Trust & Security

Security you can prove

SDefender is built for the people who answer to auditors, regulators and boards. Here is how we handle security, privacy and your data.

ISO 27001 certified ISO 27701 certified

ISO 27001 & ISO 27701 certified

SDefender LTD is certified to ISO/IEC 27001:2022 (information security management) and ISO/IEC 27701:2019 (privacy information management). Both certificates were issued in April 2025, are valid through April 2028 with annual surveillance audits, and cover our software development and security monitoring services. Certificates are available on request.

Your data stays in your environment

SDefender deploys on-premises and in your own cloud. Logs and events are collected, parsed and stored within your infrastructure; there is no requirement to ship your security telemetry to a third-party cloud.

Privacy by design (GDPR-aligned)

We collect only what is needed to operate and protect the service, and handle any personal data in line with GDPR. See our Privacy Policy and Cookie Policy for full detail.

Role-based access & full audit log

Operations are governed by Role-Based Access Control (RBAC), and every action is recorded in a complete audit log, so you always know who did what, and when.

Autonomous, signature-independent detection

Detection relies on entropy analytics, behavioral models and SmokeScreen deception rather than signatures, catching zero-day and reconnaissance activity that signature-based tools miss, with automated response governed by configurable thresholds.

Vendor-independent & resilient

SDefender ingests any log format over syslog and open agents (NXLog, Filebeat, Fluentd) via the Vector Remap Language, so it works across heterogeneous estates and is not locked to a single vendor stack.

Questions from your security or compliance team?

Book a call and we'll walk through architecture, data handling and certifications in detail.