Trust
Start here if you're reviewing us.
Skarn's own product is a local binary and a scoped licensing service - a small, low-data-access surface by design. This page indexes everything a security or procurement review typically asks for, and states plainly where we are still building the rest.
Last updated 2026-07-20.
Architecture, in short
The scan runs entirely on the machine you install it on: session files are read from disk, matched against rules compiled into the binary, and reported locally - no scan or session content ever leaves the machine. The assessed surface for a vendor review is deliberately narrow - the CLI's own network footprint is two explicit, user-invoked commands (see the telemetry statement), and the licensing/billing portal (account.getskarn.com) is where a review should focus.
Everything a review asks for
| Topic | Where |
|---|---|
| What the binary sends over the network | Telemetry statement - source-verified, updated at every release that touches network code. Two commands call out, both explicit. |
| Checking our claims without trusting us | Verify it yourself - the commands that would catch Skarn phoning home if it ever did, network-denied execution recipes, signature and checksum verification, and the two-line dependency inventory. |
| Who processes portal data | Subprocessor list - dated and versioned, notified under the DPA before any addition. |
| Reporting a security issue | Vulnerability disclosure policy and security.txt (RFC 9116) at [email protected]. |
| Verifying the audit log yourself | Audit export verification - the hash-chain construction and what it does and does not prove. |
| Running in an air-gapped network | Air-gapped licensing - a term-length signed artifact, carried in, verified offline. |
| Service status | Status page: in progress, not yet live. Until then, report a suspected outage to [email protected]. |
| Data Processing Agreement (GDPR, EU SCCs) | In legal review, not yet published for self-serve download. Request the current draft at [email protected]; a Team or Enterprise agreement is not blocked on this page. |
| Security questionnaire (CAIQ / SIG Lite) | Pre-filled internally; not yet published. Ask your account contact and we return it within a business day. |
| Penetration test | Not yet performed. Annual third-party penetration testing of the portal is planned; a summary will be linked from this page once complete. |
| Certification (ISO 27001 / SOC 2) | Not yet started. We are scoping an ISO 27001 program (the standard EU/Big-4 ask) ahead of SOC 2. This line will say "in progress," with a target date, only once a certification body engagement actually exists - not before. |
| Insurance (Tech E&O / cyber) | In procurement. Details available on request once bound. |
Why this page is this honest
A security review that finds a claim it cannot verify stops the deal, not just the claim. Every "not yet" above is a real status, not a placeholder we forgot to fill in - and every line that does claim something (the telemetry statement above all) is checked against the source that ships, not written from memory. If something here goes stale, tell us: [email protected].