Frequently Asked Questions

Everything you need to know about partnering with SkyTrust.

General & Onboarding

What makes SkyTrust different from other cybersecurity providers?

SkyTrust combines enterprise-grade security expertise with transparent, jargon-free communication. We're proactive rather than reactive: our threat monitoring stops incidents before they become breaches. Every client gets a dedicated analyst, not a ticket queue.

Do you work with small businesses or only enterprises?

We work with organizations of all sizes. Our Starter plan is specifically designed for small businesses that need enterprise-quality security without an enterprise-size budget or internal security team.

How quickly can you onboard a new client?

Most clients are fully onboarded and monitoring within 5-7 business days for threat monitoring. Compliance engagements typically begin with a discovery call and gap assessment within the first week.

Are your analysts US-based?

Our primary SOC operates from the United States with analysts in Austin, TX and New York, NY. We also maintain 24/7 coverage with international team members to ensure round-the-clock operations.

Pricing & Plans

Do you offer month-to-month contracts?

Yes. All plans are available month-to-month. We also offer 12-month and 24-month agreements with 10-15% discounts. Enterprise plans are typically custom-scoped annual agreements.

What's included in the free security assessment?

Our complimentary assessment includes a high-level review of your current security controls, identification of obvious gaps, a preliminary risk rating, and a tailored roadmap of recommended services. It takes approximately 90 minutes.

Can I upgrade or downgrade my plan?

Absolutely. You can upgrade at any time effective immediately. Downgrades take effect at the next billing cycle. Enterprise clients can adjust scope with 30 days notice.

Do you offer nonprofit or education pricing?

Yes, we offer 20% discounts for verified nonprofit organizations and educational institutions. Contact our sales team with your 501(c)(3) documentation or .edu domain to apply.

Technical Details

What SIEM platforms do you integrate with?

We integrate natively with Splunk, Microsoft Sentinel, IBM QRadar, Elastic SIEM, Sumo Logic, and Datadog Security. We can also work with other platforms via our custom connector framework.

Do you require installing agents on our systems?

For threat monitoring, lightweight agents are deployed on endpoints (typically 2-5MB). Network monitoring uses agentless flow analysis. We also integrate with your existing EDR tools (CrowdStrike, SentinelOne, Microsoft Defender).

How do you handle false positives?

Our analysts manually review all high-severity alerts before escalation. We continuously tune detection rules based on your environment. Most clients see false positive rates below 3% within 60 days of onboarding.

What's your SLA for incident response?

Business plan: 30-minute acknowledgment, 2-hour containment start. Enterprise: 15-minute acknowledgment, 1-hour containment start with dedicated on-call engineer. Starter: 60-minute acknowledgment, 4-hour containment start.

Compliance & Audits

Which compliance frameworks do you support?

We support SOC 2 Type I & II, ISO 27001, HIPAA Security & Privacy Rules, GDPR, PCI-DSS Levels 1-4, NIST CSF, CMMC, FedRAMP (advisory), and CCPA. We continuously expand our framework coverage.

Do you help with the actual audit, or just prep?

Both. We prepare you for audit, and we coordinate directly with your chosen audit firm (or can recommend accredited partners). Many clients choose us as their ongoing compliance monitoring partner post-certification.

How long does SOC 2 Type II certification take?

The observation period for SOC 2 Type II is a minimum of 6 months. Total time from kick-off to certification is typically 8-12 months depending on your current control maturity.

Can you help with GDPR compliance if we're a US-based company?

Yes. If you process personal data of EU residents, GDPR applies regardless of where you're based. We help with data mapping, DPA preparation, breach notification procedures, and cross-border transfer mechanisms.

Get Started Today

Ready to Secure Your Enterprise Infrastructure?

From 24/7 managed SOC threat monitoring and cloud security to SOC 2 compliance readiness, partner with SkyTrust to build resilience.