StoneSky

SkyKeep™ — Available now

Your documents.
Your building.
Finally, your AI.

SkyKeep is a self-hosted document vault that lets a consultant run AI over your most sensitive operations — without that data ever leaving a boundary you control. A fresh, isolated environment per engagement. You hold the keys. You own the audit log.

In the default posture — your keys, your hosting — the vendor cannot read your content. By construction.
§01

The trade-off you've been offered

Most organizations that want AI-assisted automation face an uncomfortable choice. Neither half of it is acceptable when “who could be compelled to hand over our data” is a real question.

Option A

Hand it to the cloud.

Give your internal documents to a large cloud AI platform and trust its promises hold up — including against foreign legal demands under laws like the U.S. CLOUD Act, which can compel access even to data stored in your own country.

Option B

Go without.

Skip AI-assisted discovery entirely. Rely on manual consulting hours to find and design your automations — slower, and just as expensive.

SkyKeep is the third option.

A consultant analyzes your operations and designs automation entirely inside a boundary you control — not a shared cloud platform, and not something that outlives its usefulness in your environment. This is not a claim that cloud AI is insecure. It’s a recognition that for some organizations, the calculus is different — and until now there hasn’t been an easy alternative.

§02

How it works, in plain terms

01

You provide documents

Process guides, spreadsheets, meeting notes, emails — whatever describes how your operations run today.

02

The system reads and organizes them

Finding the repetitive, manual, rule-based work ripe for automation — and the connections between people, systems, and handoffs that a document-by-document read would miss.

03

You get evidence, not a black box

Findings point back to the documents they came from, so your team can check the answer instead of taking it on faith.

04

Your consultant builds the automation

Using the findings as a blueprint — either handing you something that runs in your own existing systems, or leaving a small ongoing infrastructure piece if it makes sense.

05

When the engagement ends, it's gone

Unless you choose to keep it. Deletion is a single, demonstrable command your team can watch run — not a hope.

§03

Who it's for

Regulated industries

Where handling is law

Healthcare, financial services, defense, legal — where data handling is a compliance requirement, not a preference.

Government & public sector

Sovereign by rule

Organizations subject to data-sovereignty or localization rules, where deployment location is the requirement.

Mid-size & enterprise

No new dependency

Organizations that want AI-assisted automation discovery without adding a permanent new vendor dependency.

Consultants

An architectural story

Automation and AI consultants who want an evidence-backed way to find opportunities — and a story that sets them apart from generic AI resellers.

§04

Built for questions your tools can't ask

Multi-hop answers

Across documents

Cross-document questions standard RAG tools can’t reach — like “which counterparties appear in both our supplier contracts and our incident reports.”

Token efficiency

Pre-computed, deterministic

Relationships are computed once, deterministically — you’re not paying tokens to rediscover your own data on every query.

Structured onboarding

No magic switch

Onboarding is a structured, consultant-led project, and we say so up front. The install is co-delivered, scoped in the first conversation.

Pedigree

20–30 years deep

Built by a team carrying decades of security and business-process pedigree. This isn’t a wrapper company.

§05

Versus big-cloud AI

The comparison a security reviewer actually runs. SkyKeep depends on no vertically integrated stack to function — it can optionally bridge to them: read-only, time-limited, revocable. It never depends on them.

Big-cloud AI
SkyKeep™
Where your data lives
Inside the vendor's cloud, subject to their infrastructure and their government's legal reach
Inside a boundary you choose — your own infrastructure, or a dedicated, isolated environment stood up just for your engagement
Who holds the keys
The vendor, by default
You, by default — outsourcing custody is your explicit choice, not the default
When you stop
Data typically stays in the vendor's systems under their retention policies
A defined, demonstrable teardown — deletion and key destruction on command
Can you verify what it read
Limited visibility into internal processing
Every query and every document accessed is logged and exportable to you directly
Built for your operations
Generic assistant retrofitted to your data
Built around your process, handoffs, and systems from day one
§06

Three ways an engagement ends

You decide at kickoff — plainly, in the engagement, not buried in terms of service: who holds the keys, who operates the host, and what happens at the end.

DEFAULT

Temporary bridge

SkyKeep ingests, analyzes, and helps design the automation; the finished work is implemented in the systems you already run. Then the environment is decommissioned — nothing of SkyKeep persists.

The consultant delivers a solution and leaves.

