Five questions worth asking every vendor on your shortlist
Including us. Our answers are below, awkward ones first, because you would find them anyway and finding them here is faster for both of us.
The nine questions, answered in one place
These are the questions a procurement or data-protection review asks every supplier, in roughly this order. Four of the nine answers below are a no, and one is a dated commitment. They are also the four most useful lines on this page, because a supplier who answers all nine with a yes is either larger than us or is guessing, and you will find out which one during the audit rather than before it.
| What a review asks | The answer today | Where to check it |
|---|---|---|
| Is the processor itself ISO 27001 certified? | No. The data centre is. The company itself does not hold a certification today. | Certification |
| Who are the sub-processors, and where do they sit? | Named, with location and what each one touches. | Sub-processors |
| Is there an Article 28 data processing agreement? | Yes, signed and returned within two working days of the request. There is no template file on this site yet, which is a gap and not a policy - what you get is the current version, signed for your case. | Request one |
| Is there a third-party penetration test or audit report? | No. None has been commissioned. Saying otherwise is the single easiest claim to disprove in this industry. | Document processing in anonym.plus keeps our infrastructure out of your path |
| Is there an uptime SLA on the hosted service? | No. No service level is offered or implied. | Once activated, document processing in anonym.plus depends on no service of ours |
| What is the incident notification process? | Not published. Ask and you get the current answer in writing rather than a page that was written once and never revisited. | Ask |
| What is the liability position? | In the published terms of service, including the limitations. It is not hidden in an order form. | Terms of service |
| What happens to us if you disappear? | Local: the licence is perpetual and the installation keeps working, with no server of ours in the path. Hosted: the service stops, and the exit procedure is not yet documented. | anonym.plus |
| Where is the text actually processed? | Hetzner, Falkenstein, Germany with anonym.legal. On your own hardware with anonym.plus, and processing makes no network call. | Security |
This table is the honest state on September 26, 2026. When one of the four noes becomes a yes it changes here first, not in a sales conversation.
Written precisely enough to survive your auditor
Processing on the hosted platform takes place at Hetzner Online GmbH in Falkenstein, Germany. That facility holds ISO/IEC 27001 certification, covering the physical and operational security of the data centre.
The precision that matters. The certificate covers the facility, not this company. Vendors routinely write “ISO 27001 certified” without naming Hetzner — or whichever data centre actually holds it — and let the reader infer the rest. It reads well until an auditor checks the register, does not find the vendor listed, and the evaluation stops — not because the security was inadequate, but because the sentence was.
So here is the sentence, scoped correctly:
Processing takes place at Hetzner Online GmbH, Falkenstein, Germany. The facility holds ISO/IEC 27001 certification. The processor, Voltage Brothers Infrastruktur UG (haftungsbeschränkt), does not itself hold ISO/IEC 27001. The technical and organisational measures it applies are described at anonymize.solutions/evidence.html#security.
Where this is going. The company itself does not hold a certification today. We are not publishing a target date, because a missed certification date is worse than no date at all — it is the one promise a buyer will check.
If your framework requires a certified processor today with no exceptions, that is a real constraint and we will not talk you out of it. The route that still works is anonym.plus: processing on hardware inside a boundary you have already certified yourself.
Mechanisms, per product and per data flow
There is no single security statement that is true of both products, because one sends text over a network and the other does not.
anonym.legal — hosted
- Transport secured with TLS
- Encryption keys are derived on your device with Argon2id; custom patterns you store are encrypted in your browser, and the server keeps only ciphertext
- Text is processed in memory and not used for training. It is stored, encrypted, only if you turn on history, or as a token mapping for reversible anonymization (24 hours by default, up to 30 days if you choose persistent)
- The sign-in is not Zero-Knowledge: the password is still sent at sign-in today.
- The reversible-encryption operator uses AES in CBC mode without an authentication tag, and its key reaches the server, which sees the plaintext during that operation. “Zero-Knowledge” does not extend to it.
anonym.plus — local
- No transport surface for documents — processing makes no network call to intercept. What does go online: the one-time activation, an update check (on by default, can be switched off), the updates you choose to install, a check for new language models at start and the models you choose to download
- Document content never reaches our servers, so there is none for a third party to request from us. Licence purchase and activation do create an account and machine record on our licensing server
- The macOS build is not notarised; Gatekeeper blocks a plain download until the user allows it, and an earlier vault-setup defect on macOS is not yet confirmed fixed
- No batch, CLI or webhook surface
We publish no third-party penetration test or audit report, and no detection accuracy percentage. Both would be easy to imply and neither would survive the question “can I see it?”
Who else touches the data
Limited to what the two privacy notices document: anonym.legal’s for the hosted product, ours for this website. Where a processor is not named here, that means it is not documented there — not that we are certain there is none.
| Processor | What it does | Where |
|---|---|---|
| Hetzner Online GmbH | anonym.legal: hosting and processing. This website: hosting, fonts, server logs | Falkenstein, Germany |
| Stripe | anonym.legal: payment processing | EU / US, standard contractual clauses |
| PayPal | anonym.legal: payment processing | EU / US, standard contractual clauses |
| Microsoft 365 | This website: e-mail for messages sent to us | EU / US, EU-U.S. Data Privacy Framework and standard contractual clauses |
| Google reCAPTCHA | This website: spam check when the contact form is sent, only after consent | EU / US, EU-U.S. Data Privacy Framework |
This website’s privacy notice · anonym.legal’s privacy notice.
How to get one signed
An agreement under Article 28 GDPR sets out what we may do with personal data you send us as a processor: subject matter and duration, nature and purpose, categories of data subject, your instructions, confidentiality, security measures, sub-processor rules, assistance with data-subject requests, deletion or return at the end, and audit rights.
The contracting entity is Voltage Brothers Infrastruktur UG (haftungsbeschränkt), Europaallee 6, 66113 Saarbrücken, Germany.
There is no template file to download here, because none is published. A DPA is issued on request, signed for your specific case, and returned within two working days — which is a commitment rather than an aspiration, and the reason it is written down here where you can hold us to it.
If you are evaluating anonym.plus rather than the hosted platform, you may not need one at all: if the text never leaves your machine, we are not processing it.
Ask the sixth question
If something here sounds too convenient, that is the thing worth asking about. We would rather answer now than have it surface in your review.