Procurement / Vendor assessment
The smallest possible vendor footprint. By design.
Skarn is built to pass vendor security assessments in regulated environments. The scan runs on your machines, sends Skarn nothing it reads, and does not depend on Skarn's infrastructure to operate. Most standard vendor-assessment questions answer themselves.
Skarn is the local-first, no-egress forensic layer for the AI-session surface the inline and cloud tools disclaim: local-disk session content, MCP and tool-call detail, and post-hoc attack-chain reconstruction with a session risk score.
Vendor assessment quick reference
| Question | Answer |
|---|---|
| Scan deployment | On-premise only; the licensing portal and checkout are hosted (third parties) |
| Vendor / publisher identity | Skarn Software OÜ, Tallinn, Estonia (registry code 17585335) |
| Artifact integrity | Windows binaries Authenticode-signed (Azure Artifact Signing, Skarn Software OÜ); every release asset sha256-pinned and verified by the Homebrew formula; multi-arch container image cosign-signed (Sigstore) with SBOM + SLSA provenance |
| Scan content sent to Skarn | None. Account, license and payment data are described in the privacy policy |
| Vendor access to customer environment | None |
| Data processing agreement for the portal | Published at getskarn.com/terms/dpa/; takes effect with a Team or Enterprise order |
| Telemetry / usage data collected | None from the scanner. Website analytics and portal records are described in the privacy policy |
| Internet connectivity required to scan | None; two explicit commands call out when you run them |
| Supported operating systems | Windows, macOS, Linux (Intel + ARM) |
| Standards / framework alignment | MITRE ATLAS, OWASP LLM Top 10 2025, CWE (SARIF) |
| Source code model | Closed source |
| Availability dependency for the scan | None - self-contained binary |
The regulations your assessment asks about
NIS-2 asks organisations to manage the cyber risk in their own systems. Skarn's findings show what AI coding sessions on those systems exposed and that someone checked.
DORA asks financial entities to identify the weaknesses in their ICT systems. Skarn identifies the credentials and risky actions that AI coding sessions leave on developer machines.
The AI Act sets rules for AI systems and the records kept about them. Where you keep a record that AI activity is monitored, --audit-log (Pro) appends a hash-chained local record of each scan - timestamp, policy, finding counts, verdict, no secrets - and detects edits and reordering of that history.
Both assess cloud services. The scan runs on your own machines and makes no network call when it scans.
The umbrella law asks operators of critical installations to document their resilience measures. Skarn contributes a local, auditable record of what AI coding sessions exposed, produced without anything leaving your machines.
Vendor assessment questions
- Does the scan depend on a Skarn cloud service?
- No. The scan is a self-contained binary that runs on your own machines, makes no network call when it scans, and sends Skarn no session content. Account, license and payment data are described in the privacy policy.
- What is the provenance and code signing of Skarn?
- Skarn is published by Skarn Software OÜ. The Homebrew formula pins each platform's release asset by sha256 and verifies it on download. The container image is cosign-signed (Sigstore keyless) and ships an SPDX SBOM and SLSA build provenance, verifiable with cosign verify.
- Can Skarn provide a BSI C5 attestation or an EU Cloud Sovereignty Framework score?
- Both assess cloud services. BSI C5 sets the criteria a cloud service provider is attested against by an auditor, and the European Commission's Cloud Sovereignty Framework scores cloud services on data localisation, operational control, and legal jurisdiction. The scan runs on your own machines and makes no network call when it scans.
More for your team: CISO and CSO, Legal and DPO, CTO and VP Eng, Containers and CI, Sovereign and air-gapped
Request vendor documentation
Contact us to discuss the documentation available for your review.