Query Builder
Query Builder is a powerful no-code analytical interface that enables users to execute complex, high-precision queries across Anomaly Six datasets without SQL or programming expertise. Designed for speed and accuracy, it supports advanced filtering, aggregation, and alternative outputs, enabling analysts to move from question to insight in minutes.
Features
- No-code interface enabling complex queries without SQL or programming knowledge
- Advanced filtering across dozens of metadata and behavioural attributes
- Rapid query execution optimised for large-scale commercial telemetry datasets
- Supports alternative outputs including counts, distinct identifiers, and aggregations
- Reduces analyst workload through repeatable and saved query logic
- Enables rapid hypothesis testing and exploratory intelligence analysis
- Designed for precision querying beyond basic time and location filters
- Integrates directly with Anomaly Six data and analytics environments
- Lightweight execution minimises local compute and network resource usage
- Accelerates transition from question to insight in operational contexts
Benefits
- Allows analysts to answer complex questions without coding expertise
- Significantly reduces time from data access to actionable insight
- Improves analytical accuracy through precise filtering and structured outputs
- Enables rapid exploration of hypotheses and emerging intelligence leads
- Reduces reliance on specialist data engineering resources
- Supports consistent analysis through saved and repeatable queries
- Enhances investigative depth beyond basic location or time analysis
- Optimises analyst productivity during time-sensitive operational requirements
- Lowers technical barriers to advanced intelligence analysis
- Improves confidence in results through transparent, auditable query logic
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 8 9 3 7 1 9 6 2 3 1 3 3 8 5
Contact
VINDO TECHNOLOGY LIMITED
Paul Vingoe
Telephone: +447584 436 515
Email: support@vindo.technology
About your service
- Service categories
-
Application Development and Deployment
Analytics and business intelligence
- Location and geospatial data management and analytics
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
-
Query Builder (QB) works with Anomaly Six's (A6) other products.
Visualisation Engine (VE)
Gateway Connect (GC)
Data Direct (DD)
A6 is a technology and data company delivering secure, cloud-based geospatial and multi-domain intelligence solutions to government and security organisations. - Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- Anomaly Six services are provided subject to contractual terms and conditions, including data usage restrictions, access controls, and compliance with applicable privacy, security, and regulatory frameworks. Services are delivered via secure cloud environments and require reliable internet connectivity; performance may be impacted by client network configurations or bandwidth limitations. Hardware provisioning, endpoint security, and user devices remain the responsibility of the customer. Certain capabilities may require minimum data volumes, defined query limits, or approved use cases. Availability of specific datasets or integrations may vary by geography, jurisdiction, and contractual scope, and service levels are governed by agreed SLAs.
- System requirements
- Internet enabled device capable of running approved browser software
User support
- Email or online ticketing support
- Yes
- Support response times
- Support requests are triaged using severity levels P1 to P4. Target response and resolution times are as follows: Critical (P1): response within 1 hour, resolution within 4 hours High (P2): response within 4 business hours, resolution within 24 hours Medium (P3): response within 8 business hours, resolution within 72 hours Low (P4): response within 24 business hours, resolution within 5 business days ‘Based on approved SOW A6 will support customer time zones or 24/7 as needed. Outside these hours (including weekends), requests can be submitted and will be triaged in the next business window unless enhanced support coverage is agreed.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Support is co-ordinated by each dedicated customer technical account manager and levels are agreed as per the SLA on a customer-by-customer basis.
Out-of-hours and weekend support can be provided by agreement where required. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- User onboarding is delivered through a structured remote implementation process. We start with an onboarding call to confirm the buyer’s objectives, intended use cases, user roles, and required configuration. We then provide administrator setup guidance, access to user documentation, and (where appropriate) online training sessions for administrators and end users. During an initial bedding-in period, support is available to answer questions, resolve configuration issues, and confirm that users can access and use the service as intended. Where required, additional onboarding assistance, bespoke training, or onsite support can be provided as part of the initial package, or by agreement (pricing provided in pricing documentation).
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- At contract end, buyers can extract the limited buyer-specific data held within the service (primarily account, access-control and configuration information, plus any audit/support records generated for the buyer) by requesting an export from the support team. The core content accessed through the service is supplier-provided data and is not customer-supplied; as such, there is no bulk “customer dataset” to export beyond the buyer’s user and configuration records. Exports are provided in a commonly used machine-readable format (for example CSV or JSON) and transferred securely to a nominated buyer contact. Following confirmation that the export has been received, the buyer’s user accounts are deactivated and buyer-specific data is deleted or permanently erased in line with the agreed retention schedule and contractual requirements. If the buyer requires an extended access window for transition, this can be agreed for a defined period.
- End-of-contract process
-
At the end of the contract, the buyer is notified of the expiry date and can choose to renew or terminate in line with the contract terms. If the buyer is terminating, user access is disabled on the agreed end date and the service is offboarded in a controlled manner. Where relevant, the buyer may request an export of the limited buyer-specific information held by the service (for example user account details, access-control/configuration settings, and any buyer-specific audit or support records). The core content accessed through the service is supplier-provided data rather than customer-supplied data, so there is no bulk customer dataset to extract beyond these records. Following confirmation that any requested exports have been provided, buyer-specific data is deleted or permanently erased in line with the agreed retention schedule and contractual requirements.
