Legal / DPO / Compliance
Nothing leaves the machine. No exceptions by default.
Skarn is built from first principles for regulated, EU data-residency environments. No personal data, no source code, and no credentials are transmitted to any external party. Your most likely objections are answered by the architecture itself - before you review a contract.
Regulatory compliance, law by law
Skarn processes data exclusively on the local machine. No personal data is transferred to Skarn or any third party - there is no Skarn cloud service, no telemetry, and no vendor access. Because no personal data goes to an external processor, no Article 28 Data Processing Agreement is required. Local reports contain masked credentials only and stay on your own infrastructure.
Article 21 requires active cybersecurity risk management and documented evidence of its effectiveness; Skarn's SARIF and JSON output provides that audit trail. Article 20 places direct personal accountability on management-body members for approving and overseeing these measures.
Enforceable since 17 January 2025. Article 5 makes the management body's ownership of the ICT risk framework non-delegable; Article 8 requires identification of ICT vulnerabilities - AI session credential exposure is squarely in scope.
Skarn uses rule-based, pattern-matching detection. It is not an AI system under the Act's definition, makes no consequential decisions, and falls in no prohibited or high-risk category. It monitors AI tools used by humans; it is not itself in scope, and no obligations apply to it.
Data handling, factual summary
| Item | Status |
|---|---|
| Data transferred to vendor | None, ever |
| Cloud infrastructure dependency | None |
| Third-party sub-processors | None |
| GDPR Art. 28 DPA required | Not required |
| Cross-border data transfer | None |
| Credentials shown in plaintext in reports | Never - always masked |
| Telemetry or usage data | None |
| Optional online checks | Opt-in only - off by default |
More for your team: CISO and CSO, CEO and Board, Procurement
Request a compliance briefing
We will walk Legal and the DPO through the architecture and the data-handling position, document by document.