Company · Trust Center

Swiss standards.
Documented.

This page is maintained by ANOMAL AG. It answers common questions about security, privacy and operations of our SOC and describes our current controls and practices. It is not an independent certification.

ISO 27001:2022 certifiedSwiss Made24/7 SOC in the Zurich region
Foundation
Certification

ISO 27001 certified

ANOMAL operates an ISO/IEC 27001:2022 certified Information Security Management System. Full statement of applicability available on request under mutual NDA.

Data residency

Switzerland & EU only

Customer telemetry and case data are stored and processed in Swiss or EU regions only. Some website and marketing tools are US-based; they never receive customer telemetry or case data.

Operations

24/7 from the Zurich region

The SOC is staffed and operated from the Zurich region, 24/7/365. Analysts work as one team.

Practices

How we handle your data.

Retention & deletion

Case data retention is contractually defined per customer. Deletion is executed on request and on contract termination, with written confirmation.

Response mandates

Autonomous response only within customer-approved mandates. Every mandate is versioned, reversible, and visible in ANOVIEW.

Who has access to your data.

Parties to which ANOMAL AG transfers personal data as controller or processor for the operation of anomal.xyz and its business systems. Customer-specific variations are defined in the Data Processing Agreement.

ProviderPurposeRegionTransfer
HubSpot, Inc.CRM, lead and marketing dataEU (Germany)EU SCC + Swiss FDPIC addendum
Cloudflare, Inc.Edge delivery, DNS, Turnstile bot protectionGlobalEU SCC + Swiss FDPIC addendum
Website hostingWebsite hostingEUEU SCC
Website databaseWebsite database (enquiries, bookings, applications), data centre in Zurich, SwitzerlandCHEU SCC + Swiss FDPIC addendum
Google Ireland Ltd.Web analytics (Google Analytics), only after consentEU, possible transfer to the USEU SCC + Swiss addendum

Customer-tenant technology

Detection and response technology deployed inside the customer’s own cloud tenant. Customer remains data controller. ANOMAL operates the stack under the Master Service Agreement. These are not ANOMAL sub-processors.

ProviderPurposeRegionTransfer
Microsoft Sentinel / Defender / EntraSIEM, XDR, identity in customer tenantSwitzerland North / West EuropeCustomer-controlled
Elastic (Elastic Security / SIEM)SIEM and detection in customer tenantSwitzerland / EUCustomer-controlled
Exeon AnalyticsML-based NDR in customer networkSwitzerlandCustomer-controlled
Microsoft Defender or CrowdStrikeEDR options per customer choiceEUCustomer-controlled
HalcyonOptional anti-ransomware runtime with Ransomware WarrantyEUCustomer-controlled
Contact

Security & privacy contact.

Report a security concern, request our DPA, or ask for the ISO 27001 statement of applicability. We reply within one business day.