# Skalvar Technologies > Skalvar Technologies is a German cybersecurity company. It builds SkalvarCon (matching companies with vetted security providers) and Aeskal (a coordinated vulnerability disclosure intake channel), researches SkalvarNet (supply chain risk) and SkalvarGard (software supply chain security), and publishes the open CVD Policy format, submitted to the IETF as draft-behring-cvd-policy. - Legal entity: Skalvar Technologies UG (haftungsbeschränkt), Alter Holzhafen 15, 23966 Wismar, Germany. Founded 2026. - Founders: Marco Berg (commercial lead), Ben Luca Behring (technical lead), Johannes Kresse (strategy and IT security). - Contact: info@skalvar.de, +49 3841 7584130. Languages: German and English. - Infrastructure runs on the company's own hardware in Germany, outside the reach of the U.S. CLOUD Act. - Product status: SkalvarCon and Aeskal are announced and launching soon; SkalvarNet and SkalvarGard are in development; the CVD Policy format is published and usable today at cvd-policy.eu. - The site is German-first (/de) with a full English translation (/en). Every URL has an hreflang counterpart in the other language. - The site is a JavaScript application, but every URL is prerendered to static HTML, so the content is in the markup without running scripts. Last updated: 2026-09-18. Full text of every page: https://skalvar.de/llms-full.txt ## Deutsch (/de) - [Start](https://skalvar.de/de): Wir suchen neue Wege in der Cybersecurity und entwickeln die Verfahren dazu. Eigene Server in Deutschland, offene Formate, zwei Produkte im Einsatz. - [Über uns](https://skalvar.de/de/ueber-uns): Ein kleines Team an der Ostsee. Woran wir arbeiten, woran wir uns halten, und wer dahintersteht. - [Über uns – Vision](https://skalvar.de/de/ueber-uns/vision): Offene Fragen sind unsere Arbeit: Cybersecurity steckt voller Probleme ohne gute Antwort. Genau die suchen wir uns aus. - [Über uns – Haltung](https://skalvar.de/de/ueber-uns/haltung): Eigene Server in Deutschland, kein Zugriff nach US-Cloud-Act. Und Wissen, das wir weitergeben statt zu halten. - [Über uns – Gründer](https://skalvar.de/de/ueber-uns/gruender): Marco Berg, Ben Luca Behring und Johannes Kresse: kaufmännische Leitung, Technik, Strategie und IT-Sicherheit. - [Über uns – Kontakt](https://skalvar.de/de/ueber-uns/kontakt): Skalvar Technologies in Wismar an der Ostsee. Direkt erreichbar, ohne Formularstrecke. - [Lösungen](https://skalvar.de/de/loesungen): SkalvarCon vermittelt geprüfte Sicherheitsdienstleister, Aeskal nimmt Schwachstellenmeldungen entgegen. - [Lösungen – Abdeckung](https://skalvar.de/de/loesungen/alle): Welche Bedrohungen SkalvarCon und Aeskal abdecken, und wo sich die beiden überschneiden. - [Lösungen – SkalvarCon](https://skalvar.de/de/loesungen/skalvarcon): Vom Bedarf zum passenden Anbieter: Ausschluss nach harten Kriterien, dann Bewertung, und an jedem Übergang ein Mensch. - [Lösungen – Aeskal](https://skalvar.de/de/loesungen/aeskal): Ein Meldeweg für Schwachstellen, der dem Unternehmen gehört. security.txt und Disclosure-Policy unter der eigenen Domain. - [Forschung](https://skalvar.de/de/forschung): SkalvarNet rechnet Lieferkettenrisiken, SkalvarGard prüft Software beim Entstehen. Beides in Entwicklung. - [Forschung – SkalvarNet](https://skalvar.de/de/forschung/skalvarnet): Die Lieferkette als gerichteter Graph, bis zum einzelnen Material und zur Fertigungslinie, die daran hängt. - [Forschung – SkalvarGard](https://skalvar.de/de/forschung/skalvargard): Geprüft wird, während der Code entsteht: im Editor, in der Pipeline und im Repository, mit derselben Policy. - [Open Source](https://skalvar.de/de/open-source): Das CVD-Policy-Format: eine Disclosure-Policy, die auch Programme lesen. Eingereicht als Internet-Draft bei der IETF. - [Open Source – Das Format](https://skalvar.de/de/open-source/format): security.txt nennt einen Kontakt. Das CVD-Policy-Format ergänzt, welche Systeme Meldungen annehmen und wie gemeldet werden soll. - [Open Source – Werkzeug](https://skalvar.de/de/open-source/werkzeug): Policy erstellen, prüfen und nachlesen unter cvd-policy.eu. Läuft vollständig im Browser, ohne Konto und ohne Upload. ## English (/en) - [Home](https://skalvar.de/en): We explore new approaches to cybersecurity and develop the methods and technologies to support them. Our infrastructure is hosted on our own servers in Germany, we rely on open formats, and we currently operate two products. - [About Us](https://skalvar.de/en/about-us): A small