Every third party that touches your data, and why.
This list covers account.getskarn.com (the licensing/billing portal), the license service API, and getskarn.com itself. It does not cover the offline scan itself: skarn check, assess, and every other command run on your machine with no subprocessor in the path, except the two commands that make an explicit outbound call on their own - skarn check --update-rules and skarn license renew. By default both reach getskarn.com's own infrastructure (Cloudflare, listed below), not a third-party subprocessor. Both destinations are also configurable (--feed-url and $SKARN_LICENSE_RENEW_URL) for a customer's own proxy or self-hosted setup - a configured override is your own infrastructure, not ours, and is outside the scope of this list. See the telemetry statement for the exact list.
List version 1, published 2026-07-17. We will version and date every change here, and notify subscribers under the Data Processing Agreement before adding a new subprocessor.
| Subprocessor | Purpose | Data | Location |
|---|---|---|---|
| Cloudflare | Hosting for getskarn.com and account.getskarn.com (Workers), the licensing database (D1), backup storage (R2), DNS, and inbound email routing/forwarding. | All portal data in transit and at rest: account, member, order, and audit records. No scan or session content ever reaches this layer - the license service holds none. | Cloudflare's global network. D1 and R2 support an EU jurisdiction/location hint; DNS resolution and Workers compute route to Cloudflare's nearest edge location by design and are not region-locked. We do not represent this as a blanket EU-residency guarantee across every one of these services - ask us for the current configuration if EU data residency is a hard requirement for you. |
| Amazon Web Services (eu-central-1) | Custody of the production Ed25519 license-signing key in AWS KMS, and CloudTrail logging of every use of that key. This account holds nothing else - no application data, no database, no compute beyond the signing call. | None of your data. The signing key itself, and an immutable log of sign operations (key ARN, caller identity, timestamp - never the plaintext being signed). | eu-central-1 (Frankfurt) - a single-region account by design, verifiably so since it holds nothing else. |
| Paddle.com Market Limited | Merchant of record for Team and Enterprise subscriptions: checkout, invoicing, tax handling, and payment processing. | Billing and payment data, including card details. Card data never reaches Skarn's own systems at any point - Paddle holds it as the merchant of record. | Paddle's own infrastructure; see Paddle's published subprocessor list for its downstream processors. |
| SMTP2GO | Transactional email delivery: magic-link sign-in, license issuance notices, invite emails, account notifications. | Recipient email address and message content. Every email is built from a fixed template, not from arbitrary account data, so a license token or a scan finding is never a value that can land in a message body. | EU sending infrastructure (mail-eu.smtp2go.com). |
No other subprocessor currently processes data on our behalf. WorkOS (single sign-on and directory sync) is planned for Enterprise customers who request it but is not active for any customer today; it will be added to this table, dated and versioned, only once a customer actually activates it - not before. If that or anything else above changes, this page's version and date change with it, and customers under the Data Processing Agreement are notified per its terms before the new subprocessor goes live.
What's never on this list
Nothing here processes AI coding-session content, scan findings, or secrets - the license service is scoped to licensing, identity, and billing metadata only, and the scan itself runs on your machine with no subprocessor in the path. See the telemetry statement for the exhaustive, source-verified list of what the binary sends and to whom.