Procurement / Vendor assessment
The smallest possible vendor footprint. By design.
Skarn is built to pass vendor security assessments in regulated environments. There is no cloud service, no data processing by the vendor, and no dependency on Skarn's infrastructure for the product to operate. Most standard vendor-assessment questions answer themselves.
Skarn is the local-first, no-egress forensic layer for the AI-session surface the inline and cloud tools disclaim: local-disk session content, MCP and tool-call detail, and post-hoc attack-chain reconstruction with a session risk score.
Vendor assessment quick reference
| Question | Answer |
|---|---|
| Deployment model | On-premise only |
| Vendor / publisher identity | Red Black Tree d.o.o. - code-signed + Apple-notarized |
| Artifact integrity | macOS binaries Developer ID signed and Apple-notarized; every release asset sha256-pinned and verified by the Homebrew formula; multi-arch container image cosign-signed (Sigstore) with SBOM + SLSA provenance |
| Customer data sent to vendor | None |
| Vendor access to customer environment | None |
| Telemetry / usage data collected | None |
| Third-party sub-processors | None |
| GDPR Art. 28 DPA required | Not required - no data processing |
| Cross-border data transfer | None |
| Internet connectivity required | Optional - opt-in only |
| Supported operating systems | Windows, macOS, Linux (Intel + ARM) |
| Standards / framework alignment | MITRE ATLAS, OWASP LLM Top 10 2025, CWE (SARIF) |
| Source code model | Closed source today; source-available planned |
| Availability dependency on vendor | None - self-contained binary |
Regulatory compliance position
Compliant by architecture - no data leaves the machine, no DPA required.
Supports Article 21 evidence requirements; helps organisations demonstrate active monitoring.
Supports Article 8 ICT-vulnerability identification for financial entities. Applicable since 17 January 2025; BaFin supervises it for German entities.
Not in scope as a product - Skarn is not an AI system under the Act's definition. Where you must evidence that AI activity is monitored under the Article 12 record-keeping obligations that apply to high-risk systems from 2 August 2026, --audit-log (Team) appends a hash-chained local record of each scan - timestamp, policy, finding counts, verdict, no secrets - and detects edits and reordering of that history.
Fully supported - all data remains on-premise within your own jurisdiction.
C5 sets the criteria a cloud service provider is attested against by an auditor. Skarn ships no cloud service, so no Skarn cloud enters your assessment scope and there is no Skarn C5 attestation to request. The question is answered by the deployment model, not by a certificate.
The European Commission's framework (published 2025-10-20) scores cloud services on data localisation, operational control, and legal jurisdiction. Skarn is not scored by it, because it is not a cloud service: the scan runs on your own machines with no network call by default, so the operator is you and the jurisdiction is yours.
In force since 17 March 2026 for the physical resilience of critical installations; the cyber duties for the same operators sit in NIS-2 and the BSIG. For operators registering with the BBK by 17 July 2026 and documenting their technical, security-related, and organisational measures, Skarn contributes evidence: a local, auditable record of what AI coding sessions exposed, produced without anything leaving your machines.
Vendor assessment questions
- Does using Skarn require a Data Processing Agreement (DPA)?
- No. Skarn processes data only on the local machine and transfers no personal data to the vendor or any third party, so there is no processor relationship and no GDPR Article 28 Data Processing Agreement is required.
- Is there any vendor cloud or infrastructure to assess?
- No. Skarn is a self-contained local binary with no cloud dependency. There is no vendor infrastructure to assess for availability, breach risk, or data sovereignty - it runs entirely on your own machines.
- What is the provenance and code signing of Skarn?
- Skarn is published by Red Black Tree d.o.o. The macOS binaries are Developer ID signed and Apple-notarized, so they install with no Gatekeeper warning. The Homebrew formula pins each platform's release asset by sha256 and verifies it on download. The container image is cosign-signed (Sigstore keyless) and ships an SPDX SBOM and SLSA build provenance, verifiable with cosign verify. It is closed source today, with source-available licensing planned.
- Can Skarn provide a BSI C5 attestation or an EU Cloud Sovereignty Framework score?
- Neither applies to Skarn, because both assess cloud services. BSI C5 sets the criteria a cloud service provider is attested against by an auditor, and the European Commission's Cloud Sovereignty Framework scores cloud services on data localisation, operational control, and legal jurisdiction. Skarn ships no cloud service: it is a binary that runs on your own machines and makes no network call by default. No Skarn cloud enters your assessment scope, so there is no attestation to request and no sovereignty score to check.
More for your team: CISO and CSO, Legal and DPO, CTO and VP Eng, Containers and CI
Request vendor documentation
We will provide the security and data-handling documentation your assessment process needs.