Security practices
Encryption, tenant isolation, role-based access and audit logs.
See the controlsEncryption, tenant isolation, role-based access and audit logs.
See the controlsWhere queries are processed and logs are stored, by plan.
See residencyEvery third party that touches customer data, versioned and dated.
See the listYour organisation is the controller; Secure Domains is the processor.
Read the DPADubai DET commercial licence No. 1357380.
About the companyReport a vulnerability to security@secure-domains.org.
View security.txtThe same controls apply to every plan. Enterprise deployments add dedicated storage and private-cloud or on-premises options.
Channels between your networks, the platform and the portal are end-to-end encrypted, including DoH and DoT resolution.
Partners and large organisations run parent and child tenants from one portal, each with its own administrators, policies and reports.
Each customer is held in a logically isolated container, with per-tenant policies and audit trails.
Nine RBAC roles with enforced separation of duties: at most one security, one licence and one DNS zone role per user.
Every configuration change is recorded in Audit Logs and can be streamed to your SIEM over CEF.
Customer data is never sold, rented or shared for marketing, and never correlated or aggregated across customer organisations.
Mapped to 7 regional frameworks.
Published DPA and sub-processors.
Everything a security questionnaire asks for, available before the first call.
Self-service accounts for DNS Armor Protect™ and DNS Armor Resolve™ are served automatically from our Frankfurt, Germany service plane, and your DNS logs are archived in the region you choose at signup. Frankfurt applies to online self-signup only. On the Enterprise track, we place your service plane and logging plane together in the region you choose, so queries are processed and logs are stored in the same jurisdiction.
| Aspect | Self-service (online signup) | Enterprise |
|---|---|---|
| Products | DNS Armor Protect™ (DNS firewall) and DNS Armor Resolve™ (authoritative DNS) | Same, licensed independently |
| Service plane | Frankfurt, Germany: assigned automatically, for self-signup accounts only | In the region the customer chooses |
| Logging plane / log archive | Region chosen at signup | Same region as the service plane, always |
| Storage | Shared service plane, per-account tenant | Dedicated storage per customer or tenant; private cloud or on-premises available |
Query-log retention follows your contract, typically 30, 60 or 90 days. Stream logs to your SIEM to keep them longer.
A control-by-control view of how DNS Armor™ supports seven GCC frameworks, with the evidence behind each control.
Secure Domains acts as data processor under a Data Processing Addendum, with your organisation as controller.
How we process personal data, and the Data Processing Addendum that governs customer data.
Read the DPAThe contract for DNS Armor™ services, including acceptable use and liability.
Read the termsThe third parties that touch customer data, with purpose and location, versioned and dated.
See sub-processorsPlease report it to our security team before disclosing it publicly. We acknowledge reports and keep you updated while we investigate. Our contact details and policy are published in security.txt.
Send vendor assessments, questionnaires and architecture questions to our security team. We reply within one business day.
security@secure-domains.orgSelf-service accounts are served from our Frankfurt, Germany service plane, with DNS logs archived in the region you choose at signup. Enterprise customers choose one region for both the service plane and the logging plane, so queries are processed and logs are stored in the same jurisdiction.
Retention follows your contract, typically 30, 60 or 90 days. If a framework requires longer retention, such as 12 months under NCA ECC, stream the CEF feeds into your SIEM and retain them there.
No. Customer data is never sold, rented or shared for marketing, and it is never correlated, mined or aggregated across customer organisations.
Yes. Enterprise deployments can run in a private cloud or on-premises, and the Local Resolver appliance enforces policy inside your network.
Our team will walk through architecture, residency and controls with your security and procurement teams.