1. What is the source of your accuracy figure, and can I re-run it?
We publish no accuracy percentage, for either product, because we cannot hand you a benchmark you could re-run. When we can, it will arrive with the corpus attached. Put the same question to every vendor on your shortlist and compare what comes back.
2. Who exactly holds the certificate you are citing?
Hetzner Online GmbH, for the Falkenstein facility where processing happens — not this company. The correctly scoped wording is below, ready to lift.
3. Does your detection give the same answer twice?
That is the design, for a fixed engine build, models and configuration: checksums where arithmetic settles it, pinned NER models where context does — not yet verified with a long-running test. An ML-scored product cannot promise this, which matters the day an auditor asks you to reproduce a finding from March.
4. Can it run where my data already is?
anonym.plus processes on the customer's own machine, with 317 own pattern recognisers and no network call to process a document. The hosted platform does not, and says so in the comparison table.
5. What happens to me if you go out of business?
The local licence is perpetual and runs on your hardware; the detection core is MIT-licensed Microsoft Presidio. Support is a separate optional add-on, so declining it never stops the software working.

The nine questions, answered in one place

These are the questions a procurement or data-protection review asks every supplier, in roughly this order. Four of the nine answers below are a no, and one is a dated commitment. They are also the four most useful lines on this page, because a supplier who answers all nine with a yes is either larger than us or is guessing, and you will find out which one during the audit rather than before it.

What a review asksThe answer todayWhere to check it
Is the processor itself ISO 27001 certified?No. The data centre is. The company itself does not hold a certification today.Certification
Who are the sub-processors, and where do they sit?Named, with location and what each one touches.Sub-processors
Is there an Article 28 data processing agreement?Yes, signed and returned within two working days of the request. There is no template file on this site yet, which is a gap and not a policy - what you get is the current version, signed for your case.Request one
Is there a third-party penetration test or audit report?No. None has been commissioned. Saying otherwise is the single easiest claim to disprove in this industry.Document processing in anonym.plus keeps our infrastructure out of your path
Is there an uptime SLA on the hosted service?No. No service level is offered or implied.Once activated, document processing in anonym.plus depends on no service of ours
What is the incident notification process?Not published. Ask and you get the current answer in writing rather than a page that was written once and never revisited.Ask
What is the liability position?In the published terms of service, including the limitations. It is not hidden in an order form.Terms of service
What happens to us if you disappear?Local: the licence is perpetual and the installation keeps working, with no server of ours in the path. Hosted: the service stops, and the exit procedure is not yet documented.anonym.plus
Where is the text actually processed?Hetzner, Falkenstein, Germany with anonym.legal. On your own hardware with anonym.plus, and processing makes no network call.Security

This table is the honest state on September 26, 2026. When one of the four noes becomes a yes it changes here first, not in a sales conversation.

Written precisely enough to survive your auditor

Processing on the hosted platform takes place at Hetzner Online GmbH in Falkenstein, Germany. That facility holds ISO/IEC 27001 certification, covering the physical and operational security of the data centre.

The precision that matters. The certificate covers the facility, not this company. Vendors routinely write “ISO 27001 certified” without naming Hetzner — or whichever data centre actually holds it — and let the reader infer the rest. It reads well until an auditor checks the register, does not find the vendor listed, and the evaluation stops — not because the security was inadequate, but because the sentence was.

So here is the sentence, scoped correctly:

Processing takes place at Hetzner Online GmbH, Falkenstein, Germany. The facility holds ISO/IEC 27001 certification. The processor, Voltage Brothers Infrastruktur UG (haftungsbeschränkt), does not itself hold ISO/IEC 27001. The technical and organisational measures it applies are described at anonymize.solutions/evidence.html#security.

Where this is going. The company itself does not hold a certification today. We are not publishing a target date, because a missed certification date is worse than no date at all — it is the one promise a buyer will check.

If your framework requires a certified processor today with no exceptions, that is a real constraint and we will not talk you out of it. The route that still works is anonym.plus: processing on hardware inside a boundary you have already certified yourself.

Mechanisms, per product and per data flow

There is no single security statement that is true of both products, because one sends text over a network and the other does not.

Text leaves the machine
  • Transport secured with TLS
  • Encryption keys are derived on your device with Argon2id; custom patterns you store are encrypted in your browser, and the server keeps only ciphertext
  • Text is processed in memory and not used for training. It is stored, encrypted, only if you turn on history, or as a token mapping for reversible anonymization (24 hours by default, up to 30 days if you choose persistent)
  • The sign-in is not Zero-Knowledge: the password is still sent at sign-in today.
  • The reversible-encryption operator uses AES in CBC mode without an authentication tag, and its key reaches the server, which sees the plaintext during that operation. “Zero-Knowledge” does not extend to it.
No text leaves the machine

anonym.plus — local

  • No transport surface for documents — processing makes no network call to intercept. What does go online: the one-time activation, an update check (on by default, can be switched off), the updates you choose to install, a check for new language models at start and the models you choose to download
  • Document content never reaches our servers, so there is none for a third party to request from us. Licence purchase and activation do create an account and machine record on our licensing server
  • The macOS build is not notarised; Gatekeeper blocks a plain download until the user allows it, and an earlier vault-setup defect on macOS is not yet confirmed fixed
  • No batch, CLI or webhook surface
Not available

We publish no third-party penetration test or audit report, and no detection accuracy percentage. Both would be easy to imply and neither would survive the question “can I see it?”

Who else touches the data

Limited to what the two privacy notices document: anonym.legal’s for the hosted product, ours for this website. Where a processor is not named here, that means it is not documented there — not that we are certain there is none.

Document processing itself involves only Hetzner. The others are billing and website functions. Processing a document with anonym.plus involves none of them, because it makes no network call.
ProcessorWhat it doesWhere
Hetzner Online GmbHanonym.legal: hosting and processing. This website: hosting, fonts, server logsFalkenstein, Germany
Stripeanonym.legal: payment processingEU / US, standard contractual clauses
PayPalanonym.legal: payment processingEU / US, standard contractual clauses
Microsoft 365This website: e-mail for messages sent to usEU / US, EU-U.S. Data Privacy Framework and standard contractual clauses
Google reCAPTCHAThis website: spam check when the contact form is sent, only after consentEU / US, EU-U.S. Data Privacy Framework

This website’s privacy notice · anonym.legal’s privacy notice.

How to get one signed

An agreement under Article 28 GDPR sets out what we may do with personal data you send us as a processor: subject matter and duration, nature and purpose, categories of data subject, your instructions, confidentiality, security measures, sub-processor rules, assistance with data-subject requests, deletion or return at the end, and audit rights.

The contracting entity is Voltage Brothers Infrastruktur UG (haftungsbeschränkt), Europaallee 6, 66113 Saarbrücken, Germany.

There is no template file to download here, because none is published. A DPA is issued on request, signed for your specific case, and returned within two working days — which is a commitment rather than an aspiration, and the reason it is written down here where you can hold us to it.

If you are evaluating anonym.plus rather than the hosted platform, you may not need one at all: if the text never leaves your machine, we are not processing it.

Ask the sixth question

If something here sounds too convenient, that is the thing worth asking about. We would rather answer now than have it surface in your review.