Security Overview
Last updated: July 1, 2026
SkillTap.ai is operated by FullBricks LLC ("FullBricks", "we", "us"), 30 N Gould St Ste N, Sheridan, WY 82801, USA.
This page describes the controls we actually run today. Where we do not have something, we say so rather than leave it ambiguous.
Authentication
We do not store passwords. Sign-in is through Google or a single-use email link.
There is no password to guess, reuse, phish, or leak, and credential-stuffing has no surface here.
Tenant isolation
Every request re-verifies your organization membership against our database before any data is accessed. Requests for another organization's data are rejected.
This is enforced on the server for every application request, not applied selectively or left to a query filter someone has to remember to add.
Authorization
Within your organization, access is role-based. Your administrators decide which roles can do what — including which roles can see other members' transcripts and scores. Some thresholds, such as billing and member management, cannot be lowered, so an organization cannot accidentally lock its own administrators out.
Call audio
We do not retain call audio. Audio is streamed to an AI inference provider to generate the roleplay in real time, and is not stored by us. Only the transcript is kept.
See our Privacy Policy for what we do retain and for how long.
Voice session credentials
Voice sessions use single-use credentials that expire after 30 minutes. Long-lived API keys are never exposed to the browser.
AI provider terms
We do not use your content to train AI models, and our AI inference provider operates under paid-tier terms under which submitted content is not used to improve its products or train its models.
Our AI Transparency page explains what the AI does and what it cannot do.
Encryption
Data is encrypted in transit with TLS and encrypted at rest.
Compliance
Our SOC 2 Type II observation period is underway. We will make the report available under NDA once complete. We do not currently hold a SOC 2 certification.
We would rather tell you that plainly than imply otherwise.
What we do not have yet
- SAML single sign-on and SCIM provisioning
- A published penetration test
- A bug bounty program
- ISO 27001 or HIPAA attestation
If any of these gate a deal for you, tell us — it helps us prioritize.
Reporting a vulnerability
Email security@skilltap.ai. We will acknowledge within 2 business days and keep you updated until it is resolved. Please give us a reasonable window to fix an issue before disclosing it publicly.
Incident response
If we become aware of a breach affecting your data, we will notify you without undue delay, with what we know, what we are doing, and what we recommend. Our Data Processing Addendum makes that a contractual commitment.
Contact
FullBricks LLC 30 N Gould St Ste N Sheridan, WY 82801, USA