# Skalvar Technologies > Skalvar Technologies is a German cybersecurity company. It builds SkalvarCon (matching companies with vetted security providers) and Aeskal (a coordinated vulnerability disclosure intake channel), researches SkalvarNet (supply chain risk) and SkalvarGard (software supply chain security), and publishes the open CVD Policy format, submitted to the IETF as draft-behring-cvd-policy. - Legal entity: Skalvar Technologies UG (haftungsbeschränkt), Alter Holzhafen 15, 23966 Wismar, Germany. Founded 2026. - Founders: Marco Berg (commercial lead), Ben Luca Behring (technical lead), Johannes Kresse (strategy and IT security). - Contact: info@skalvar.de, +49 3841 7584130. Languages: German and English. - Infrastructure runs on the company's own hardware in Germany, outside the reach of the U.S. CLOUD Act. - Product status: SkalvarCon and Aeskal are announced and launching soon; SkalvarNet and SkalvarGard are in development; the CVD Policy format is published and usable today at cvd-policy.eu. - The site is German-first (/de) with a full English translation (/en). Every URL has an hreflang counterpart in the other language. - The site is a JavaScript application, but every URL is prerendered to static HTML, so the content is in the markup without running scripts. Last updated: 2026-09-18. Index only: https://skalvar.de/llms.txt ## Deutsch (/de) ### Skalvar Technologies URL: https://skalvar.de/de Wir suchen neue Wege in der Cybersecurity und entwickeln die Verfahren dazu. Eigene Server in Deutschland, offene Formate, zwei Produkte im Einsatz. Skalvar Technologies entwickelt Verfahren für Cybersecurity: die Vermittlung geprüfter Sicherheitsdienstleister (SkalvarCon), einen Meldeweg für Schwachstellen (Aeskal), Lieferketten-Risikoanalyse (SkalvarNet) und Sicherheit für Software-Lieferketten (SkalvarGard). Dazu das offene CVD-Policy-Format. Eigene Server in Deutschland, Sitz in Wismar. ### Über uns URL: https://skalvar.de/de/ueber-uns Ein kleines Team an der Ostsee. Woran wir arbeiten, woran wir uns halten, und wer dahintersteht. Neue Wege zu einer sicheren Welt. #### Offene Fragen sind unsere Arbeit _ANSPRUCH_ Cybersecurity steckt voller Probleme, für die es noch keine gute Antwort gibt. Genau die suchen wir uns aus und entwickeln die Verfahren, die dafür nötig sind. Aus dieser Neugier ist Skalvar entstanden. #### Die Welt ein Stück sicherer machen _ZIEL_ Gute Sicherheit soll nicht davon abhängen, wie groß ein Unternehmen ist. Was wir entwickeln, geht an die Betriebe, die bisher allein dastehen. ### Vision · Über uns URL: https://skalvar.de/de/ueber-uns/vision Offene Fragen sind unsere Arbeit: Cybersecurity steckt voller Probleme ohne gute Antwort. Genau die suchen wir uns aus. Same content as https://skalvar.de/de/ueber-uns. ### Haltung · Über uns URL: https://skalvar.de/de/ueber-uns/haltung Eigene Server in Deutschland, kein Zugriff nach US-Cloud-Act. Und Wissen, das wir weitergeben statt zu halten. Woran wir uns halten. #### Ihre Daten bleiben in Deutschland _DATENSOUVERÄNITÄT_ Entwickelt in Wismar, gehostet auf deutschen Servern. Kein Zugriff nach US-Cloud-Act, keine Drittlandtransfers. Diese Entscheidung stand am Anfang und hat alles Weitere eingeschränkt. #### Sicherheit wächst, wenn man sie teilt _GRUNDSATZ_ Wissen, das nur einer hat, schützt auch nur einen. Wir geben weiter, was wir lernen: an Kunden, an Partner, an die Fachwelt. Jeder Beitrag macht das Feld für alle sicherer, uns eingeschlossen. ### Gründer · Über uns URL: https://skalvar.de/de/ueber-uns/gruender Marco Berg, Ben Luca Behring und Johannes Kresse: kaufmännische Leitung, Technik, Strategie und IT-Sicherheit. #### Marco Berg _GRÜNDER · KAUFMÄNNISCHE LEITUNG_ Kam aus der Logistik, danach Cybersecurity als Entwickler, Consultant und Platform Architect. Verantwortet Vertrieb und Finanzen. #### Ben Luca Behring _GRÜNDER · TECHNISCHE LEITUNG_ Backend, Prozessdesign, Linux-Administration, zuletzt