By · Last updated 2026-03-19

返回博客技术

ISO 27001加零知识缩短供应商评估时间

2025年一项调查发现,"缺乏认可的安全认证"是CISO淘汰SaaS供应商的第二大原因。ISO 27001加零知识组合能实现什么?

March 19, 20267 分钟阅读
ISO 27001 certificationvendor assessmentCISO procuremententerprise securityzero-knowledge

供应商采购中的认证缺口

企业安全团队每年审查数十个供应商,需要快速筛选工具。ISO 27001认证提供了这样一个工具:审计机构已经核查了供应商的控制措施,内部团队不必重复同样的工作。

没有此认证的供应商必须在每次交易中单独建立自己的案例,这对双方都耗费时间,拖慢审查并增加核查失败的风险。

2022年标准涵盖的内容

当前版本的附件A包含四个组的93个控制:组织、人员、物理和技术。团队重点关注几个关键领域:

密码控制(附件A 8.24): 供应商必须定义密钥使用规则,涵盖密钥的创建、存储、访问和移除,认证表明审计机构确认该政策有效运作。

访问控制(附件A 8.2-8.5): 员工对客户数据的访问必须遵循最小权限规则,认证表明这些限制已记录在案并得到执行。

供应商关系(附件A 5.19-5.22): 供应商必须为自己的供应商记录安全规则,当买家必须证明其自身供应商的安全性时,这一点非常重要。

认证确认流程和组织控制已到位,将定制审查缩减为标准不涉及的更小的架构问题集。

认证无法回答的问题

标准回答流程问题,而不回答受监管机构最关心的问题:供应商能读取我们的数据吗?

经认证的供应商可能仍然持有服务端密钥。认证确认密钥管理遵循政策,但不确认该政策阻止了供应商访问明文。

零知识设计回答了标准遗留的问题:密钥在客户端生成,服务器上没有密钥,数据在离开客户端前使用AES-256-GCM加密,供应商无法读取客户数据——这是结构性事实,而非政策选择。

这涵盖了两个不同的顾虑:认证满足采购表中的流程和组织核查,零知识设计满足受监管机构排名最高的数据访问顾虑。两者合力清除了医疗、金融和法律市场云供应商审批的两个主要关卡。

对审查时间的影响

认证缩短了文件审查时间:认证书和适用性声明作为证明,审计机构已核查控制,采购团队不必重复这项工作。

零知识设计缩短了架构审查时间:数据访问问题有明确的结构性答案,没有什么可以协商,除了设计本身。

两个因素都减少了延长供应商审查的来回沟通。当难题在首次提交时获得直接答案,团队推进速度更快。减少轮次意味着减少延迟。

对于受监管市场的供应商,这在每次交易中都很重要:更短的审查意味着更短的销售周期,在企业交易规模下,这种差异积累快速。能够在第一天就回答最难问题的供应商在整个过程中面临更少摩擦。

请参阅FAQ中心了解常见问题。

参考资料

准备好保护您的数据了吗?

开始使用 285 种实体类型在 48 种语言中匿名化 PII。

About this page

We update this page when our platform or the law changes.

Read our founder note for how we work.

Each change shows up in the timestamp at the top.

Related reading

We follow these rules

  • GDPR (EU 2016/679).
  • ISO/IEC 27001:2022.
  • NIS2 (EU 2022/2555).
  • HIPAA safe harbor under 45 CFR § 164.514(b)(2).

Our promise

We do not sell your data.

We do not train models on your text.

We store your files in Germany.

You can delete your account at any time.

You own your work.

Where we run

Our servers live in Falkenstein, Germany.

We use Hetzner. They hold ISO 27001 certification.

All data stays in the EU.

Backups run every day.

Need help?

Email support@anonym.legal.

We reply within one business day.

How we test

We run a full check suite on every release.

Each surface gets its own sweep script and report.

Human reviewers spot-check the output each week.

We track recall and precision on a labelled set.

Bad runs block the deploy.

What we never do

  • We never sell your information to third parties.
  • We never train models on what you upload.
  • We never keep your work after you delete it.
  • We never share keys with any outside firm.
  • We never run ads inside the product.

Plans in plain words

We sell credits, not seats.

One credit covers one short job.

Long jobs use a few credits each.

You can top up at any time.

Unused credits roll over each month.

Read the plans page for current rates.

Who built this

A small team of engineers and lawyers built this.

We ship from Europe and work in the open.

Our founder note spells out why we started.

Where to start

How the parts fit

A browser add-on cleans text inside Chrome.

A Word plug-in handles drafts in Office.

A small desktop tool works on whole folders.

An agent protocol link feeds large models safely.

All four share one core engine and one rule set.

Words from our team

We started this work after a lunch about cookies.

One friend kept getting odd ads on her phone.

We asked why a court file leaked through a draft.

We sketched the first build on a napkin that week.

By month three we had a tiny demo for a friend.

She used it on her first case the next day.

Common questions we hear

Can the tool read scanned PDFs? Yes, with OCR.

Does it work on long files? Yes, in small chunks.

Can I roll my own rule set? Yes, save it as a preset.

Does it run offline? The desktop build runs offline.

Do you keep my files? No, the cloud build wipes after each run.

Will it learn from my work? No, we never train on inputs.

A short tour of the workflow

Upload a file or paste a snippet of prose.

Pick the entities you want gone from the draft.

Choose a method: replace, mask, hash, encrypt, or redact.

Press run and watch the side panel show each hit.

Skim the result and tweak any rule that misfired.

Save the cleaned file or send it to a teammate.