By · Last updated 2026-09-23

Statement of Applicability (SoA)

Document ID: ISMS-POL-005
Version: 1.0
Effective Date: December 29, 2025
Review Date: December 29, 2026
Classification: Internal

1. Purpose#

This Statement of Applicability (SoA) documents the ISO/IEC 27001:2022 Annex A controls applicable to anonym.legal, their implementation status, and justification for inclusion or exclusion.

2. Scope#

This SoA covers all information security controls relevant to the anonym.legal PII anonymization platform, including:

  • Cloud-hosted infrastructure (Hetzner)
  • Web application (web framework frontend)
  • Backend services (Presidio Analyzer/Anonymizer)
  • Database (relational database)
  • Customer data processing

3. Control Selection Methodology#

Controls were selected based on:

  • Risk assessment results
  • Legal and regulatory requirements (GDPR)
  • Business requirements
  • Customer expectations
  • Industry best practices

4. Control Categories Overview#

CategoryTotal ControlsApplicableImplementedPartialNot Applicable
A.5 Organizational372520512
A.6 People86422
A.7 Physical145509
A.8 Technological34302824
Total936657927

5. Detailed Control Status#

A.5 Organizational Controls#

ControlTitleApplicableStatusJustification
A.5.1Policies for information security✅ImplementedInformation Security Policy documented
A.5.2Information security roles✅ImplementedRoles defined in RBAC system
A.5.3Segregation of duties✅ImplementedAdmin/Editor/User role separation
A.5.4Management responsibilities✅ImplementedDocumented in policies
A.5.5Contact with authorities✅PartialGDPR contacts identified
A.5.6Contact with special interest groups❌N/ASmall organization
A.5.7Threat intelligence✅Partialnpm audit, security advisories
A.5.8Information security in project management✅ImplementedSecurity in development process
A.5.9Inventory of information✅ImplementedAsset inventory documented
A.5.10Acceptable use of information✅ImplementedTerms of Service, policies
A.5.11Return of assets❌N/ASaaS model, no physical assets
A.5.12Classification of information✅ImplementedData classification defined
A.5.13Labelling of information❌N/AAutomated system handling
A.5.14Information transfer✅ImplementedTLS encryption, secure APIs
A.5.15Access control✅ImplementedRBAC, plan-based gating
A.5.16Identity management✅ImplementedNextAuth.js, JWT sessions
A.5.17Authentication information✅ImplementedPassword policy, 2FA
A.5.18Access rights✅ImplementedRole-based permissions
A.5.19Information security in supplier relationships✅PartialHetzner, Stripe reviewed
A.5.20Addressing security in supplier agreements✅PartialStandard agreements
A.5.21Managing information security in ICT supply chain✅ImplementedDependency management
A.5.22Monitoring, review of supplier services✅PartialUptime monitoring
A.5.23Information security for cloud services✅ImplementedHetzner security config
A.5.24Information security incident management✅ImplementedIncident Response Plan
A.5.25Assessment and decision on events✅ImplementedSeverity classification
A.5.26Response to information security incidents✅ImplementedResponse procedures
A.5.27Learning from incidents✅ImplementedPost-incident review
A.5.28Collection of evidence✅ImplementedLog retention, audit trails
A.5.29Information security during disruption✅ImplementedBackup/recovery procedures
A.5.30ICT readiness for business continuity✅ImplementedHetzner snapshots
A.5.31Legal, statutory, regulatory requirements✅ImplementedGDPR compliance
A.5.32Intellectual property rights✅ImplementedLicense compliance
A.5.33Protection of records✅ImplementedData retention policy
A.5.34Privacy and protection of PII✅ImplementedCore business function
A.5.35Independent review of information security❌N/ASmall organization
A.5.36Compliance with security policies✅ImplementedAutomated enforcement
A.5.37Documented operating procedures✅ImplementedDocumentation in docs/

