Skilled Edge Group
← Back to skillededge.io
Security & Trust

Your business data stays yours.

A Profit Optimization Audit means handing us job costing, labor, and billing exports from your business. That's sensitive information. Here is exactly how we handle it — and what we will never do with it.

What we ask for

We ask for the minimum, and nothing personal.

Every audit runs on a small set of CSV exports. We don't need access to your systems, we don't need logins, and we don't need anything about your employees as individuals.

  • No system access. You send exports. We never ask for credentials or a login to your accounting, job-costing, or payroll system.
  • No personally identifiable information. Employee data must be anonymized to numeric IDs before it reaches us. No names, no Social Security numbers, no addresses — it's written into our engagement agreement.
  • No customer lists. The audit works from job-level cost and billing data. We don't need your customer contact information.
  • Only what the analysis requires. If a data field isn't used in one of the audit categories, we don't ask for it.
AI & your data

The question every owner actually asks.

"Are you putting my bids, my pricing, and my job costs into ChatGPT?" It's the right question. Here's the straight answer.

We do not sell your data. Ever.

Not to lead brokers, not to data aggregators, not to anyone. Your operational data has exactly one purpose here: producing your audit report.

We minimize what goes to any third-party system.

Analysis is performed on the data you send, and we limit what is transmitted to outside services to what the work genuinely requires. Where sensitive client data is involved, we use business-tier AI services configured so that customer content is not used to train the provider's models.

Your data is not used to build products for anyone else.

We don't pool client data, we don't benchmark one client against another using their identifiable information, and we don't reuse your files to build tools we sell to other companies.

How it's protected

Practical controls, honestly described.

We're a small, focused firm — not an enterprise software vendor. Rather than list certifications we don't hold, here's what is actually in place.

🔑

Multi-Factor Authentication

MFA is enabled on the accounts used to receive, store, and analyze client data.

🔒

Encrypted Storage & Transit

Client files are transmitted over encrypted connections and held in encrypted storage environments.

👤

Single-Operator Access

Client data is accessed only by personnel directly performing your engagement. There is no broad internal access.

🗑️

Deletion in 14 Days

Raw client data files are permanently deleted within 14 calendar days after your report is delivered. This is a contractual commitment, not a policy preference.

📄

Confidentiality in Writing

Mutual confidentiality obligations are part of every engagement agreement before any data changes hands.

🇺🇸

U.S.-Based

Skilled Edge Group LLC is a Virginia limited liability company. Your engagement is governed by Virginia law.

Straight talk

What we don't claim.

Plenty of firms decorate a page like this with compliance logos that don't apply to them. We'd rather tell you where we actually stand.

  • We are not SOC 2 certified. If your procurement process requires it, tell us early and we'll be straight with you about fit.
  • We are not CMMC certified. If you perform defense work with controlled unclassified information, that data should not be included in an audit export — talk to us first and we'll scope around it.
  • We do not hold HIPAA, PCI, or ISO 27001 attestations, because none of them apply to the work we do for you.

Questions before you share anything?

If you have a security requirement, a vendor questionnaire, or you just want to know exactly what happens to a file after you send it — ask before you sign, not after.

Email dave@skillededge.io