Netzwerkarchitektur. Verantwortet Architektur und Produkt. #### Johannes Kresse _GRÜNDER · STRATEGIE UND IT-SICHERHEIT_ Fast zwanzig Jahre IT-Sicherheit: Antiviren-Hersteller, DAX-Projekte, zuletzt Geschäftsführer eines Security-Dienstleisters. ### Kontakt · Über uns URL: https://skalvar.de/de/ueber-uns/kontakt Skalvar Technologies in Wismar an der Ostsee. Direkt erreichbar, ohne Formularstrecke. Direkt, ohne Formularstrecke. #### Wismar, Deutschland _STANDORT_ Skalvar Technologies sitzt in Wismar an der Ostsee. Von hier aus entwickeln wir für ganz Europa. #### Kontaktieren Sie uns _ERREICHBARKEIT_ info@skalvar.de +49 3841 7584130 Für Partnerschaften, Anfragen und Informationen. ### Lösungen URL: https://skalvar.de/de/loesungen SkalvarCon vermittelt geprüfte Sicherheitsdienstleister, Aeskal nimmt Schwachstellenmeldungen entgegen. #### Abdeckung CON: Ransomware, Phishing, Penetrationstest, Cloud Security AESKAL: CVD-Meldungen, Meldeweg, Zero-Day Beide: Compliance, Incident Response ### Abdeckung · Lösungen URL: https://skalvar.de/de/loesungen/alle Welche Bedrohungen SkalvarCon und Aeskal abdecken, und wo sich die beiden überschneiden. Same content as https://skalvar.de/de/loesungen. ### SkalvarCon · Lösungen URL: https://skalvar.de/de/loesungen/skalvarcon Vom Bedarf zum passenden Anbieter: Ausschluss nach harten Kriterien, dann Bewertung, und an jedem Übergang ein Mensch. #### Vom Bedarf zum passenden Anbieter _ABLAUF · Demnächst_ Ein Unternehmen beschreibt, was geschützt werden soll, was der Anlass ist und bis wann eine Antwort gebraucht wird. Zwei Stufen werten die Angaben aus: zuerst ein Ausschluss nach harten Kriterien, danach eine Bewertung der verbliebenen Anbieter. An jedem Übergang prüft ein Mensch das Ergebnis. > Ergebnis sind zwei bis vier vergleichbare Angebote. #### Ein Überblick, den kleinere Betriebe nicht vorhalten _EINORDNUNG_ Den richtigen Sicherheitsdienstleister zu finden, setzt Marktkenntnis voraus. Große Unternehmen haben dafür eine Einkaufsabteilung, kleinere nicht. SkalvarCon übernimmt diese Arbeit, damit die Größe eines Unternehmens nicht darüber entscheidet, ob es den passenden Partner findet. > Die Auswahl ist der Teil, der bisher Ressourcen brauchte. ### Aeskal · Lösungen URL: https://skalvar.de/de/loesungen/aeskal Ein Meldeweg für Schwachstellen, der dem Unternehmen gehört. security.txt und Disclosure-Policy unter der eigenen Domain. #### Was mit einer Schwachstellenmeldung passiert _ABLAUF · Demnächst_ Sicherheitsforscher melden über ein öffentliches Formular oder per E-Mail. Anhänge gehen in Quarantäne, jede Meldung wird mit bekannten Schwachstellen abgeglichen. Wird dieselbe Lücke mehrfach gemeldet, bleiben alle Meldungen erhalten und werden miteinander verknüpft. Anschließend sichtet ein Analyst die Meldung und leitet sie an die hinterlegte Adresse weiter. > Die Anreicherung ordnet ein. Über die Gültigkeit entscheidet sie nie. #### Ein Meldeweg, der dem Unternehmen gehört _EINORDNUNG_ security.txt und Disclosure-Policy pflegt das Unternehmen selbst und veröffentlicht sie unter der eigenen Domain. Die Domain wird über einen DNS-Eintrag verifiziert, die Veröffentlichung danach laufend auf Abweichungen geprüft. Beides folgt offenen Standards: RFC 9116 und einer Spezifikation, die niemandem gehört. > Das erzeugte Dokument bleibt auch ohne Aeskal vollständig gültig. ### Forschung URL: https://skalvar.de/de/forschung SkalvarNet rechnet Lieferkettenrisiken, SkalvarGard prüft Software beim Entstehen. Beides in Entwicklung. #### Wer fällt mit, wenn dieser eine ausfällt? _DER GRAPH · In Entwicklung_ Die Lieferkette liegt als gerichteter Graph über mehrere Stufen, und zwar bis unter die Unternehmensebene: bis zum einzelnen Material und zu der Fertigungslinie, die daran hängt. Fällt ein Zulieferer aus oder wird eine Schwachstelle bekannt, ergibt sich daraus, wen das erreicht, über welche Wege und in welcher Reihenfolge. > Je mehr Unternehmen