Security & trust

How we keep your trust data safe

SkyQon is a security product, so we hold ourselves to the same bar we measure you against. Here is exactly how the service is built, where your data lives, and how to reach us if you find a problem.

Data residency — everything stays in the EU

SkyQon is built, hosted and operated in the European Union. The application and its database run on infrastructure in Germany; the marketing site and lead handling run on EU hosting. Your account data, scan history and evidence never leave the EU.

External by default

SkyQon scans your domains the same way an attacker, a mailbox provider or a browser would: from the outside. We only ever read what is already publicly observable — DNS records, published certificates, TLS configuration and mail-authentication policy. Monitoring needs no software on your systems, no credentials and no inbound access, so nothing we run can reach inside your network.

What the optional agents can and cannot do

Two optional add-ons run software on your own hosts, so “no agent” would be the wrong claim to make without qualification. An internal discovery agent (Linux, plus a Windows build for AD CS) inventories certificates and keys that never appear on a public socket, and the Certificate Auto-Renew agent renews certificates in place. You install them yourself, only if you take those add-ons, and their scope is deliberately narrow:

  • Outbound only. The agent opens every connection to us. SkyQon never connects in, and you never open a port for it.
  • Metadata, not secrets. Discovery reports algorithm, key type and size, fingerprint, validity window, subject and issuer — never a private key, never key material, never your traffic.
  • Your keys stay yours. Auto-Renew drives the ACME client you already run; the private key is generated on your host and never leaves it. Only the public certificate chain comes back to us.
  • Scoped credentials. Each agent carries its own token, bound server-side to your tenant and write-only to the ingest endpoint. A stolen agent token cannot read your findings and cannot touch another tenant.
  • Least privilege on your host. The renewal agent runs as an unprivileged service user under a hardened systemd unit, and every value we hand it is validated against a strict character set before it can reach a shell.

The precise claim, then: monitoring gives us no path into your network, so a compromise of SkyQon cannot become a compromise of you. Running an agent opens exactly one path — outbound, metadata only — and it stays under your control: revoke the token or stop the service at any time, without asking us.

Encryption

All traffic to the dashboard and API is served over TLS. Credentials and connected-service tokens are encrypted at the application layer, and off-host backups are encrypted before they leave the server. Tenant data is isolated at the database level so one customer can never read another's findings.

Subprocessors

We keep the list of third parties that process data on our behalf short and EU-centered:

  • Hetzner (Germany) — application and database hosting.
  • Hostinger (EU) — marketing site and lead capture.
  • Brevo (EU) — transactional and alert email.
  • Paddle — payments and Merchant of Record; card data never touches our servers.
  • Cloudflare — DNS, CDN and edge protection for our own domains.

Our privacy policy and Data Processing Addendum describe how each is used and the safeguards in place.

Access and authentication

Dashboard accounts support two-factor authentication (TOTP) and passwordless passkeys (WebAuthn), and a tenant can require 2FA for everyone. Sign-in is rate-limited and locks out after repeated failures. Administrative access to production is restricted and key-based.

Responsible disclosure

If you believe you have found a security issue in SkyQon, please tell us before disclosing it publicly. Email [email protected] with enough detail to reproduce it. We will acknowledge your report within three business days and keep you updated while we investigate. We will not pursue action against researchers who act in good faith, avoid privacy violations and data destruction, and give us reasonable time to fix the issue. Our machine-readable policy lives at /.well-known/security.txt.

Audit-ready evidence you can inspect

Frameworks like NIS2 expect you to show that certificate and cryptographic controls are working. SkyQon turns your scan history into a signed, reproducible NIS2 Article 21(2) evidence report, with an integrity hash an auditor can recompute and a precise map of what is directly evidenced, what is supporting, and what is out of scope. Rather than describe it, here is a real one generated by the product from our own infrastructure:

Download a sample NIS2 report (PDF)

What we don't claim

We would rather be precise than impressive. SkyQon is not currently SOC 2 or ISO 27001 certified, and we will not display a badge we haven't earned. What we do offer is an EU-native service, transparent engineering practices, and the same continuous checks we run for our customers, run on ourselves. If your procurement process needs specific documentation, talk to us.

Run the same checks on your own domain

See also: how the Trust Score is calculated · system status · privacy policy.