Trust & security

Where your keys and your data actually go.

A security platform asks for a lot of trust: a key to your cloud, and a copy of its weaknesses. Here is precisely how Skans stores the first, what it keeps of the second, and where both live.

Your credentials

Never stored in the clear.

The only secret Skans holds is the read-only API key you connect. It is encrypted by the application itself before it ever reaches the database — not left to the disk or the database engine.

  • AES-256-GCM, at the application layer

    Every credential is sealed with AES-256-GCM authenticated encryption before it is written. A copy of the database alone reveals nothing.

  • Versioned keys, rotated without interruption

    Encryption keys live in a versioned keyring: master keys are rotated and stored secrets re-encrypted with no downtime, and nothing to re-enter on your side.

  • Never shown again

    A secret key can be replaced or deleted, never read back: it does not appear in the interface, in API responses or in application logs.

Your data

Configuration, not content.

Skans reads how your cloud is configured — never what it contains. What it keeps is the security picture of your infrastructure, and that picture does not travel.

Metadata only

Your inventory, its configuration and the findings derived from them. Never the content of your buckets, databases or machines.

Hosted in France, under EU jurisdiction

The platform runs in France, on European infrastructure, operated under European law — outside the reach of the CLOUD Act and FISA.

Encrypted in transit

Every connection is TLS-encrypted — from your browser to Skans, and from Skans to your cloud provider’s API.

Never outside the EU

No subprocessor outside the EU. Your inventory and findings are not sent, mirrored or backed up outside the Union, for any reason.

National residency

When “in Europe” is not precise enough.

Some organisations need their data in one country — a German operator whose inventory must stay on German soil, a French one bound to French providers. On Enterprise, Skans deploys as a dedicated instance, in the country and on the European provider you designate. Your data shares its infrastructure with no one.

Talk to us about residency

Accounts & access

Held to the same standard.

The rigour Skans demands of your cloud applies to Skans accounts too.

Read-only, always

Skans works with read-only credentials and never needs write access to your cloud.

argon2id passwords, TOTP MFA

Passwords are hashed with argon2id at OWASP-aligned parameters, and two-factor authentication is built in.

Team roles

Access inside a workspace is scoped by role — an analyst and an owner do not hold the same rights.

Responsible disclosure

Found something? Tell us.

We publish a security.txt and read every report, in English or French.

security@skans.eu