Legal / DPO / Compliance

Nothing the scan reads leaves the machine.

Skarn is built from first principles for regulated environments. The scan sends no personal data, no source code, and no credentials to any external party. Your most likely objections are answered by the architecture itself - before you review a contract.

The regulations, by purpose

Session content

The scan processes session content only on your machine and sends none of it to Skarn or any third party. Its reports mask every credential they show and stay on your own infrastructure. The privacy policy describes the account, license and payment data Skarn does hold.

NIS-2

NIS-2 asks organisations to manage their cyber risk, to show that the measures work, and it holds management accountable for them. Skarn's SARIF and JSON output is a record of what AI coding sessions exposed and that someone checked.

DORA

DORA asks financial entities to own their ICT risk and to identify the weaknesses in their systems. Credentials exposed in AI coding sessions are one such weakness, and Skarn finds them.

EU AI Act

The AI Act sets rules for AI systems and the organisations that use them. Where you keep a record that AI activity is monitored, --audit-log (Pro) appends a hash-chained record of each scan: timestamp, policy, finding counts, verdict, no secrets.

Cyber Resilience Act

The CRA asks software manufacturers to develop securely, to take care over the components they ship, and to report serious incidents. Skarn supplies development-process evidence for those duties: redacted findings from AI coding sessions, dependency context those sessions observed, and a hash-chained audit record when audit logging is on. It is not a conformity assessment and not a claim that a product is compliant.

Data handling, factual summary

ItemStatus
Scan content sent to SkarnNone. Account, license and payment data are described in the privacy policy
Cloud dependency for the scanNone
Credentials shown in plaintext in reportsNever - always masked
Telemetry or usage dataNone from the scanner. Website analytics and portal records are described in the privacy policy
Data processing agreement for the portalPublished at getskarn.com/terms/dpa/; takes effect with a Team or Enterprise order
Optional online checksOpt-in only - off by default

More for your team: CISO and CSO, CEO and Board, Procurement

Book a live demo

A 30-minute live demo for Legal and the DPO: the architecture and the data-handling position, document by document.

hello@getskarn.com