A.6 People Controls#

ControlTitleApplicableStatusJustification
A.6.1Screening❌N/ASolo/small team
A.6.2Terms and conditions of employment❌N/ASolo/small team
A.6.3Information security awareness✅PartialSelf-awareness
A.6.4Disciplinary process❌N/ASolo/small team
A.6.5Responsibilities after termination✅ImplementedCredential revocation
A.6.6Confidentiality agreements✅ImplementedCustomer agreements
A.6.7Remote working✅ImplementedSecure remote access
A.6.8Information security event reporting✅ImplementedIncident reporting

A.7 Physical Controls#

ControlTitleApplicableStatusJustification
A.7.1Physical security perimeters✅ImplementedHetzner data centers
A.7.2Physical entry✅ImplementedHetzner controlled
A.7.3Securing offices, rooms, facilities❌N/ACloud-only
A.7.4Physical security monitoring✅ImplementedHetzner monitoring
A.7.5Protecting against physical threats✅ImplementedHetzner facilities
A.7.6Working in secure areas❌N/ACloud-only
A.7.7Clear desk and clear screen❌N/ARemote work
A.7.8Equipment siting and protection✅ImplementedHetzner data centers
A.7.9Security of assets off-premises❌N/ACloud-only
A.7.10Storage media❌N/ANo physical media
A.7.11Supporting utilities❌N/AHetzner managed
A.7.12Cabling security❌N/AHetzner managed
A.7.13Equipment maintenance❌N/AHetzner managed
A.7.14Secure disposal or re-use❌N/AHetzner managed

A.8 Technological Controls#

ControlTitleApplicableStatusJustification
A.8.1User endpoint devices❌N/ASaaS, no managed endpoints
A.8.2Privileged access rights✅ImplementedAdmin role, SSH keys
A.8.3Information access restriction✅ImplementedRBAC, feature gating
A.8.4Access to source code✅ImplementedPrivate repository
A.8.5Secure authentication✅ImplementedPassword policy, 2FA
A.8.6Capacity management✅ImplementedHetzner scalable
A.8.7Protection against malware✅ImplementedServer hardening
A.8.8Management of technical vulnerabilities✅Implementednpm audit, updates
A.8.9Configuration management✅ImplementedInfrastructure as code
A.8.10Information deletion✅ImplementedData deletion procedures
A.8.11Data masking✅ImplementedCore business function
A.8.12Data leakage prevention✅ImplementedEncryption, access control
A.8.13Information backup✅ImplementedHetzner snapshots
A.8.14Redundancy of information processing✅PartialSingle server (cost)
A.8.15Logging✅ImplementedApplication/system logs
A.8.16Monitoring activities✅ImplementedUptime, error tracking
A.8.17Clock synchronization✅ImplementedNTP configured
A.8.18Use of privileged utility programs✅ImplementedRestricted to admin
A.8.19Installation of software✅ImplementedControlled deployment
A.8.20Networks security✅ImplementedFirewall, brute force protection
A.8.21Security of network services✅ImplementedTLS, secure protocols
A.8.22Segregation of networks✅PartialApplication isolation
A.8.23Web filtering❌N/AServer-side only
A.8.24Use of cryptography✅ImplementedAES-256-GCM, TLS
A.8.25Secure development life cycle✅ImplementedCode review, testing
A.8.26Application security requirements✅ImplementedSecurity in design
A.8.27Secure system architecture✅ImplementedDefense in depth
A.8.28Secure coding✅ImplementedBest practices, linting
A.8.29Security testing in development✅ImplementedUnit testing, end-to-end testing, audit
A.8.30Outsourced development❌N/AIn-house development
A.8.31Separation of development, test, production✅PartialStaging environment
A.8.32Change management✅ImplementedVersion control, changelog
A.8.33Test information✅ImplementedMock data for tests
A.8.34Protection during audit testing✅ImplementedIsolated test environment

6. Exclusion Justifications#

Physical Controls (A.7.3, A.7.6, A.7.7, A.7.9-A.7.14)#

Justification: anonym.legal is a cloud-only SaaS platform hosted on Hetzner Cloud. Physical security is managed by Hetzner (ISO 27001 certified data centers). No physical premises or equipment are maintained.

