Trust

Start here if you're reviewing us.

Skarn's own product is a local binary and a scoped licensing service - a small, low-data-access surface by design. This page indexes everything a security or procurement review typically asks for, and states plainly where we are still building the rest.

Last updated 2026-07-20.

Architecture, in short

The scan runs entirely on the machine you install it on: session files are read from disk, matched against rules compiled into the binary, and reported locally - no scan or session content ever leaves the machine. The assessed surface for a vendor review is deliberately narrow - the CLI's own network footprint is two explicit, user-invoked commands (see the telemetry statement), and the licensing/billing portal (account.getskarn.com) is where a review should focus.

Everything a review asks for

TopicWhere
What the binary sends over the network Telemetry statement - source-verified, updated at every release that touches network code. Two commands call out, both explicit.
Checking our claims without trusting us Verify it yourself - the commands that would catch Skarn phoning home if it ever did, network-denied execution recipes, signature and checksum verification, and the two-line dependency inventory.
Who processes portal data Subprocessor list - dated and versioned, notified under the DPA before any addition.
Reporting a security issue Vulnerability disclosure policy and security.txt (RFC 9116) at [email protected].
Verifying the audit log yourself Audit export verification - the hash-chain construction and what it does and does not prove.
Running in an air-gapped network Air-gapped licensing - a term-length signed artifact, carried in, verified offline.
Service status Status page: in progress, not yet live. Until then, report a suspected outage to [email protected].
Data Processing Agreement (GDPR, EU SCCs) In legal review, not yet published for self-serve download. Request the current draft at [email protected]; a Team or Enterprise agreement is not blocked on this page.
Security questionnaire (CAIQ / SIG Lite) Pre-filled internally; not yet published. Ask your account contact and we return it within a business day.
Penetration test Not yet performed. Annual third-party penetration testing of the portal is planned; a summary will be linked from this page once complete.
Certification (ISO 27001 / SOC 2) Not yet started. We are scoping an ISO 27001 program (the standard EU/Big-4 ask) ahead of SOC 2. This line will say "in progress," with a target date, only once a certification body engagement actually exists - not before.
Insurance (Tech E&O / cyber) In procurement. Details available on request once bound.

Why this page is this honest

A security review that finds a claim it cannot verify stops the deal, not just the claim. Every "not yet" above is a real status, not a placeholder we forgot to fill in - and every line that does claim something (the telemetry statement above all) is checked against the source that ships, not written from memory. If something here goes stale, tell us: [email protected].