AWS Partner Cloud & AI Consulting Australia-wide delivery

Security

How we handle your systems
and your data

Consultants get access to production. Here is what we do to deserve it, and who to contact if you find a problem.

Data residency ap-southeast-2 by default Disclosure hello@skylinkitsolution.consulting

Our security practices

Access to your environment

We work in your accounts under identities you control and can revoke. We ask for the narrowest role that lets us do the work, time-bound where your tooling supports it.

  • Named individual identities, never shared credentials
  • Multi-factor authentication on every account we use
  • No long-lived access keys on consultant machines
  • Access revoked at engagement close, confirmed in writing

Your data stays yours

Production data stays in your environment. Where we need data to work with, we prefer synthetic or de-identified sets, and we say so explicitly when we do not.

  • No copying production data to consultant machines
  • Australian data residency by default
  • Any exception raised explicitly and approved in writing

What we build for you

Everything is in version control in your repositories, reviewed before it reaches an environment, and scanned for secrets and known vulnerabilities in your pipeline.

  • Peer review on every change
  • Secret scanning and dependency checks in CI
  • Preventative guardrails over detective controls

Our people

Consultants are Australian-based employees, not an offshore subcontracting chain. Where a specialist partner is required, they are named in the proposal rather than after award.

  • Background checks appropriate to the engagement
  • Confidentiality obligations in every employment agreement
  • Security training on joining and annually
This website

How this site itself is run

A consultancy that cannot secure its own brochure site is not a good sign, so here is what this one does.

  • Static content served from private object storage, reachable only through the CDN
  • HTTPS enforced, with HSTS and a content security policy that restricts scripts to this origin
  • The enquiry form is processed by an isolated function that only the CDN can invoke
  • Submissions are encrypted at rest in the Sydney region and expire automatically
  • No advertising or tracking cookies, and no third-party analytics
Responsible disclosure

Found something? Tell us.

If you believe you have found a security vulnerability in this website or in something we have built, email hello@skylinkitsolution.consulting with enough detail to reproduce it.

We will acknowledge your report within two business days and tell you what we intend to do about it. We will not pursue legal action against anyone who reports a genuine issue in good faith, provided you do not access, modify or destroy data belonging to anyone else, and give us reasonable time to fix the issue before disclosing it publicly.

We do not currently run a paid bug bounty. We do credit reporters who want to be credited.

Need this in questionnaire form?

If your procurement process needs a completed security assessment rather than a web page, ask and we will complete yours.