit: Connections use modern transport encryption where supported.
  • At rest: Customer information is encrypted at rest through applicable cloud and data-storage controls.

Encryption capabilities may vary based on service configuration, deployment model, and connected systems.

Multi-Tenant Architecture

Skuiddy is designed as a multi-tenant enterprise platform.

Customer information is logically separated by organization and protected through tenant-aware access controls.

Platform services are designed to enforce organizational context across:

  • Users and Workspaces
  • Smart Sensors and Discovery Runs
  • Entities and Relationships
  • Organizational Twins
  • Insights, Findings, and Recommendations
  • Policies
  • Events and Audit Logs

Identity and Access Management

Skuiddy supports role-based access patterns designed to limit access according to organizational responsibility.

Platform roles may include:

  • Platform Administrator
  • Organization Administrator
  • Workspace Administrator
  • Sensor Operator
  • Analyst
  • Viewer

Future enterprise identity capabilities may include:

  • Single sign-on
  • OpenID Connect and SAML
  • Enterprise identity-provider integration
  • Automated user provisioning
  • Multi-factor authentication
  • Conditional access integration

Availability may depend on product edition and deployment status.

Auditability

Skuiddy is designed to maintain traceability across important platform activity.

Audit information may include:

  • User activity
  • Authentication events
  • Smart Sensor configuration changes
  • Discovery activity
  • Entity and relationship changes
  • Policy updates
  • Administrative actions
  • API activity

Audit capabilities support investigation, accountability, governance, and operational review.

Discovery Provenance

Organizational intelligence should be explainable.

Skuiddy is designed to retain information about:

  • Which Smart Sensor discovered an entity
  • When the entity was first and last observed
  • Which source contributed information
  • How a relationship was identified
  • The confidence associated with discovered or inferred knowledge
  • How the Organizational Twin changed over time

This provenance helps users evaluate and validate the information represented in the Organizational Twin.

Knowledge Coverage and Twin Confidence

Skuiddy uses concepts such as Knowledge Coverage and Twin Confidence to communicate the breadth and confidence of organizational knowledge.

These indicators are designed to improve transparency. They are not certifications or guarantees of:

  • Completeness
  • Accuracy
  • Security
  • Compliance
  • Risk elimination

Customers should evaluate Skuiddy information alongside appropriate technical, operational, security, legal, and governance expertise.

Secure Development

Skuiddy is developed using security-conscious engineering practices that may include:

  • Source-code management and peer review
  • Dependency management
  • Automated testing
  • Environment separation
  • Infrastructure as code
  • Controlled deployments
  • Logging and monitoring
  • Vulnerability remediation
  • Secure configuration management

Our practices will continue to mature as the platform and customer requirements evolve.

Responsible AI

Skuiddy may use AI to classify entities, infer relationships, identify patterns, summarize organizational information, and generate insights or recommendations.

AI-assisted results are intended to support human decision-making.

Skuiddy is designed to promote:

  • Explainability
  • Provenance
  • Confidence indicators
  • Human review
  • Appropriate access controls
  • Policy-aware processing

AI-generated results should be reviewed before they are used for consequential decisions.

Customer Responsibilities

Security is a shared responsibility.

Customers are responsible for:

  • Protecting user credentials
  • Managing authorized users
  • Reviewing Smart Sensor permissions
  • Applying least-privilege access
  • Securing connected systems
  • Rotating credentials where appropriate
  • Reviewing Organizational Twin access
  • Validating insights before acting on them
  • Promptly reporting suspected security concerns

Vulnerability Reporting

If you believe you have identified a security vulnerability affecting Skuiddy, please report it responsibly.

Include:

  • A description of the issue
  • Affected service or feature
  • Reproduction steps
  • Potential impact
  • Relevant supporting information

Please do not publicly disclose a suspected vulnerability before we have had a reasonable opportunity to investigate and respond.

LumaSeer LLC

Skuiddy Security

security@skuiddy.com

Our Commitment

Skuiddy's purpose is to help organizations better understand their environments.

We believe that understanding must be built on trust.

As Skuiddy evolves, we will continue strengthening security, privacy, governance, transparency, and enterprise readiness across the platform.