Procurement / Vendor assessment

The smallest possible vendor footprint. By design.

Skarn is built to pass vendor security assessments in regulated environments. There is no cloud service, no data processing by the vendor, and no dependency on Skarn's infrastructure for the product to operate. Most standard vendor-assessment questions answer themselves.

Skarn is the local-first, no-egress forensic layer for the AI-session surface the inline and cloud tools disclaim: local-disk session content, MCP and tool-call detail, and post-hoc attack-chain reconstruction with a session risk score.

Vendor assessment quick reference

QuestionAnswer
Deployment modelOn-premise only
Vendor / publisher identityRed Black Tree d.o.o. - code-signed + Apple-notarized
Artifact integritymacOS binaries Developer ID signed and Apple-notarized; every release asset sha256-pinned and verified by the Homebrew formula; multi-arch container image cosign-signed (Sigstore) with SBOM + SLSA provenance
Customer data sent to vendorNone
Vendor access to customer environmentNone
Telemetry / usage data collectedNone
Third-party sub-processorsNone
GDPR Art. 28 DPA requiredNot required - no data processing
Cross-border data transferNone
Internet connectivity requiredOptional - opt-in only
Supported operating systemsWindows, macOS, Linux (Intel + ARM)
Standards / framework alignmentMITRE ATLAS, OWASP LLM Top 10 2025, CWE (SARIF)
Source code modelClosed source today; source-available planned
Availability dependency on vendorNone - self-contained binary
Because Skarn is a locally-deployed binary with no cloud dependency, it presents a substantially lower vendor-risk profile than comparable SaaS security products. There is no Skarn cloud infrastructure to assess for availability, breach risk, or data sovereignty. The binary either works on your machine or it does not - independent of any vendor system.

Regulatory compliance position

GDPR

Compliant by architecture - no data leaves the machine, no DPA required.

NIS-2

Supports Article 21 evidence requirements; helps organisations demonstrate active monitoring.

DORA (BaFin)

Supports Article 8 ICT-vulnerability identification for financial entities. Applicable since 17 January 2025; BaFin supervises it for German entities.

EU AI Act

Not in scope as a product - Skarn is not an AI system under the Act's definition. Where you must evidence that AI activity is monitored under the Article 12 record-keeping obligations that apply to high-risk systems from 2 August 2026, --audit-log (Team) appends a hash-chained local record of each scan - timestamp, policy, finding counts, verdict, no secrets - and detects edits and reordering of that history.

EU data residency

Fully supported - all data remains on-premise within your own jurisdiction.

BSI C5 (Nachweis)

C5 sets the criteria a cloud service provider is attested against by an auditor. Skarn ships no cloud service, so no Skarn cloud enters your assessment scope and there is no Skarn C5 attestation to request. The question is answered by the deployment model, not by a certificate.

EU Cloud Sovereignty Framework

The European Commission's framework (published 2025-10-20) scores cloud services on data localisation, operational control, and legal jurisdiction. Skarn is not scored by it, because it is not a cloud service: the scan runs on your own machines with no network call by default, so the operator is you and the jurisdiction is yours.

KRITIS-Dachgesetz

In force since 17 March 2026 for the physical resilience of critical installations; the cyber duties for the same operators sit in NIS-2 and the BSIG. For operators registering with the BBK by 17 July 2026 and documenting their technical, security-related, and organisational measures, Skarn contributes evidence: a local, auditable record of what AI coding sessions exposed, produced without anything leaving your machines.

Vendor assessment questions

Does using Skarn require a Data Processing Agreement (DPA)?
No. Skarn processes data only on the local machine and transfers no personal data to the vendor or any third party, so there is no processor relationship and no GDPR Article 28 Data Processing Agreement is required.
Is there any vendor cloud or infrastructure to assess?
No. Skarn is a self-contained local binary with no cloud dependency. There is no vendor infrastructure to assess for availability, breach risk, or data sovereignty - it runs entirely on your own machines.
What is the provenance and code signing of Skarn?
Skarn is published by Red Black Tree d.o.o. The macOS binaries are Developer ID signed and Apple-notarized, so they install with no Gatekeeper warning. The Homebrew formula pins each platform's release asset by sha256 and verifies it on download. The container image is cosign-signed (Sigstore keyless) and ships an SPDX SBOM and SLSA build provenance, verifiable with cosign verify. It is closed source today, with source-available licensing planned.
Can Skarn provide a BSI C5 attestation or an EU Cloud Sovereignty Framework score?
Neither applies to Skarn, because both assess cloud services. BSI C5 sets the criteria a cloud service provider is attested against by an auditor, and the European Commission's Cloud Sovereignty Framework scores cloud services on data localisation, operational control, and legal jurisdiction. Skarn ships no cloud service: it is a binary that runs on your own machines and makes no network call by default. No Skarn cloud enters your assessment scope, so there is no attestation to request and no sovereignty score to check.

More for your team: CISO and CSO, Legal and DPO, CTO and VP Eng, Containers and CI

Request vendor documentation

We will provide the security and data-handling documentation your assessment process needs.

[email protected]