Skip to content

Legal and compliance

Security practices

How AnyLB protects customer data, from edge controls to organisational process.

Last updated: August 12, 2026

Encryption in transit and at rest

All customer traffic is served over TLS 1.3 with managed certificates. Connections to your origins use TLS by default, with optional mTLS for private origins. Stored configuration, logs and backups are encrypted at rest with AES-256.

Access control

Internal access to production systems requires hardware-backed multi-factor authentication, is granted on a least-privilege basis, and is reviewed quarterly. Every administrative action is logged and retained for one year.

  • Hardware MFA required for all engineering access
  • Just-in-time elevation with peer approval
  • Quarterly access reviews and immediate offboarding
  • Full audit trail of administrative actions

Resilience and DDoS mitigation

The AnyLB control plane runs in multiple regions behind an active-active configuration. Customer traffic is absorbed across Cloudflare's anycast network, with L3–L7 mitigation enabled by default. Control plane recovery objectives are RPO 15 minutes and RTO 60 minutes.

Compliance and disclosure

AnyLB maintains SOC 2 Type II attestation and aligns with ISO 27001 controls. We operate a coordinated vulnerability disclosure programme and acknowledge reports within 24 hours. Report issues to security@anylb.com.

Need a signed copy or a questionnaire filled in?

We can return completed security questionnaires, a signed DPA, and our SOC 2 Type II report under NDA.