Sovereign and air-gapped
Every control on this surface needs something first. Skarn needs a machine.
An account. A detection server. A commercial-cloud tenant. An eligible plan. Each of the four is a precondition the vendor states in its own documentation, and each one is what rules the product out of an air-gapped network, a sovereign cloud, or a public-sector estate.
In one line: Skarn reads the AI coding sessions on the machine that wrote them, with no server in the detection path, no tenant, and no network call by default - the free license is a file, verified offline, that an air-gapped machine never fetches itself - so the environments that disqualify the alternatives by their own prerequisites are the environments it was built for.
Incumbent claims current as of 2026-09-02. Every cell below quotes that vendor's own documentation and links to it; see methodology and sources.
The four tethers
Architectural and deployment properties only - what each control requires before it can run, quoted from the vendor. Not detection-accuracy benchmarks.
| What it needs first | The vendor's own documentation | Skarn |
|---|---|---|
| A vendor account | GitGuardian Developer Endpoint Protection. The stated prerequisite is "a GitGuardian business account with Endpoint Protection enabled," and the enrolled machine "shows up under Endpoint protection - Endpoints in the GitGuardian dashboard" (GitGuardian docs, 2026-07-29) | No vendor dashboard enrolment or runtime dependency. skarn assess needs no license at all and
runs on a machine that has never contacted us; skarn check uses a free license file, a one-time fetch you can carry into an air-gapped network, verified offline |
| A detection server | The core ggshield engine. "ggshield relies on the GitGuardian API to perform secret scanning," and the pre-commit hook "requires an API key to work." A self-hosted instance is selectable, and detection still routes through a GitGuardian API endpoint (GitGuardian docs, 2026-07-24, 2026-07-24) | The engine is in the binary. No network call by default; --offline
disables all network access outright |
| A commercial-cloud tenant | Microsoft Defender for Endpoint, local AI agent discovery (Preview). "Your environment is in the commercial cloud. Sovereign and national clouds aren't supported." It also requires "a Microsoft Defender for Endpoint Plan 2, Microsoft 365 E5, Microsoft Agent 365, or Microsoft 365 E7 license," devices onboarded to Defender, and the Microsoft Defender portal to read the result (Microsoft Learn, 2026-05-27) | No tenant, no portal, no onboarding. The report is a local file you keep - text, JSON, or SARIF 2.1.0 for the SIEM you already run |
| An eligible plan | Anthropic's Claude Compliance API. "The Compliance API is available to Enterprise plan organizations, excluding Public Sector organizations, and to Claude Platform customers in Claude chats" (Anthropic support, fetched 2026-09-02), and its content endpoints, session transcripts included, "serve Claude Enterprise data only" (Anthropic docs, 2026-09-02) | No eligibility list. The free core is the whole engine, and a public-sector team runs the same binary as everyone else |
Preconditions as documented by each vendor, current as of 2026-09-02. Every cell links to that vendor's own dated source. Microsoft's local AI agent discovery is a Preview product and is dated as such.
What these products do, in their own words
The tether is the precondition. Here is what each product does, from the same sources.
Developer Endpoint Protection states that "all scanning happens locally on the endpoint" and that "only structured metadata leaves the endpoint," across AI tool directories and log files (GitGuardian, 2026-06-16). The tether is the account and the dashboard, not the scan location.
AI agent runtime protection inspects "user prompts, tool requests before execution, and tool responses after execution" and can "audit or block activity at each supported event point" on Claude Code, Codex CLI, and GitHub Copilot (Microsoft Learn, 2026-05-27, Preview). The tether is the tenant, the licence, and - for local agent discovery - the commercial cloud.
Every prompt and tool call is "scanned and validated before the AI model processes it" (Palo Alto, 2025-11-19). That is a deployment choice, not an omission, and it is a different moment in the timeline than an audit of what already accumulated on disk.
Skarn's side, stated as negatives
Each of these is a present-tense property of the binary you can run today.
The core scanner costs nothing, under a free license anyone can register for: all 251 detection rules, attack-chain correlation, the 0-100 session risk score, enforced redaction, and every output format. No trial window, no seat count, no card. Pro adds the paid controls - policy, baselines with per-entry provenance, audit evidence, and guard enforcement - and Team the organization around them.
No workspace and no endpoint enrolling
into a vendor console. skarn assess scans every AI session on the machine with no account and
no license; skarn check uses a free license file, fetched once and verified offline - an air-gapped machine never fetches it itself.
