| Independent security / no-logs audit | ❌Not foundVendor claims logging is disabled. Annual transparency reports exist (2019-2025) but are not an independent security or no-logs audit. Resolver software is undisclosed. | ⚠️PartialVendor states regular external pen tests and audits. No public no-logs audit PDF. Independent C5 work in 2022 was described by usd AG. Ask for current pentest and attestation reports. |
|---|
| ISO 27001 | ❌Not foundNo ISO 27001 claim found on dns.sb privacy, FAQ, or xTom imprint pages reviewed. | ✅VerifiedBSI-IGZ-0667-2024, issued 2024-12-18, valid to 2027-12-17. Scope is Myra Security DDoS-Schutz at six outsourced DC sites, not automatically every CDN PoP. |
|---|
| SOC 2 / SOC 3 | ❌Not foundNo SOC 2 or SOC 3 claim found on the official pages reviewed. | ❌Not foundNo SOC 2 report published. Closest published control attestations are BSI C5 Type 2 (claimed) and IDW PS 951 Type 2 / ISAE 3402 (claimed). |
|---|
| GDPR / EU data protection | ⚠️Vendor claimedGerman controller (xTom GmbH). Privacy policy includes a GDPR rights section and states DNS query data is not collected. Website analytics described as self-hosted Plausible on legitimate interests. | ⚠️Vendor claimedGerman controller/processor, GDPR pages, optional Germany-only TLS termination. Confirm DPA and processing locations in contract. |
|---|
| US CLOUD Act exposure (indicative) | ⚠️PartialEU entity and no known US parent, but public unicast list includes US cities and US-group providers (Amazon AWS Seoul, DigitalOcean Bengaluru, Vultr Toronto) plus HostVenom Chicago. Anycast includes the United States. Not legal advice. | ⚠️PartialEU entity, no known US parent, self-operated filter plane. Partial because CDN PoPs are described as global, six DC sites are outsourced and unnamed, and no product subprocessor register was found. Not legal advice. Vendor claims it is not subject to CLOUD Act/FISA 702. |
|---|
| Data processing agreement (B2B) | ❌Not foundNo public DPA. Free service is personal/non-commercial; commercial terms are by contact only. | ❌Not foundNo public Art. 28 DPA PDF on legal/GDPR/terms pages. EU CAPTCHA FAQ asks whether a DPA must be signed, which implies one exists for that product. Request the current AVV. |
|---|
| EU AI Act | —Not applicablePublic DNS resolver, not an AI system. | —Not applicableCDN/WAAP edge. Marketing mentions AI-powered DDoS detection. Not an AI-system product page. |
|---|
| BSI C5 Type 2 | Niet vermeld | ⚠️Vendor claimedCurrent Type 2 claimed on certifications page. usd AG publicly described a 2022 C5 audit with HKKG. Current-year attestation PDF not found. |
|---|
| PCI DSS Level 1 | Niet vermeld | ⚠️Vendor claimedVendor certifications page: PCI DSS Level 1 service provider. No public AOC in this research pass. |
|---|
| IDW PS 951 Type 2 (ISAE 3402) | Niet vermeld | ⚠️Vendor claimedVendor claim of Type 2 over a twelve-month period. Report not published. |
|---|
| KRITIS operator (BSIG section 8a(3)) | Niet vermeld | ⚠️Vendor claimedVendor certifications page. Confirm current attestation in procurement. |
|---|