im Netz, desto genauer die Rechnung für alle. #### Ausbreitung wird gelernt, nicht angenommen _DAS MODELL_ Ein temporales Graph-Neural-Network wertet den Graphen als Ganzes aus: Es lernt aus vergangenen Verläufen, welche Ausfälle sich tatsächlich fortpflanzen, über welche Kanten und mit welcher Verzögerung. Die Ausbreitung folgt damit keinem Regelwerk über die Lieferkette, sondern ergibt sich aus ihr. > Die Zeit gehört zum Modell, nicht nur der Graph. ### SkalvarNet · Forschung URL: https://skalvar.de/de/forschung/skalvarnet Die Lieferkette als gerichteter Graph, bis zum einzelnen Material und zur Fertigungslinie, die daran hängt. Same content as https://skalvar.de/de/forschung. ### SkalvarGard · Forschung URL: https://skalvar.de/de/forschung/skalvargard Geprüft wird, während der Code entsteht: im Editor, in der Pipeline und im Repository, mit derselben Policy. #### Geprüft wird, während der Code entsteht _DREI ZEITPUNKTE · In Entwicklung_ Drei Punkte im Leben einer Software werden abgedeckt: das Schreiben im Editor, das Bauen in der Pipeline und das Repository, das danach weiterläuft. Abhängigkeiten, Secrets und Codequalität prüft an allen drei Stellen dieselbe Policy. > Ein Fund bedeutet an jeder der drei Stellen dasselbe. #### Der Agent arbeitet, ohne alles zu sehen _AGENT GUARD_ KI-Agenten schreiben Code, indem sie lesen, was im Projekt liegt. Was dabei tatsächlich bei ihnen ankommt, bestimmt eine Regel je Pfad und nicht der Agent selbst. Er bleibt arbeitsfähig, und was nicht für ihn bestimmt ist, erreicht ihn nicht. > Der Inhalt erreicht den Kontext des Agenten nicht. ### Open Source URL: https://skalvar.de/de/open-source Das CVD-Policy-Format: eine Disclosure-Policy, die auch Programme lesen. Eingereicht als Internet-Draft bei der IETF. #### Eine Policy, die auch Programme lesen können _FORMAT · Internet-Draft_ security.txt nennt einen Kontakt. Das CVD-Policy-Format ergänzt eine JSON-Datei unter einer angegebenen HTTPS-Adresse: welche Systeme Meldungen annehmen, welche Prüfregeln der Betreiber erklärt und wie gemeldet werden soll. Ein Werkzeug kann das auswerten, bevor es die erste Anfrage stellt. > Maschinen können es lesen. Menschen auch. #### Was das Format nicht ist _GRENZEN_ Es weist kein Eigentum nach, erteilt keine rechtliche Erlaubnis und sichert keine Straffreiheit zu. Es ist auch keine Bewertung: kein Score, keine Reifegrade, kein Vergleich. Es hält fest, was ein Betreiber erklärt hat, und sonst nichts. > V1 ist experimentell. Feld und Medientyp können sich ändern. Link: draft-behring-cvd-policy-00 - https://www.ietf.org/archive/id/draft-behring-cvd-policy-00.html ### Das Format · Open Source URL: https://skalvar.de/de/open-source/format security.txt nennt einen Kontakt. Das CVD-Policy-Format ergänzt, welche Systeme Meldungen annehmen und wie gemeldet werden soll. Same content as https://skalvar.de/de/open-source. ### Werkzeug · Open Source URL: https://skalvar.de/de/open-source/werkzeug Policy erstellen, prüfen und nachlesen unter cvd-policy.eu. Läuft vollständig im Browser, ohne Konto und ohne Upload. #### Erstellen, prüfen, nachlesen _IM BROWSER · Open Source_ Drei Schritte: das Dokument erzeugen, es unter der gewählten HTTPS-Adresse veröffentlichen und diese Adresse mit einem CVD-Policy-Feld in der security.txt angeben. Generator, Validator und Erklärung laufen vollständig im Browser. > Kein Backend, kein Upload, keine Anfrage an fremde Domains. #### Getrennt von allem, was wir verkaufen _NEUTRALITÄT_ Eigenes Repository, eigene Domain, eigenes Erscheinungsbild. Kein Feld im Format existiert, weil ein Dienst es braucht. Aeskal nutzt die Spezifikation wie jeder andere auch. > Ein Standard, der dem Betreiber eines Dienstes gehört, ist keiner. Link: cvd-policy.eu - https://cvd-policy.eu/ Link: github.com/cvd-policy - https://github.com/cvd-policy Link: @cvd-policy auf npm - https://www.npmjs.com/~skalvartechnologies ## English (/en) ### Skalvar