Security & Compliance
Last updated: January 1, 2025
At AI SKI, operated by TheMadHacker LLC, the security of your resort data is foundational. Ski operations run on real-time data, and we treat that trust with the utmost seriousness. This page describes how we protect your information.
1. Data Protection by Design
- Encryption in transit: All connections use TLS 1.2+ (HTTPS).
- Encryption at rest: Data at rest is encrypted using AES-256.
- Read-only integrations: We connect to your systems with the minimum scope needed — typically read-only.
- Role-based access: Internal access to your data is restricted by strict least-privilege controls.
2. Compliance
- GDPR — Full compliance for EU/EEA data subjects.
- CCPA/CPRA — California residents' rights honored.
- SOC 2 Type II — In progress; annual audits planned.
- Data Processing Agreements (DPA) — Available on request.
3. Infrastructure
We run on enterprise-grade cloud infrastructure with:
- Automated, encrypted daily backups
- Multi-region redundancy for high availability (99.9% uptime SLA on Enterprise)
- Continuous monitoring and automated threat detection
- Regular penetration testing by independent third parties
4. Incident Response
We maintain a documented incident-response plan. In the event of a data breach affecting your information, we will notify affected parties without unreasonable delay, and in any case within 72 hours as required by GDPR.
5. Sub-processors
We use a limited set of trusted sub-processors (hosting, email delivery, analytics). Each is bound by contractual data-protection obligations. A current list is available on request.
6. Security Reviews
Enterprise plans include a full security review, dedicated DPO support, and the ability to sign custom security addenda.
7. Contact
For security-specific inquiries or to report a vulnerability, email [email protected].