Included in the contract price are the standard service subscription for the contracted term, access for authorised users, standard documentation, and standard support during agreed business hours. Additional costs may apply for enhanced support (for example extended hours or named technical contacts), onsite support, bespoke training, professional services (including custom integrations or transition assistance), and any non-standard export support such as bespoke reformatting or accelerated offboarding. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Our onboarding and offboarding documentation is provided in accessible digital formats and is structured to support use with common assistive technologies. Documents use clear headings and consistent navigation, meaningful link text, and plain language. Where documents are provided as PDFs, we aim to use tagged PDFs with selectable text (not scanned images), appropriate reading order, and descriptive headings. Images and diagrams are accompanied by descriptive text where required. Documentation is designed to be usable with keyboard-only navigation and screen readers. If a user experiences an accessibility barrier, we will provide reasonable adjustments, including alternative formats (for example, HTML, accessible PDF, or structured text) and assisted walkthroughs via email or call on request
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
Mobile Access Differences and Limitations
Anomaly Six services are optimised for secure desktop, tablet, and laptop environments. Mobile access is limited to smaller viewing and interoperable functionality and does not support large-scale visualisation, or complex analytical workflows. Certain features, including bulk analysis, and multi-layer geospatial rendering may be limited due to mobile processing and memory constraints. Performance and functionality may be constrained by device security policies, screen size, and network reliability. Mobile use is intended for situational awareness and high-level review rather than detailed analysis or operational tasking. - Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The service provides a secure web-based interface for authorised users to access the platform’s core capabilities, manage users and permissions, configure relevant settings, and review outputs. Access is controlled through authenticated user accounts and role-based permissions. Administrative functions are restricted to designated administrators. Audit and reporting features are available to support operational oversight.
- Accessibility standards
- None or don’t know
- Description of accessibility
- The service interface has not been formally certified against WCAG 2.2 or EN 301 549. Accessibility considerations are incorporated into design and QA, and issues reported by users are triaged and prioritised. Where required, reasonable adjustments can be agreed, and alternative support channels are available for users who experience accessibility barriers.
- Accessibility testing
- Formal testing with users of assistive technology has not yet been conducted. We design and review the interface with reference to recognised accessibility guidance, including US Section 508 expectations. Internal QA includes checks for keyboard-only operation, focus order and visibility, colour contrast, semantic structure (for example headings and labels) and basic screen reader operability checks using common tools. Accessibility feedback is welcomed and issues are prioritised for remediation. Targeted testing with assistive technology users can be arranged where required.
- API
- Yes
- What users can and can't do using the API
- The service provides an API for authorised users to integrate with external systems and automate key workflows. Users can provision and configure supported settings via the Gateway Connect application which operates similar to an API, and can retrieve outputs and relevant metadata programmatically. Administrative actions are restricted by role-based access control and API credentials scoped to the buyer’s tenant. Some configuration and operational actions may be limited to the web interface for security and safety reasons, or may require supplier enablement. Gateway Connect credit rates provide necessary thresholds quotas apply to protect platform stability. Full endpoint coverage, limitations, and example workflows are provided in the API documentation.
- API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Buyers can customise the service through tenant-level configuration, subject to their permissions. Typical customisation includes user roles and access controls, configurable settings relevant to the service, alerting or notification preferences, and integration configuration (where applicable). Customisation is performed by designated buyer administrators via the service interface (and via the API where enabled). Deep customisation such as bespoke feature development is not part of the standard service and, where required, would be handled as a separately scoped professional services engagement subject to feasibility, security review, and commercial agreement.
Scaling
- Independence of resources
- Anomaly 6 foundationally creates technologies to scale demand so that users are not adversely affected by other users’ demand through tenant isolation and controlled resource allocation. The service applies quotas and rate limiting to prevent any single tenant from consuming disproportionate capacity, and we monitor utilisation and performance to identify and remediate contention. Capacity is managed to maintain stable performance under expected load, and where higher throughput is required, additional capacity can be provisioned and agreed to support the buyer’s baseline and peak usage requirements.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide service usage metrics to support operational oversight and security monitoring. Metrics typically include user activity (for example logins and session activity), request/transaction volumes (including API usage where enabled), access and authentication events, audit log events, and high-level service health indicators (for example availability and error rates). The exact metrics available depend on the buyer’s configuration, enabled features, and any agreed reporting requirements
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Anomaly Six LLC
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Other
- Other data at rest protection approach
- Anomaly 6 adheres to international stat protection standards. Buyer-specific data held by the service is limited (for example, user access credentials, access-control settings, and configuration). Use of industry-standard, FIPS-validated encryption, such as AES-256, is required to protect controlled data stored on laptops, servers, databases, and backup media. Anomaly 6 protects backup data at its storage locations (Practice MP.L2-3.8.9). This ensures that if physical backup media is stolen or compromised, the data remains unreadable.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Users can export all Anomaly 6 data in csv, tsv, psv, json, xlsx, geojson, and kml formats. Users can export the limited buyer-specific data held within the service (primarily user accounts, access-control/configuration settings, and any buyer-specific audit or support records) by submitting an export request to the support team. Exports are provided in a commonly used machine-readable format and transferred securely to a nominated buyer contact. The core content accessed through the service is supplier-provided data rather than customer-supplied data, so there is no bulk customer dataset to export beyond these buyer-specific records.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- JSON
- Geojson
- Kml
- Psv
- Tsv
- Xlxs
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- JSON
- Psv
- Tsv
- Kml
- Geojson
- Xlxs
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection between networks
- Where required by the buyer, additional network protections (such as VPN or private connectivity) can be agreed as part of the deployment. This can also include white listing connections or access controls.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection within supplier network
- CMMC 2.0 requires defense contractors to protect Controlled Unclassified Information (CUI) using encryption validated by FIPS 140-2/3 standards, primarily mapping to NIST SP 800-171 controls (Level 2). Key requirements include using AES-256 for data at rest and TLS 1.2+ for data in transit. Proper implementation, including secure key management, is essential for compliance.
