Trust
Security
Last updated October 1, 2026
Clients trust us with their ideas, their footage, their contracts and their payments. We protect that trust the same way we run a production: planned in advance, checked twice and never left to chance. Security comes before convenience in every decision we make about our systems.
skyllamaspac.com is one of the Skyllamas Productions LLC websites, and they all run on the same protected systems. This page explains what we do today, what we have already done and what we are working on next.
Signing in
- No passwords for clientsClients and students sign in with a one-time code sent to their email. The code expires after 10 minutes, works once, and allows only a few tries. There is no client password to steal or reuse.
- Two-step sign-in for our teamTeam members choose their own password of at least 12 characters, and a sign-in from a new device also needs a code sent to their email. Passwords are stored in a one-way scrambled form that nobody, including us, can read back.
- Two-step verification on every company accountOur email, web hosting, database, domain, payment and email-sending accounts all require a second step to sign in.
- Bots and guessing blockedSign-in pages use an automated bot check, limit repeated attempts and refuse throwaway email addresses.
- Sessions that endTeam sessions end after 12 hours, and any account can be signed out of every device at once.
Your information stays yours
- You only ever see your own recordsEverything in your account is matched to your verified email. Changing a link or a number in your browser never opens anyone else’s information.
- Checked every timeEvery page and every action checks permission on our server before it does anything. We never rely on simply hiding a button.
- Only the team members who need itEach team member’s access matches their job. Nobody can give anyone more access than they have themselves.
- A database closed to the publicOur database refuses all outside access. Only our own website’s server can read or write it.
- A permanent activity recordSign-ins, access changes, settings, payments, exports and deletions are recorded. The record can be added to but never edited or erased by the website.
- Download links that expireA link to download one of your files closes automatically after two hours.
- We never sell your informationSee our Privacy Policy for exactly what we collect and why.
Read our privacy policy.
Payments
- Your card number never reaches usYou pay through Stripe, a payment processor trusted by millions of businesses. You type your card into Stripe’s own secure payment box, so we never see or store the full number.
- Confirmed by Stripe, not by your browserA payment only counts once Stripe’s own record shows it went through for the right amount. Messages from Stripe are checked for a signature so they can’t be faked.
- No saved cards, no surprise chargesWe don’t keep cards on file, and nothing is ever charged automatically.
- A separate payment account for each businessEach Skyllamas business has its own payment account, all held by Skyllamas Productions LLC.
Behind the scenes
- Keys never written into our codeThe passwords and keys that connect our systems live only in our providers’ locked settings. Every change to our software is scanned automatically, and a change that contains a key or password is stopped.
- Every change approved before it goes liveChanges are prepared and tested separately, must pass automatic checks, and go live only after the owner approves them.
- Test systems with made-up dataNew work is tried on a separate test copy that holds made-up data, never real client information.
- Careful database changesEvery change to the database is written down, tried on the test copy first, and applied to the live system only after a fresh backup.
- New features switched on deliberatelyNew features stay switched off on the live site until they have been checked and approved.
- A written rule on sensitive dataEveryone who works on our systems, and every software tool that helps us build them, follows a written rule: no viewing, copying or storing of passwords, keys, card or bank details, or personal information a task doesn’t need.
- Tamper-evident agreementsSigned proposals are sealed with a digital fingerprint, so any later change to the document would show.
Backups and monitoring
- Backed up every day and every nightOur database is backed up daily, and every night an encrypted copy is stored with a separate company, so one provider’s problem can’t take everything with it.
- Backups we have testedEach night’s copy is restored automatically as a test. We have also practised a full restore by hand.
- Your files backed up tooClient files get their own nightly encrypted copy, with the file names encrypted as well.
- Alerts within minutesOur websites are checked around the clock. If a site goes down, an error happens or a backup is missed, we get an email.
- Encrypted connections everywhereEvery page loads over an encrypted connection, and private pages are never stored in your browser’s cache.
What we have done
- Completed a full security review of our systems and fixed every important finding.
- Turned on two-step verification for every company account.
- Set up nightly encrypted off-site backups with automatic restore tests, and practised a full restore.
- Scanned the complete history of our software for leaked keys: none found. Every new change is now scanned automatically.
- Built a separate test system with made-up data, so real information is never used for testing.
- Started a permanent activity record of sensitive actions.
- Wrote step-by-step plans for replacing a key, securing an account and recovering from a backup.
What comes next
Security is never finished. These improvements are planned:
- Passkeys or an authenticator app for every team member, in addition to today’s two-step sign-in.
- Confirming the team member’s identity again before the most sensitive actions, such as changing access or payment settings.
- Sign in with Google or Apple for clients, still with no password to remember.
- A team workspace on its own private address, separate from our public websites.
- Dedicated private storage for the files we deliver to you.
- Stronger browser protections and bot checks on every public form.
- Restore drills every three months.
Report a concern
If you notice anything that looks wrong, or have a question about how we handle your information, email [email protected] or call 973-913-5885. We look into every report.
No system can be perfectly secure. If a breach ever affected your personal information, we would tell you as the law requires.
