In-region logging on Enterprise.Details
Secure Domains
Trust Center

Proof you can check.

How DNS Armor™ protects customer data, where it is processed and stored, and the documents your security and procurement teams need.

At a glance

Everything a security review asks for.

Security practices

Encryption, tenant isolation, role-based access and audit logs.

See the controls

Data residency

Where queries are processed and logs are stored, by plan.

See residency

Sub-processors

Every third party that touches customer data, versioned and dated.

See the list

Data Processing Addendum

Your organisation is the controller; Secure Domains is the processor.

Read the DPA
Security practices

How customer data is protected.

The same controls apply to every plan. Enterprise deployments add dedicated storage and private-cloud or on-premises options.

Encryption in transit

Channels between your networks, the platform and the portal are end-to-end encrypted, including DoH and DoT resolution.

Delegated multi-tenancy

Partners and large organisations run parent and child tenants from one portal, each with its own administrators, policies and reports.

Tenant isolation

Each customer is held in a logically isolated container, with per-tenant policies and audit trails.

Role-based access

Nine RBAC roles with enforced separation of duties: at most one security, one licence and one DNS zone role per user.

Audit logs

Every configuration change is recorded in Audit Logs and can be streamed to your SIEM over CEF.

No data sale or correlation

Customer data is never sold, rented or shared for marketing, and never correlated or aggregated across customer organisations.

Evidence

Documents, not promises.

Mapped to 7 regional frameworks.

Published DPA and sub-processors.

Everything a security questionnaire asks for, available before the first call.

Data residency

Where your data runs.

Self-service accounts for DNS Armor Protect™ and DNS Armor Resolve™ are served automatically from our Frankfurt, Germany service plane, and your DNS logs are archived in the region you choose at signup. Frankfurt applies to online self-signup only. On the Enterprise track, we place your service plane and logging plane together in the region you choose, so queries are processed and logs are stored in the same jurisdiction.

Self-serviceServed automatically from Frankfurt, Germany. Logs archived in the region you pick at signup.
EnterpriseService plane and logging plane together in the region you choose.
Data residency by plan
AspectSelf-service (online signup)Enterprise
ProductsDNS Armor Protect™ (DNS firewall) and DNS Armor Resolve™ (authoritative DNS)Same, licensed independently
Service planeFrankfurt, Germany: assigned automatically, for self-signup accounts onlyIn the region the customer chooses
Logging plane / log archiveRegion chosen at signupSame region as the service plane, always
StorageShared service plane, per-account tenantDedicated storage per customer or tenant; private cloud or on-premises available

Query-log retention follows your contract, typically 30, 60 or 90 days. Stream logs to your SIEM to keep them longer.

Compliance

Mapped to the frameworks your auditor uses.

A control-by-control view of how DNS Armor™ supports seven GCC frameworks, with the evidence behind each control.

  • NCA ECCSaudi Arabia
  • NCA CCCSaudi Arabia · cloud
  • SAMA CSFSaudi financial sector
  • UAE IA v2United Arab Emirates
  • DESC ISR v3Dubai
  • Qatar NIAQatar
  • PDPLUAE & Saudi Arabia
Open the full compliance mapping
Responsible disclosure

Found a vulnerability?

Please report it to our security team before disclosing it publicly. We acknowledge reports and keep you updated while we investigate. Our contact details and policy are published in security.txt.

Security questionnaires and due diligence

Send vendor assessments, questionnaires and architecture questions to our security team. We reply within one business day.

security@secure-domains.org
Questions

Common trust questions

Where does my data live?

Self-service accounts are served from our Frankfurt, Germany service plane, with DNS logs archived in the region you choose at signup. Enterprise customers choose one region for both the service plane and the logging plane, so queries are processed and logs are stored in the same jurisdiction.

How long do you keep DNS query logs?

Retention follows your contract, typically 30, 60 or 90 days. If a framework requires longer retention, such as 12 months under NCA ECC, stream the CEF feeds into your SIEM and retain them there.

Do you use customer data for anything else?

No. Customer data is never sold, rented or shared for marketing, and it is never correlated, mined or aggregated across customer organisations.

Can DNS Armor™ run on our own infrastructure?

Yes. Enterprise deployments can run in a private cloud or on-premises, and the Local Resolver appliance enforces policy inside your network.

Have a security review to complete?

Our team will walk through architecture, residency and controls with your security and procurement teams.