Swiss standards.
Documented.
This page is maintained by ANOMAL AG. It answers common questions about security, privacy and operations of our SOC and describes our current controls and practices. It is not an independent certification.
ISO 27001 certified
ANOMAL operates an ISO/IEC 27001:2022 certified Information Security Management System. Full statement of applicability available on request under mutual NDA.
Switzerland & EU only
Customer telemetry and case data are stored and processed in Swiss or EU regions only. Some website and marketing tools are US-based; they never receive customer telemetry or case data.
24/7 from the Zurich region
The SOC is staffed and operated from the Zurich region, 24/7/365. Analysts work as one team.
How we handle your data.
Retention & deletion
Case data retention is contractually defined per customer. Deletion is executed on request and on contract termination, with written confirmation.
Response mandates
Autonomous response only within customer-approved mandates. Every mandate is versioned, reversible, and visible in ANOVIEW.
Who has access to your data.
Parties to which ANOMAL AG transfers personal data as controller or processor for the operation of anomal.xyz and its business systems. Customer-specific variations are defined in the Data Processing Agreement.
| Provider | Purpose | Region | Transfer |
|---|---|---|---|
| HubSpot, Inc. | CRM, lead and marketing data | EU (Germany) | EU SCC + Swiss FDPIC addendum |
| Cloudflare, Inc. | Edge delivery, DNS, Turnstile bot protection | Global | EU SCC + Swiss FDPIC addendum |
| Website hosting | Website hosting | EU | EU SCC |
| Website database | Website database (enquiries, bookings, applications), data centre in Zurich, Switzerland | CH | EU SCC + Swiss FDPIC addendum |
| Google Ireland Ltd. | Web analytics (Google Analytics), only after consent | EU, possible transfer to the US | EU SCC + Swiss addendum |
Customer-tenant technology
Detection and response technology deployed inside the customer’s own cloud tenant. Customer remains data controller. ANOMAL operates the stack under the Master Service Agreement. These are not ANOMAL sub-processors.
| Provider | Purpose | Region | Transfer |
|---|---|---|---|
| Microsoft Sentinel / Defender / Entra | SIEM, XDR, identity in customer tenant | Switzerland North / West Europe | Customer-controlled |
| Elastic (Elastic Security / SIEM) | SIEM and detection in customer tenant | Switzerland / EU | Customer-controlled |
| Exeon Analytics | ML-based NDR in customer network | Switzerland | Customer-controlled |
| Microsoft Defender or CrowdStrike | EDR options per customer choice | EU | Customer-controlled |
| Halcyon | Optional anti-ransomware runtime with Ransomware Warranty | EU | Customer-controlled |
Security & privacy contact.
Report a security concern, request our DPA, or ask for the ISO 27001 statement of applicability. We reply within one business day.