Legal / DPO / Compliance

Nothing leaves the machine. No exceptions by default.

Skarn is built from first principles for regulated, EU data-residency environments. No personal data, no source code, and no credentials are transmitted to any external party. Your most likely objections are answered by the architecture itself - before you review a contract.

Regulatory compliance, law by law

GDPR - Regulation (EU) 2016/679

Skarn processes data exclusively on the local machine. No personal data is transferred to Skarn or any third party - there is no Skarn cloud service, no telemetry, and no vendor access. Because no personal data goes to an external processor, no Article 28 Data Processing Agreement is required. Local reports contain masked credentials only and stay on your own infrastructure.

NIS-2 - Directive (EU) 2022/2555

Article 21 requires active cybersecurity risk management and documented evidence of its effectiveness; Skarn's SARIF and JSON output provides that audit trail. Article 20 places direct personal accountability on management-body members for approving and overseeing these measures.

DORA - Regulation (EU) 2022/2554 (financial entities)

Enforceable since 17 January 2025. Article 5 makes the management body's ownership of the ICT risk framework non-delegable; Article 8 requires identification of ICT vulnerabilities - AI session credential exposure is squarely in scope.

EU AI Act - Regulation (EU) 2024/1689

Skarn uses rule-based, pattern-matching detection. It is not an AI system under the Act's definition, makes no consequential decisions, and falls in no prohibited or high-risk category. It monitors AI tools used by humans; it is not itself in scope, and no obligations apply to it.

CRA - Regulation (EU) 2024/2847

From 11 September 2026 (Art 69(3), Art 71(2)), a software manufacturer must report severe incidents and actively-exploited vulnerabilities on a 24-hour early-warning and 72-hour notification cadence (Article 14), exercise due diligence over third-party components (Article 13(5)), and compile technical documentation (Annex VII). Skarn supplies development-process evidence supporting these duties: redacted AI-session credential and behavioural findings for the confidentiality and secure-development requirements (Art 13(2); Annex I Part I), session-observed dependency and malicious-package context for third-party due diligence (Art 13(5)), and a hash-chained audit record (when audit logging is enabled) as possible supporting evidence within the technical documentation (Annex VII) - not a conformity assessment and not a claim that a product is compliant.

National criminal provisions under NIS-2 and DORA transposition vary by member state and can reach individuals; that is a matter for counsel, not architecture. By operating entirely on-premise, Skarn reduces your organisation's regulatory exposure on this surface.

Data handling, factual summary

ItemStatus
Data transferred to vendorNone, ever
Cloud infrastructure dependencyNone
Third-party sub-processorsNone
GDPR Art. 28 DPA requiredNot required
Cross-border data transferNone
Credentials shown in plaintext in reportsNever - always masked
Telemetry or usage dataNone
Optional online checksOpt-in only - off by default

More for your team: CISO and CSO, CEO and Board, Procurement

Request a compliance briefing

We will walk Legal and the DPO through the architecture and the data-handling position, document by document.

hello@getskarn.com