Skip to content
SkyRosterBook a discovery call

The six desks · IT security

Radu, IT security reviewer*

“I have eleven questions and a spreadsheet. If one answer is ‘contact us’, the vendor scores zero on that line.”

What he needs to decide

Whether this clears the bar before the contract stage

Radu is not choosing the vendor. He is deciding whether SkyRoster clears his organisation's minimum technical bar well enough to let procurement keep talking to us, and what to flag for the lawyers and the ops team if it does. That means precise answers where we have them, and an honest, specific reason where we don't, rather than a marketing paragraph standing in for either.

The eleven questions

Answered here, in order, with no brochure in between

QuestionAnswer
Where can our data actually live?

Three shapes: shared SaaS on infrastructure we operate, dedicated SaaS reserved for your organisation, or your own infrastructure, self-hosted on Kubernetes. Shared hosting is included in the software licence; dedicated hosting is priced separately and is required for bespoke code outside the standard supported release or requested isolation. Changes included in the standard supported release do not themselves trigger dedicated hosting. Standard product releases use the same codebase across these shapes. Customer-specific code has a separately agreed release and maintenance scope.

configured
Is our data isolated from your other customers?

Yes. Every tenant gets its own identity realm (Keycloak) and, per our infrastructure practice, its own separate database. A query cannot cross tenant boundaries by accident, because there is no shared table it could cross. This is true whether you're on our shared cluster or a dedicated one.

verified
Can we sign in through our own identity provider?

Yes: Microsoft Entra ID (Azure AD) through Keycloak's OIDC federation, or an on-premises Active Directory through LDAP, with optional Kerberos for a passwordless internal login. Your staff sign in with the credentials they already have; you keep control of the account lifecycle.

configured
Can new starters and leavers sync from our directory automatically?

New starters, yes: a scheduled job reads your Active Directory over LDAP and creates or updates the matching employee record automatically. Leavers, no, not yet: the sync creates and updates, it does not deactivate someone who has left your directory. Removing an ex-employee's access is still a manual step today.

configured
How fine-grained is the permission model?

Permissions are scoped on a six-level ladder, from your own record up to the whole organisation, applied independently to read and write, for every one of 17 securable areas, down to individual business actions such as approve a swap versus delete a leave request. Write access can never exceed read access for the same role.

verified
Is access enforced only in the interface, or in the data as well?

Protected endpoints and handlers check operation privileges, and secured repositories apply employee and unit scopes. Coverage differs between persistence paths. Include direct API and target-record authorization tests for the workflows and roles in your deployment.

verified
Are uploaded employee documents, IDs, licences, medical certificates, encrypted at rest?

Supported uploaded-document storage encrypts file content. Key management and legacy-file coverage must be reviewed for the deployment. General employee responses separate confidential fields; history and exports have additional access paths and must be included in the permissions review.

verified
Is there a change-audit trail we can hand to our own auditors?

Audit & History provides actor, time and before/after values for supported recorded changes. Confirm the implemented coverage, permitted viewers, retention and any export requirement in the written offer. It is not an exhaustive or tamper-proof record of every action.

verified
Do your internal services trust each other blindly?

The gateway strips the external caller's internal-call marker. User-facing calls propagate a security context, while background jobs and message consumers have service contexts. Review those privileges and the deployed network boundary together.

verified
Has the platform been independently tested for security issues?

Request the current assessment scope, tested version, open findings, remediation evidence and regression coverage during evaluation. This page does not establish that every finding is closed or that every deployment has the same tested controls.

stated
If we leave, does our data actually go away?

When an engagement ends we can deprovision your tenant: its identity realm removed, its database dropped, its stored secrets revoked. It is a documented step in how we retire a tenant, not an afterthought we improvise on request.

verified

Service and assurance commitments

Start with the deployment you need

Standard SaaS includes a 99.5% uptime SLA, automatic updates and daily backups on Microsoft Azure in the EU. Customer support is optional. Assurance evidence, recovery-time and recovery-point objectives, support response times and additional service requirements are agreed for the deployment and contract you choose.

Bring your assurance and service requirements to a working sessionso the written offer addresses the exact commitments your scorecard requires.

What it can't do for him

Two honest limits

  • It cannot make your own infrastructure secure for you. If you choose to self-host, patching and hardening the underlying cluster is your team's responsibility; our guarantees cover the software running on it, not your operating system.
  • It cannot show you a complete change history for every field in the system today. Audit coverage is real, verified, and growing deliberately, not total on the day you sign.

The full breakdown behind every row above lives on the security page, and what the product deliberately does not do is catalogued on the limits page.

* Radu is a fictional persona, not a specific customer or contact. He stands in for the technical reviewer role every ANSP procurement puts in the room before a contract is signed.

Bring your own eleven questions.

If your list is longer than ours, a working session is where we go line by line against your actual questionnaire, with an engineer in the room, not a salesperson reading a script.

Book a discovery call

Booking opens a 20-minute discovery call. A tailored working session is arranged afterwards.

Send a question instead