Technologies URL: https://skalvar.de/en We explore new approaches to cybersecurity and develop the methods and technologies to support them. Our infrastructure is hosted on our own servers in Germany, we rely on open formats, and we currently operate two products. Skalvar Technologies develops methods for cybersecurity: matching companies with vetted security providers (SkalvarCon), a vulnerability reporting channel (Aeskal), supply chain risk analysis (SkalvarNet) and software supply chain security (SkalvarGard), plus the open CVD Policy format. Own servers in Germany, based in Wismar. ### About Us URL: https://skalvar.de/en/about-us A small team based on the Baltic coast. What we work on, the standards we set for ourselves, and the people behind Skalvar. New routes to a safer world. #### Open Questions Are the Work _AMBITION_ Cybersecurity is full of problems that still have no good answer. Those are the ones we choose, and we develop the methods they need. Skalvar grew out of that curiosity. #### Making the World a Safer Place _GOAL_ Good security should not depend on how big a company is. What we develop goes to the businesses that have so far stood alone. ### Vision · About Us URL: https://skalvar.de/en/about-us/vision Unsolved problems are our work. Cybersecurity faces many problems without good answers. Those are the problems we choose to take on. Same content as https://skalvar.de/en/about-us. ### Principles · About Us URL: https://skalvar.de/en/about-us/principles Our own servers in Germany, without dependence on providers subject to the U.S. CLOUD Act. And knowledge we share rather than keep to ourselves. What we hold ourselves to. #### Your Data Stays in Germany _DATA SOVEREIGNTY_ Developed in Wismar, hosted on German servers. No US Cloud Act exposure, no third-country transfers. That decision came first and constrained everything after it. #### Security Grows When You Share It _PRINCIPLE_ Knowledge that only one party holds protects only that party. We pass on what we learn: to customers, to partners, to the wider field. Every contribution makes the whole safer, us included. ### Founders · About Us URL: https://skalvar.de/en/about-us/founders Marco Berg, Ben Luca Behring and Johannes Kresse: commercial lead, technical lead, strategy and IT security. #### Marco Berg _FOUNDER · COMMERCIAL LEAD_ Came from logistics, then cybersecurity as developer, consultant and platform architect. Responsible for sales and finance. #### Ben Luca Behring _FOUNDER · TECHNICAL LEAD_ Backend development, process design, Linux administration, most recently network architecture. Responsible for architecture and product. #### Johannes Kresse _FOUNDER · STRATEGY AND IT SECURITY_ Nearly twenty years in IT security: an antivirus vendor, projects for DAX-listed corporations, most recently managing director of a security provider. ### Contact · About Us URL: https://skalvar.de/en/about-us/contact Skalvar Technologies in Wismar at the Baltic Sea. Reach us directly, without going through a chain of forms. Directly, with no forms first. #### Wismar, Germany _LOCATION_ Skalvar Technologies is based in Wismar on the Baltic Sea. From here we build for Europe. #### Contact Us _REACH OUT_ info@skalvar.de +49 3841 7584130 For partnerships, enquiries and information. ### Solutions URL: https://skalvar.de/en/solutions SkalvarCon connects businesses with verified security providers. Aeskal provides a structured way to receive vulnerability reports. #### Coverage CON: Ransomware, Phishing, Penetration Testing, Cloud Security AESKAL: CVD Reports, Reporting Channel, Zero-Day Both: Compliance, Incident Response ### Coverage · Solutions URL: https://skalvar.de/en/solutions/all The threats SkalvarCon and Aeskal address, and where their coverage overlaps. Same content as https://skalvar.de/en/solutions. ### SkalvarCon · Solutions URL: https://skalvar.de/en/solutions/skalvarcon From requirement to