In practice today: data residency on AWS European Sovereign Cloud as the default, agent boundaries, secure SDLC, SBOM, SLSA build provenance and signed images. Dated next: customer-managed keys and data classification in Q3 2026, independent penetration test in Q4 2026, and ISO 27001 certification targeted for Q3 2027.
AWS European Sovereign Cloud (Brandenburg, DE), other regions on request
Live in production, design partners welcome
Customer-managed keys · data classification · Q3 2026
Skansar runs today on AWS European Sovereign Cloud in Germany, operated by EU residents under an EU parent company, and that is the default. If you need another jurisdiction, we deploy into your own AWS account in that region. Your supplier lists and documents are never moved somewhere you did not pick.
Skansar reads the records you connect and writes nothing back to your systems. Connections are read-only by default, and any exception stays switched off until you turn it on.
Each company's data is fully isolated. Nothing you connect is visible to any other supplier, buyer or competitor on the platform.
You can export everything in open formats and walk away, with no lock-in and no exit fee. Customer-managed encryption keys, so you hold and can revoke your own key material, arrive in Q3 2026.
The full security and compliance detail a procurement review needs is below.
Regulated buyers do not buy on claims. This section documents the security posture, deployment options, integration boundaries, audit-pack anatomy, proof points and exit terms a procurement and security review will ask for.
Agents act inside Skansar. They never write to your source systems, and no regulator-bound figure is submitted without human approval. Deterministic calculations produce every compliance figure; agents analyse, prioritise and explain.
Every change gates on TypeScript, unit + regression tests, ESLint, Lighthouse and a11y checks in CI. Static analysis via CodeQL, secret scanning via gitleaks, and OSV vulnerability scanning via osv-scanner on every push. Production dependency npm audit high-severity gate. Dependabot on. Deploy to a protected AWS environment via GitHub OIDC federation, no long-lived AWS keys in the repo. Production access limited to founders.
CycloneDX Software Bill of Materials produced by BuildKit at build time and attached to every ECR image as an OCI attestation, plus uploaded as a CI artefact per release. Covers all runtime dependencies with licence and vulnerability posture. Consumers verify with cosign download attestation; shared under NDA on request.
Every image carries a SLSA mode=max build provenance attestation identifying the exact workflow run and commit that built it. Attached to the ECR image manifest and readable via docker buildx imagetools inspect or cosign download attestation, answering "what is in the image and who built it" as verifiable evidence, not a trust assertion.
Every image is signed via Sigstore keyless flow, bound to the CI workflow OIDC identity. Signatures attach to the image in ECR and are recorded to Rekor public transparency log, so forgeries are publicly detectable. Zero key material stored in AWS, GitHub, or the repo. KMS-backed signing keys planned for customer-controlled roots of trust.
BYOK for data at rest. Key rotation, revocation and shred-on-exit under customer control.
Customer source records, derived evidence and audit logs classified separately. Retention, access and export controls applied per class.
Independent third-party penetration test before first paid customer. Summary report shared under NDA.
Certification targeted for Q3 2027. Controls being implemented and operated in advance of the audit.
Residency is your choice. Running today, and the default, is AWS European Sovereign Cloud: physically and logically separate from AWS global regions, operated by EU residents, governed by an EU parent entity. Other jurisdictions are delivered through a customer-managed AWS account in the region you need.
| OPTION | RESIDENCY | AVAILABILITY |
|---|---|---|
| AWS European Sovereign Cloud | Brandenburg, DE | LIVE |
| Additional ESC regions | Belgium, Netherlands, Portugal (via AWS Local Zones) | Follows AWS rollout |
| Customer VPC, EU | Customer-managed EU AWS account | Design partner |
| Customer VPC, United States | Customer-managed US AWS account | On request |
| Customer VPC, Gulf | Customer-managed AWS account (UAE, KSA) | On request |
| Customer VPC, Asia-Pacific | Customer-managed APAC AWS account | On request |
| On-premise / Air-gapped | Customer or classified environments | On request |
First connector: SAP S/4HANA, in active development. Additional ERP, PLM, MES and supplier portal connectors will be added based on design partner demand. Read-only by default. Write boundaries are explicit, documented per connector, and disabled until the customer authorises them.
Target architecture: every figure traces back to a source record through a six-step lifecycle, source record → calculation → exception → approval → submission → replay. We are working through the EDIP methodology with our pilot programme. Initial scope is EDIP origin evidence; additional regulatory templates will be added as customer engagement defines them.
Cyber patch SLA: Security patches applied within 14 days of vendor release for all runtime dependencies.
Customer retains ownership of all source records and derived evidence. Skansar processes data under a DPA aligned with EU GDPR and customer security requirements.
Full export of source records, evidence graph and audit pack in open formats on request. No lock-in clauses. Decryption keys will be retained by the customer under BYOK once customer-managed keys ship in Q3 2026.
Source code escrow available for enterprise contracts. Triggered release on defined continuity events.
Customer can continue to read and verify their audit pack independently of Skansar via the published verification specification.