Engineering
Security Architecture
Last updated 24 August 2026
Current controls and intended boundaries across Skolvo Agent, CampusNova, and SignalWatch. This is not an audit report or certification.
1. The design rule
The cheapest way to protect sensitive data is to never hold it. Every architectural decision below follows from that: process on the edge, store the minimum, and make the stored form useless on its own.
2. Biometrics: on-device processing
CampusNova is being designed so face matching runs on the device at the gate rather than on a cloud server. This is a prototype architecture and has not been independently audited.
The intended downstream record is an attendance event rather than a face photograph. We are not publishing liveness, accuracy, or attack-resistance claims before controlled testing.
3. Access control
The prototype uses invitation flows and role-scoped access rather than public product registration. Server-side role enforcement and tenant isolation are design requirements that must be verified before general availability.
Academy separation is part of the planned data model. No claim of production isolation or penetration-tested enforcement is made while the product remains a prototype.
4. Data in transit and at rest
The public website is served over HTTPS. Product credential storage, database exposure, backup, and encryption controls must be documented against the eventual deployment before launch.
5. Audit trail
An attributable change history is a CampusNova product requirement. It should not be read as a claim that a production audit trail is deployed today.
6. Regulatory Watchdog data sources
SignalWatch is designed around public FDA sources and client watch configuration. The current workflow does not require confidential submissions; users should not provide them.
7. Skolvo Agent data boundary
Skolvo Agent may process candidate profiles, work-authorisation details, CV files, job records, and application workflow state. Live external submission is not currently presented as available; actions requiring user review must remain visible.
8. What we do not yet claim
We are a small studio in early access. We do not currently hold SOC 2, ISO 27001, or HIPAA certification, and we will not imply otherwise on a marketing page. The products are not generally available. If your procurement process requires a specific certification, tell us. We would rather scope that honestly than lose your trust later.
9. Reporting a vulnerability
If you find a security issue, email support@skolvo.online with “security” in the subject. Please give us a reasonable window to fix it before publishing. We ask researchers to report in good faith and avoid accessing other people's data.