suitable provider: hard criteria narrow the field, scoring ranks the remaining options, and a person stays involved at every stage. #### From a Requirement to a Suitable Provider _PROCESS · Coming Soon_ A company describes what needs protecting, what prompted it and by when an answer is needed. Two stages evaluate those details: first an exclusion against hard criteria, then a scoring of the providers that remain. A person checks the result at every handover. > The outcome is two to four comparable quotes. #### An Overview Smaller Companies Cannot Keep on Hand _CONTEXT_ Finding the right security provider takes knowledge of the market. Large organisations have a purchasing function for that; smaller ones do not. SkalvarCon takes that work on, so that the size of a company does not decide whether it finds the right partner. > Selection is the part that used to take resources. ### Aeskal · Solutions URL: https://skalvar.de/en/solutions/aeskal A vulnerability reporting channel the company owns. security.txt and disclosure policy under its own domain. #### What Happens to a Vulnerability Report _PROCESS · Coming Soon_ Researchers report through a public form or by email. Attachments go into quarantine and every report is correlated against known vulnerabilities. When the same finding is reported more than once, every report is kept and the reports are linked to one another. An analyst then reviews it and forwards it to the address on file. > Enrichment places a report in context. It never rules on its validity. #### A Reporting Channel the Company Owns _CONTEXT_ The company maintains its own security.txt and disclosure policy and publishes them under its own domain. The domain is verified through a DNS record, and the publication is checked for drift from then on. Both follow open standards: RFC 9116, and a specification that belongs to nobody. > The generated document stays fully valid without Aeskal. ### Research URL: https://skalvar.de/en/research SkalvarNet assesses supply chain risk. SkalvarGard reviews software as it is being built. Both are currently in development. #### Who Goes Down With This One? _THE GRAPH · In Development_ The supply chain sits as a directed graph across several tiers, and it goes below the company level: down to the individual material and the production line that depends on it. If a supplier fails or a vulnerability lands, what follows from it is who that reaches, along which paths and in what order. > The more companies in the network, the more accurate the result for all of them. #### Propagation Is Learned, Not Assumed _THE MODEL_ A temporal graph neural network reads the graph as a whole: it learns from past events which failures actually travel, along which edges and with what delay. Propagation is then not a set of rules imposed on the supply chain but a result drawn from it. > Time is part of the model, not only the graph. ### SkalvarNet · Research URL: https://skalvar.de/en/research/skalvarnet The supply chain modeled as a directed graph, tracing dependencies down to individual materials and the production lines that rely on them. Same content as https://skalvar.de/en/research. ### SkalvarGard · Research URL: https://skalvar.de/en/research/skalvargard Checked simultaneously as the code is being written: in the editor, in the pipeline and in the repository, by the same policy. #### Checked While the Code Is Being Written _THREE MOMENTS · In Development_ Three points in a piece of software's life are covered: writing it in the editor, building it in the pipeline, and the repository it lives in afterwards. Dependencies, secrets and code quality are checked at all three by the same policy. > A finding means the same thing at all three points. #### The Agent Works Without Seeing Everything _AGENT GUARD_ AI agents write code by reading what is in the project. What actually reaches them is decided by a rule per path, not by the agents