team based on the Baltic coast. What we work on, the standards we set for ourselves, and the people behind Skalvar. - [About Us – Vision](https://skalvar.de/en/about-us/vision): Unsolved problems are our work. Cybersecurity faces many problems without good answers. Those are the problems we choose to take on. - [About Us – Principles](https://skalvar.de/en/about-us/principles): Our own servers in Germany, without dependence on providers subject to the U.S. CLOUD Act. And knowledge we share rather than keep to ourselves. - [About Us – Founders](https://skalvar.de/en/about-us/founders): Marco Berg, Ben Luca Behring and Johannes Kresse: commercial lead, technical lead, strategy and IT security. - [About Us – Contact](https://skalvar.de/en/about-us/contact): Skalvar Technologies in Wismar at the Baltic Sea. Reach us directly, without going through a chain of forms. - [Solutions](https://skalvar.de/en/solutions): SkalvarCon connects businesses with verified security providers. Aeskal provides a structured way to receive vulnerability reports. - [Solutions – Coverage](https://skalvar.de/en/solutions/all): The threats SkalvarCon and Aeskal address, and where their coverage overlaps. - [Solutions – SkalvarCon](https://skalvar.de/en/solutions/skalvarcon): From requirement to suitable provider: hard criteria narrow the field, scoring ranks the remaining options, and a person stays involved at every stage. - [Solutions – Aeskal](https://skalvar.de/en/solutions/aeskal): A vulnerability reporting channel the company owns. security.txt and disclosure policy under its own domain. - [Research](https://skalvar.de/en/research): SkalvarNet assesses supply chain risk. SkalvarGard reviews software as it is being built. Both are currently in development. - [Research – SkalvarNet](https://skalvar.de/en/research/skalvarnet): The supply chain modeled as a directed graph, tracing dependencies down to individual materials and the production lines that rely on them. - [Research – SkalvarGard](https://skalvar.de/en/research/skalvargard): Checked simultaneously as the code is being written: in the editor, in the pipeline and in the repository, by the same policy. - [Open Source](https://skalvar.de/en/open-source): The CVD Policy format is a machine-readable disclosure policy. It has been submitted to the IETF as an Internet-Draft. - [Open Source – The Format](https://skalvar.de/en/open-source/format): The security.txt specifies where to make contact. The CVD Policy format adds which assets accept vulnerability reports and how those reports should be submitted. - [Open Source – Tool](https://skalvar.de/en/open-source/tool): Build, validate, and learn about CVD Policies at cvd-policy.eu. Everything runs locally in your browser, with no account required and no data uploaded. ## Standards and resources - [CVD Policy format](https://cvd-policy.eu/): open specification for machine-readable coordinated vulnerability disclosure policies, with a validator that runs in the browser - [Internet-Draft draft-behring-cvd-policy](https://www.ietf.org/archive/id/draft-behring-cvd-policy-00.html): the specification as submitted to the IETF - [CVD Policy source](https://github.com/cvd-policy): reference implementation and tooling - [@cvd-policy/core](https://www.npmjs.com/package/@cvd-policy/core): reference implementation of the CVD Policy format on npm - validation, generation, evaluation, explanation - [@cvd-policy/cli](https://www.npmjs.com/package/@cvd-policy/cli): command line tool for the CVD Policy format - validate, check and explain policy documents - [npm profile skalvartechnologies](https://www.npmjs.com/~skalvartechnologies): the packages above, published by Skalvar Technologies - [CVD policy](https://skalvar.de/cvd-policy.html): how to report a vulnerability in Skalvar's own systems - [Skalvar's cvd-policy.json](https://skalvar.de/cvd-policy.json): the company's own disclosure policy, machine-readable - [sitemap.xml](https://skalvar.de/sitemap.xml): every URL with its hreflang set ## Optional - [Datenschutz / Privacy policy (de)](https://skalvar.de/de/datenschutz): required disclosures, no product information - [Impressum / Legal notice (de)](https://skalvar.de/de/impressum): required disclosures, no product information - [Datenschutz / Privacy policy (en)](https://skalvar.de/en/privacy-policy): required disclosures, no product information - [Impressum / Legal notice (en)](https://skalvar.de/en/legal-notice): required disclosures, no product information