Procurement / Vendor assessment

The smallest possible vendor footprint. By design.

Skarn is built to pass vendor security assessments in regulated environments. The scan runs on your machines, sends Skarn nothing it reads, and does not depend on Skarn's infrastructure to operate. Most standard vendor-assessment questions answer themselves.

Skarn is the local-first, no-egress forensic layer for the AI-session surface the inline and cloud tools disclaim: local-disk session content, MCP and tool-call detail, and post-hoc attack-chain reconstruction with a session risk score.

Vendor assessment quick reference

QuestionAnswer
Scan deploymentOn-premise only; the licensing portal and checkout are hosted (third parties)
Vendor / publisher identitySkarn Software OÜ, Tallinn, Estonia (registry code 17585335)
Artifact integrityWindows binaries Authenticode-signed (Azure Artifact Signing, Skarn Software OÜ); every release asset sha256-pinned and verified by the Homebrew formula; multi-arch container image cosign-signed (Sigstore) with SBOM + SLSA provenance
Scan content sent to SkarnNone. Account, license and payment data are described in the privacy policy
Vendor access to customer environmentNone
Data processing agreement for the portalPublished at getskarn.com/terms/dpa/; takes effect with a Team or Enterprise order
Telemetry / usage data collectedNone from the scanner. Website analytics and portal records are described in the privacy policy
Internet connectivity required to scanNone; two explicit commands call out when you run them
Supported operating systemsWindows, macOS, Linux (Intel + ARM)
Standards / framework alignmentMITRE ATLAS, OWASP LLM Top 10 2025, CWE (SARIF)
Source code modelClosed source
Availability dependency for the scanNone - self-contained binary
The scan binary either works on your machine or it does not - independent of any vendor system.

The regulations your assessment asks about

NIS-2

NIS-2 asks organisations to manage the cyber risk in their own systems. Skarn's findings show what AI coding sessions on those systems exposed and that someone checked.

DORA

DORA asks financial entities to identify the weaknesses in their ICT systems. Skarn identifies the credentials and risky actions that AI coding sessions leave on developer machines.

EU AI Act

The AI Act sets rules for AI systems and the records kept about them. Where you keep a record that AI activity is monitored, --audit-log (Pro) appends a hash-chained local record of each scan - timestamp, policy, finding counts, verdict, no secrets - and detects edits and reordering of that history.

BSI C5 and the EU Cloud Sovereignty Framework

Both assess cloud services. The scan runs on your own machines and makes no network call when it scans.

KRITIS-Dachgesetz

The umbrella law asks operators of critical installations to document their resilience measures. Skarn contributes a local, auditable record of what AI coding sessions exposed, produced without anything leaving your machines.

Vendor assessment questions

Does the scan depend on a Skarn cloud service?
No. The scan is a self-contained binary that runs on your own machines, makes no network call when it scans, and sends Skarn no session content. Account, license and payment data are described in the privacy policy.
What is the provenance and code signing of Skarn?
Skarn is published by Skarn Software OÜ. The Homebrew formula pins each platform's release asset by sha256 and verifies it on download. The container image is cosign-signed (Sigstore keyless) and ships an SPDX SBOM and SLSA build provenance, verifiable with cosign verify.
Can Skarn provide a BSI C5 attestation or an EU Cloud Sovereignty Framework score?
Both assess cloud services. BSI C5 sets the criteria a cloud service provider is attested against by an auditor, and the European Commission's Cloud Sovereignty Framework scores cloud services on data localisation, operational control, and legal jurisdiction. The scan runs on your own machines and makes no network call when it scans.

More for your team: CISO and CSO, Legal and DPO, CTO and VP Eng, Containers and CI, Sovereign and air-gapped

Request vendor documentation

Contact us to discuss the documentation available for your review.

hello@getskarn.com