It scans locally and makes no network
connection by default. Two commands transmit anything off the machine, and only when you run them:
the optional signed rule-feed fetch and skarn license renew. No session content or
secret the scan finds leaves the machine, and --offline disables all network access. skarn serve binds to 127.0.0.1.
An incomplete scan does not have to report
green: --fail-on-scan-error exits non-zero when a source errored out of discovery or a
session failed to parse, so a pipeline can refuse a scan that could not read everything.
One binary, one data path. The same engine audits the sessions already on disk across 13 assistants and backs the real-time pre-execution guard hook on 9 of them. There is no second product and no second place your session content can go.
The frameworks a regulated EU buyer names
Each mapped to a capability. Skarn produces evidence; your organisation owns the obligation.
C5 sets the criteria a cloud service provider is attested against by an auditor. The scan runs on your machine and makes no network call when it scans.
The European Commission's framework scores cloud services on data localisation, operational control, and legal jurisdiction. It does not score the scan, which runs on your machine and makes no network call when it scans.
The umbrella law asks operators of critical installations to document their resilience measures. Skarn's contribution is evidence: a local, auditable record of what AI coding sessions exposed, produced without anything leaving the operator's machines.
NIS-2 asks organisations to manage their cyber risk, including the security of how they develop software. Skarn produces documented SARIF 2.1.0 evidence of AI-session scanning, crosswalked to MITRE ATLAS and the OWASP Top 10 for LLM Applications 2025.
DORA asks financial entities to identify the weaknesses in their ICT systems. Credentials leaking through AI coding tools are one of them, and you can evidence it rather than assume it.
The AI Act sets rules for AI systems and the records
kept about them. Where you keep a record that AI activity is monitored,
--audit-log (Pro) appends a hash-chained record of each scan - timestamp, policy,
finding counts, verdict, no secrets - and detects in-place edits and reordering of that
history.
Methodology and sources
We compare only on the architectural and deployment axis - what a control requires before it runs, where it runs, and what egress it needs - because those properties are structural to each product's design. Every precondition above is quoted from the named vendor's own dated source.
- GitGuardian Developer Endpoint Protection prerequisites (business account, dashboard enrolment, workspace or self-hosted instance): docs.gitguardian.com, last updated 2026-07-29.
- GitGuardian Developer Endpoint Protection scan location (local scan, metadata-only egress): blog.gitguardian.com, published 2026-06-16.
- GitGuardian core ggshield engine cloud-API dependency: docs.gitguardian.com, last updated 2026-07-24, and the pre-commit hook API-key requirement, last updated 2026-07-24.
- Microsoft Defender for Endpoint, local AI agent discovery (commercial cloud only, licence, portal, discovery scope): learn.microsoft.com, Preview, 2026-05-27.
- Microsoft Defender for Endpoint, AI agent runtime protection (local inspection and blocking at agent hook points): learn.microsoft.com, Preview, 2026-05-27.
- Palo Alto Prisma AIRS inline interception for Claude Code: paloaltonetworks.com, published 2025-11-19.
- Anthropic Compliance API eligibility (Enterprise plan organizations, excluding Public Sector organizations, and Claude Platform customers in Claude chats): support.claude.com, fetched 2026-09-02; content scope (Claude Enterprise data only): platform.claude.com, fetched 2026-09-02.
- BSI C5 criteria catalogue (criteria for cloud service providers, auditor attestation to ISAE 3000): bsi.bund.de, fetched 2026-07-12.
- European Commission Cloud Sovereignty Framework (sovereignty objectives, SEAL levels, sovereignty score): commission.europa.eu, published 2025-10-20.
- KRITIS-Dachgesetz (physical resilience of critical installations): gesetze-im-internet.de, fetched 2026-07-12.
- Skarn architectural claims (local-first, no egress by default, offline flag, audit log, guard hook): the Skarn manual and the editions boundary, as of 2026-07-12.
Attribution and scope: GitGuardian's Endpoint Protection does scan locally, and Microsoft Defender does inspect and block locally at agent hook points - neither is claimed otherwise here, and the cells above are about preconditions, not capabilities. Microsoft's commercial-cloud prerequisite is documented for local AI agent discovery specifically, and both Defender capabilities are in Preview. The Prisma AIRS cell is a deployment-model contrast, not a missing feature. Each vendor may change any of this at any time; every claim is dated so you can check it against the source.
Run it on one machine, with the network unplugged
A 30-minute live demo of the scanner on a developer's machine, run with you. Nothing leaves the laptop: you watch it run and keep the redacted report.
Runs on macOS, Windows, and Linux, on both Intel and ARM.