Trust

Start here if you're reviewing us.

Skarn's own product is a local binary and a scoped licensing service - a small, low-data-access surface by design. This page indexes everything a security or procurement review typically asks for, and states plainly what does not exist.

Last updated 2026-09-18.

Architecture, in short

The scan runs entirely on the machine you install it on: session files are read from disk, matched against rules compiled into the binary, and reported locally - no scan or session content ever leaves the machine. The assessed surface for a vendor review is deliberately narrow - the CLI's own network footprint is two explicit, user-invoked commands (see the telemetry statement), and the licensing/billing portal (account.getskarn.com) is where a review should focus. See the sovereign and air-gapped page for the full architectural comparison against tethered alternatives.

Everything a review asks for

TopicWhere
What the binary sends over the network Telemetry statement - two commands call out, both explicit.
Checking our claims without trusting us Verify it yourself - the commands that would catch Skarn phoning home if it ever did, network-denied execution recipes, signature and checksum verification, and the two-line dependency inventory.
Third parties we use Third parties for the website, licensing, checkout and support - who they are, in which role, and what each one receives.
Reporting a security issue Vulnerability disclosure policy and security.txt (RFC 9116) at security@getskarn.com.
Who publishes Skarn Official channels and publisher identity - the canonical list of distribution channels and publisher accounts, and where to report an impostor. Anything not listed there is not ours.
Verifying the audit log yourself Audit export verification - the hash-chain construction and what it does and does not prove.
Running in an air-gapped network Air-gapped licensing - a term-length signed artifact, carried in, verified offline.
Security questionnaire (CAIQ / SIG Lite) Not published. Contact us to discuss the documentation available for your review.
Certifications, penetration test, status page None today. Skarn holds no ISO 27001 or SOC 2 certificate, has no penetration test report, and runs no public status page.

Why this page is this honest

A security review that finds a claim it cannot verify stops the deal, not just the claim. If something here goes stale, tell us: hello@getskarn.com.