Pricing
Log inStart free
Security

What runs where.

This is the page to forward to your engineering lead or your security reviewer. What Skene can reach depends on which of the two products you run, so each one is answered separately below.

Start freeContact us about your security review

Skene OSS requests no access. Skene Cloud is scoped per repository.

  • ›

    Skene OSS runs entirely on your machine

    MIT-licensed, no Skene account, reads your codebase read-only.

  • ⑂

    Never pushes to your default branch

    Changes arrive as pull requests you review and merge yourself. No personal access tokens.

  • ⇄

    Supabase starts read-only

    Schema introspection only. No row data, no table counts, never writes.

121SupabasePostHogMixpanelBigQueryResend
Access scopes / GitHub App4 permissions
Contents
Read & write
Pull requests
Read & write
Issues
Read & write
Metadata
Read
Skene OSS

Runs entirely on your machine.

Reads your codebase read-only, writes skene-context/journey.yaml into your repository. With lmstudio or ollama, nothing leaves the machine.

Skene Cloud

The managed version, plus what OSS does not do.

Adds pull request review, the journey canvas, and the record of launch checks. The MCP server is hosted; your coding agent connects with a workspace API key.

Access scopes

Four permissions, and what each is for.

Skene OSS requests no access. Skene Cloud connects to GitHub through the Skene GitHub App, scoped to the repositories you select.

  • ⌘Contents

    Read & write. Reading your code and skene-context/ files; committing updates back through pull requests.

  • ↔Pull requests

    Read & write. Reading diffs, posting reviews, opening fix pull requests.

  • ○Issues

    Read & write. Responding to /skene fix comments.

  • ⌕Metadata

    Read. Listing the repositories the installation can access.

Skene Cloud makes two connections.

A workspace owner adds both. Supabase takes a production and an optional development project, assigned separately. GitHub holds one repository and branch.

  • ✓Exactly two roles, owner and member. No permission matrix to configure.
  • ✓Deploys and every write target the production project only.
Integrations/skene-dashboard
2 connected
  • Supabase
    connected
  • Productionacme-production
    assigned
  • Development database
    not assigned
  • GitHubacme/webappmain
    connected
Data retention

Skene OSS keeps nothing.

Skene Cloud purges the interaction events Flows captures after 90 days; a workspace owner can delete them sooner. Detailed personal-data retention times are available on request.

Settings / Data retention
WhatKept for
Skene OSS outputNothing
Skene Cloud personal dataAccount duration
Flows interaction events90 days
Everything, on requestImmediately
Third parties in the path

What each one does, and what it sees.

The third parties below are in the path for Skene Cloud.

ServiceWhat it doesWhat it sees
VercelApplication hosting for the dashboard and the APIRequest traffic, session cookies, API payloads
SupabaseAuthentication, Postgres and storageAccounts, workspaces, artifacts, encrypted secrets
OpenRouterGateway for the managed LLM analysisPrompts, which can include repository and schema context
OpenAIThe default managed model, openai/gpt-5.6-terra, reached through OpenRouterThe same analysis prompts
GoogleGap-analysis models and Skene Agent, through OpenRouter, Gemini and Cloud RunAnalysis prompts and agent chat context
ResendTransactional email from support@skene.ai: invites, welcome, onboarding, reminders and quota warningsEmail address and message content
StripeBilling and paymentsCustomer and payment metadata. Card details go to Stripe, not Skene
GitHubThe Skene GitHub App: link, webhooks, PR reviewsRepository metadata, PR diffs, review comments
Upstash RedisBuffering on the event ingest path, when it is configured. Without it events buffer in Postgres insteadBuffered analytics events awaiting their scheduled drain
Upstash QStashFanning the scheduled ingest job out per workspace, when it is configured. Without it the job runs inlineWorkspace identifiers, and the scheduling of the work rather than its contents
Certification

Not SOC 2 certified today.

SOC 2 certificationROADMAP

It is on the roadmap and not yet started, and there is no date to give you. If a certification is a hard requirement for your procurement, say so early. Contact us and we will answer your security review directly.

What you keep if we go away.

  • ✓Your product data stays in the database you already own.
  • ✓Uninstalling the GitHub App withdraws all four permissions at once, from GitHub rather than from us.
  • ✓Skene OSS is MIT-licensed and public: if Skene Cloud stopped tomorrow, the tool still runs.
Start freeContact us about your security review

Product data your GTM team can trust.

Product

Before you shipHow it worksFeaturesIntegrationsSecuritySupabasePricing

Developers

DevelopersSkene CloudMCP servervs coding agentsOpen sourceDocs

Resources

ResourcesGlossaryPlaybooksBlogReleases

Company

AboutCommunityEventsContactPrivacyTerms
© 2026 Skene Technologies. All rights reserved.