Trust
Start here if you're reviewing us.
Skarn's own product is a local binary and a scoped licensing service - a small, low-data-access surface by design. This page indexes everything a security or procurement review typically asks for, and states plainly what does not exist.
Last updated 2026-09-18.
Architecture, in short
The scan runs entirely on the machine you install it on: session files are read from disk, matched against rules compiled into the binary, and reported locally - no scan or session content ever leaves the machine. The assessed surface for a vendor review is deliberately narrow - the CLI's own network footprint is two explicit, user-invoked commands (see the telemetry statement), and the licensing/billing portal (account.getskarn.com) is where a review should focus. See the sovereign and air-gapped page for the full architectural comparison against tethered alternatives.
Everything a review asks for
| Topic | Where |
|---|---|
| What the binary sends over the network | Telemetry statement - two commands call out, both explicit. |
| Checking our claims without trusting us | Verify it yourself - the commands that would catch Skarn phoning home if it ever did, network-denied execution recipes, signature and checksum verification, and the two-line dependency inventory. |
| Third parties we use | Third parties for the website, licensing, checkout and support - who they are, in which role, and what each one receives. |
| Reporting a security issue | Vulnerability disclosure policy and security.txt (RFC 9116) at security@getskarn.com. |
| Who publishes Skarn | Official channels and publisher identity - the canonical list of distribution channels and publisher accounts, and where to report an impostor. Anything not listed there is not ours. |
| Verifying the audit log yourself | Audit export verification - the hash-chain construction and what it does and does not prove. |
| Running in an air-gapped network | Air-gapped licensing - a term-length signed artifact, carried in, verified offline. |
| Security questionnaire (CAIQ / SIG Lite) | Not published. Contact us to discuss the documentation available for your review. |
| Certifications, penetration test, status page | None today. Skarn holds no ISO 27001 or SOC 2 certificate, has no penetration test report, and runs no public status page. |
Why this page is this honest
A security review that finds a claim it cannot verify stops the deal, not just the claim. If something here goes stale, tell us: hello@getskarn.com.