People Controls (A.6.1, A.6.2, A.6.4)#

Justification: Small team/solo operation. Formal HR processes not applicable at current scale.

Endpoint Controls (A.8.1, A.8.23)#

Justification: SaaS model where customers use their own devices. No managed endpoints.

Outsourced Development (A.8.30)#

Justification: All development is performed in-house.

7. Implementation Evidence#

Control CategoryEvidence Location
Policiesdocs/iso27001/
Access Controllib/roles.ts, lib/plan-features.ts
Authenticationlib/auth.ts, lib/auth/two-factor.ts
Encryptionlib/encryption.ts
LoggingApplication logs, journalctl
Testingtests/ directory
Change Managementdocs/CHANGELOG.md
Configurationapp.config.js, web server configs

8. Continuous Improvement#

Planned Improvements#

ControlCurrent StatusTarget StatusTimeline
A.5.35N/AConsider external auditQ2 2026
A.8.14PartialFull redundancyQ3 2026
A.8.22PartialFull network segmentationQ2 2026

9. Document Control#

VersionDateAuthorChanges
1.02025-12-29Security TeamInitial release

About this page

We update this page when our platform or the law changes.

Read our founder note for how we work.

Each change shows up in the timestamp at the top.

We follow these rules

  • GDPR (EU 2016/679).
  • ISO/IEC 27001:2022, held by our hosting provider.
  • NIS2 (EU 2022/2555).
  • HIPAA safe harbor under 45 CFR § 164.514(b)(2).

Our promise

We do not sell your data.

We do not train models on your text.

We store your files in Germany.

You can delete your account at any time.

You own your work.

Where we run

Our company HQ is in Saarbrücken, Germany. Our servers run in Hetzner's Falkenstein datacenter.

Hetzner holds ISO 27001 certification.

All data stays in the EU.

Backups run every day.

Need help?

Email support@anonym.legal.

We reply within one business day.

How we test

Automated checks run on every release.

Each surface gets its own sweep script and report.

Human reviewers spot-check the output each week.

We test detection against sample documents before each release.

A failing unit or integration run stops the release.

What we never do

  • We never sell your information to third parties.
  • We never train models on what you upload.
  • We never keep your work after you delete it.
  • We never share keys with any outside firm.
  • We never run ads inside the product.

Plans in plain words

We sell credits, not seats.

One credit covers one short job.

Long jobs use a few credits each.

Paid plans can buy top-up credits.

Credits reset at the end of each cycle.

Read the plans page for current rates.

Who built this

A small team of engineers and lawyers built this.

We ship from Europe and work in the open.

Our founder note spells out why we started.

Where to start

How the parts fit

A browser add-on cleans text inside Chrome.

A Word plug-in handles drafts in Office.

A small desktop tool works on whole folders.

An agent protocol link feeds large models safely.

All four share one core engine and one rule set.

Words from our team

We started this work after a lunch about cookies.

One friend kept getting odd ads on her phone.

We asked why a court file leaked through a draft.

We sketched the first build on a napkin that week.

By month three we had a tiny demo for a friend.

She used it on her first case the next day.

Common questions we hear

Can the tool read scanned PDFs? Yes, with OCR.

Does it work on long files? Yes, in small chunks.

Can I roll my own rule set? Yes, save it as a preset.

Does it run offline? The desktop build runs offline.

Do you keep my files? No, the cloud build wipes after each run.

Will it learn from my work? No, we never train on inputs.

A short tour of the workflow

Upload a file or paste a snippet of prose.

Pick the entities you want gone from the draft.

Choose a method: replace, mask, hash, encrypt, or redact.

Press run and watch the side panel show each hit.

Skim the result and tweak any rule that misfired.

Save the cleaned file or send it to a teammate.