themselves. They can still work, and what is not meant for them does not arrive. > The content stays out of the agent's context. ### Open Source URL: https://skalvar.de/en/open-source The CVD Policy format is a machine-readable disclosure policy. It has been submitted to the IETF as an Internet-Draft. #### A Policy That Programs Can Read _FORMAT · Internet-Draft_ security.txt names a contact. The CVD Policy format adds a JSON file at an advertised HTTPS address: which assets accept reports, which testing rules the publisher states, and how to report. A tool can evaluate that before it sends its first request. > Machines can read it. So can people. #### What the Format Is Not _LIMITS_ It does not prove ownership, grant legal authorisation or guarantee safe harbour. Nor is it a rating: no score, no maturity level, no comparison. It records a publisher statement, and nothing more. > V1 is experimental. The field and media type may change. Link: draft-behring-cvd-policy-00 - https://www.ietf.org/archive/id/draft-behring-cvd-policy-00.html ### The Format · Open Source URL: https://skalvar.de/en/open-source/format The security.txt specifies where to make contact. The CVD Policy format adds which assets accept vulnerability reports and how those reports should be submitted. Same content as https://skalvar.de/en/open-source. ### Tool · Open Source URL: https://skalvar.de/en/open-source/tool Build, validate, and learn about CVD Policies at cvd-policy.eu. Everything runs locally in your browser, with no account required and no data uploaded. #### Create, Check, Read Up _IN BROWSER · Open Source_ Three steps: generate the document, publish it at the HTTPS address you selected, and advertise that address with one CVD-Policy field in your security.txt. The generator, validator and explainer all run in the browser. > No backend, no upload, no request to any other domain. #### Kept Apart From Everything We Sell _NEUTRALITY_ Its own repository, its own domain, its own look. No field exists in the format because a service needed one. Aeskal consumes the specification like anyone else. > A standard owned by the operator of a service is not a standard. Link: cvd-policy.eu - https://cvd-policy.eu/ Link: github.com/cvd-policy - https://github.com/cvd-policy Link: @cvd-policy on npm - https://www.npmjs.com/~skalvartechnologies ## Standards and resources - [CVD Policy format](https://cvd-policy.eu/): open specification for machine-readable coordinated vulnerability disclosure policies, with a validator that runs in the browser - [Internet-Draft draft-behring-cvd-policy](https://www.ietf.org/archive/id/draft-behring-cvd-policy-00.html): the specification as submitted to the IETF - [CVD Policy source](https://github.com/cvd-policy): reference implementation and tooling - [@cvd-policy/core](https://www.npmjs.com/package/@cvd-policy/core): reference implementation of the CVD Policy format on npm - validation, generation, evaluation, explanation - [@cvd-policy/cli](https://www.npmjs.com/package/@cvd-policy/cli): command line tool for the CVD Policy format - validate, check and explain policy documents - [npm profile skalvartechnologies](https://www.npmjs.com/~skalvartechnologies): the packages above, published by Skalvar Technologies - [CVD policy](https://skalvar.de/cvd-policy.html): how to report a vulnerability in Skalvar's own systems - [Skalvar's cvd-policy.json](https://skalvar.de/cvd-policy.json): the company's own disclosure policy, machine-readable - [sitemap.xml](https://skalvar.de/sitemap.xml): every URL with its hreflang set ## Optional ### Datenschutz URL: https://skalvar.de/de/datenschutz (English: https://skalvar.de/en/privacy-policy) Legal text, not summarised here. Fetch the URL if the answer depends on it. ### Impressum URL: https://skalvar.de/de/impressum (English: https://skalvar.de/en/legal-notice) Legal text, not summarised here. Fetch the URL if the answer depends on it.