Permanent store

The environment keeps running as your ongoing infrastructure — because the automation’s value depends on continuously reasoning across systems, or you want to keep the knowledge base.

A durable institutional-memory layer.

Handoff

At engagement end, the environment and all keys transfer to your ownership. Every credential issued during the engagement is revoked — “the consultant retains no access” is a property of the system’s state, not a promise about behavior.

Self-host it. No vendor dependency.

§07

Enterprise grade is a set of properties,
not a price tag

Seven properties define it, at every engagement size. HA clustering, dedicated HSMs, and 24/7 monitoring are enterprise features, priced for the clients who need them — not requirements for the guarantee to hold.

01
Isolation a regulated buyer would accept

One sealed environment, storage, and key per client. Nothing shared.

02
Access that follows your organization

Plug into your directory; disabling an account blocks new sessions immediately, with a documented revocation window.

03
A complete record you own

Every access, allowed and refused, in a tamper-evident log you hold and can hand to your own auditors.

04
A documented, provable data lifecycle

Brought in, used, recoverable if something breaks, then destroyed or handed over on command.

05
Written clarity on responsibility

Keys, hosting, backups, retained records — stated in the contract, not assumed.

06
A stated path for fixes and bad days

A committed timeline for security fixes and a defined incident-response path.

07
An honest standards mapping

Answers a security questionnaire honestly — even where the honest answer is “not applicable at this tier, and here’s why.”

§08

Speaks the standards

The architecture maps to the frameworks a security questionnaire asks about — answered structurally, not with policy language.

Zero-trust

NIST SP 800-207 — every request independently verifies the person, the workload, and the machine. AND-ed, failing closed.

Workload identity

SPIFFE trust model — software identity is attested, not asserted.

AuthN & AuthZ

NIST SP 800-63B, ABAC (NIST 800-162), least privilege and separation of duties.

AI security

OWASP Top 10 for LLM Applications, NIST AI RMF, EU AI Act Art. 12 record-keeping — answered structurally.

Infrastructure & crypto

AES-256 at rest, TLS 1.2+ / mTLS in transit, NIST 800-57 key practices, NIST 800-88 cryptographic erasure.

Compliance frameworks

Structured so evidence collection for SOC 2, HIPAA, GDPR, and ISO 27001 is straightforward when a client pursues certification.

Aligns with — never “certified against.” SkyKeep maps to these standards; StoneSky holds no SOC 2, ISO, or FedRAMP attestation today, and we’d rather tell you that plainly than imply otherwise. An honest “in progress” survives diligence.

§09

The questions worth asking

Custody. Your DMS vendor holds your documents on their cloud, under their terms — read the export clauses. SkyKeep runs inside your perimeter and the vendor holds no key. They’re also different jobs: your DMS stores and organizes; SkyKeep answers questions across everything. It can sit beside the DMS and read from it.

Keep it. SkyKeep maps to your Entra security structures through its connectors, so it enforces the access rules your directory already defines. It reads SharePoint under your existing model and becomes the memory layer across the systems Copilot doesn’t reach — your ERP, your file server, your correspondence archive. And its knowledge stays yours when your Microsoft agreement changes.

Compliance proves you followed your policies. It doesn’t stop a breach — plenty of certified firms leak anyway. SkyKeep gives you the security property itself — no cross-compartment leakage — and the append-only audit trail falls out as a byproduct, which makes your next audit cheaper too.

Ask where the documents go. With a cloud assistant the answer is a policy that can change. Here it’s an architecture you can inspect: the files never leave your building.

The vault runs without us. Data, audit log, access — all yours, on your hardware. Test it during your evaluation: block the vendor heartbeat and keep working. Most software can’t make that offer.

Not yet — certification is on the funded roadmap, and we say “aligns with,” never “certified against,” until an attestation actually exists. What exists today: an architecture where the vendor can’t touch your data, which removes most of what SOC 2 audits vendors for. Bring your security team; a threat model and deployment guide are available under NDA.

You’re early, and priced like it. Early customers get founder attention no later customer will get, a locked rate, and input on the connector roadmap. The security layer is the part that’s been built and tested longest — the early part is the operational tooling around the vault, not the vault.

Keep the watch

Verify us.
Don't trust us.

A 20-minute demonstration on a real document. Ask it something you’d ask a senior associate. The install is co-delivered, scoped in the first conversation.

Scroll to Top