Where your keys and your data actually go.
A security platform asks for a lot of trust: a key to your cloud, and a copy of its weaknesses. Here is precisely how Skans stores the first, what it keeps of the second, and where both live.
Never stored in the clear.
The only secret Skans holds is the read-only API key you connect. It is encrypted by the application itself before it ever reaches the database — not left to the disk or the database engine.
AES-256-GCM, at the application layer
Every credential is sealed with AES-256-GCM authenticated encryption before it is written. A copy of the database alone reveals nothing.
Versioned keys, rotated without interruption
Encryption keys live in a versioned keyring: master keys are rotated and stored secrets re-encrypted with no downtime, and nothing to re-enter on your side.
Never shown again
A secret key can be replaced or deleted, never read back: it does not appear in the interface, in API responses or in application logs.
Configuration, not content.
Skans reads how your cloud is configured — never what it contains. What it keeps is the security picture of your infrastructure, and that picture does not travel.
Metadata only
Your inventory, its configuration and the findings derived from them. Never the content of your buckets, databases or machines.
Hosted in France, under EU jurisdiction
The platform runs in France, on European infrastructure, operated under European law — outside the reach of the CLOUD Act and FISA.
Encrypted in transit
Every connection is TLS-encrypted — from your browser to Skans, and from Skans to your cloud provider’s API.
Never outside the EU
No subprocessor outside the EU. Your inventory and findings are not sent, mirrored or backed up outside the Union, for any reason.
When “in Europe” is not precise enough.
Some organisations need their data in one country — a German operator whose inventory must stay on German soil, a French one bound to French providers. On Enterprise, Skans deploys as a dedicated instance, in the country and on the European provider you designate. Your data shares its infrastructure with no one.
Talk to us about residencyHeld to the same standard.
The rigour Skans demands of your cloud applies to Skans accounts too.
Read-only, always
Skans works with read-only credentials and never needs write access to your cloud.
argon2id passwords, TOTP MFA
Passwords are hashed with argon2id at OWASP-aligned parameters, and two-factor authentication is built in.
Team roles
Access inside a workspace is scoped by role — an analyst and an owner do not hold the same rights.
Found something? Tell us.
We publish a security.txt and read every report, in English or French.
security@skans.eu