Availability and resilience
- Guaranteed availability
-
Anomaly Six shall maintain a minimum uptime of ninety-eight percent (98%) for all contracted technology, products, and services, measured on a monthly basis.
Anomaly Six shall provide Client with no less than seventy-two (72) hours' advance written notice of scheduled maintenance that may affect system availability. Scheduled maintenance windows shall not count against uptime calculations.
Monthly uptime percentage shall be calculated as follows: ((Total minutes in month – Unscheduled downtime minutes) / Total minutes in month) × 100.
Anomaly Six represents and warrants that the supply of the Data will conform to the service levels as detailed in the SLA.
In the event Anomaly Six fails to meet the uptime commitment
specified in Section 1.1, Client shall be entitled to service credits as follows:
Monthly Uptime Percentage Service Credit (% of Monthly Fees)
97.0% – 97.9% - 5%
95.0% – 96.9% - 10%
90.0% – 94.9% - 20%
Below 90.0% - 30%
Service credits shall be applied to the next invoice following approval. Service credits are non-transferable, hold no cash value, and shall not exceed thirty percent (30%) of the applicable monthly fees in any given month. - Approach to resilience
-
The service is designed to be resilient through redundancy and operational controls that reduce single points of failure and support timely recovery from incidents. Platform components are monitored, and capacity and performance are managed to maintain stable operation under expected demand. Backup and recovery processes are in place to support restoration of service where required, and changes are controlled through defined release and rollback procedures to minimise operational risk.
The hosting environment uses resilient datacentre infrastructure with physical security controls and managed facilities operations. The service is deployed on infrastructure designed for high availability, with fault-tolerant configuration of critical components and procedures to respond to and recover from component or site-level degradation. Further details of the datacentre resilience design (including specific architectural patterns and hosting configuration) are available to buyers on request, subject to contractual and security constraints. - Outage reporting
-
Anomaly Six shall provide Client with no less than seventy-two (72) hours' advance written notice of scheduled maintenance that may affect system availability.
In the event Anomaly Six fails to meet the data quality threshold specified Anomaly Six shall notify Client within forty-eight (48) hours of identifying that data holdings have fallen below the minimum threshold.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Dedicated link (for example VPN)
- Username or password
- Other
- Other user authentication
- Physical tokens
- Access restrictions in management interfaces and support channels
- Access to management interfaces is restricted to authorised administrators using role-based access control and least-privilege permissions. Administrative actions require authenticated accounts and are logged for audit. Privileged access is limited to named personnel, reviewed periodically, and removed promptly when no longer required. Support channels verify requester identity and authority before taking actions that affect configuration, access, or data. Sensitive requests (for example user changes, access resets, or configuration updates) require validation against the buyer’s nominated contacts and may require additional approvals. At all times, Anomaly 6 requires multi-factor authentication and secure credential handling are used to reduce unauthorised access risk.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Other
- Other security governance standards
- Anomaly 6 supports CMMC2.0, IL5, IL6, IL7, NIST SP 800-171 controls (Level 2), or any applicable government requirement as determined by the client, include using AES-256 for data at rest and TLS 1.2+ for data in transit.
- Information security policies and processes
-
Information security is governed through documented policies and procedures covering access control, secure development, vulnerability management, incident response, logging and monitoring, change management, data protection and retention, and supplier/third-party risk. Accountability sits with a named senior security lead (with escalation to executive leadership as required), supported by engineering and operations leads responsible for implementation within their areas.
Policies are embedded into day-to-day delivery through role-based access controls and least-privilege administration, mandatory security practices within the development and release lifecycle (for example code review and controlled deployments), centralised audit logging, and routine review of security events and vulnerabilities. Compliance is reinforced through onboarding and periodic awareness training, documented operational runbooks, and management oversight of key security activities (for example patching, incident handling, and access reviews). Security issues and incidents are reported through defined channels, triaged by severity, and escalated via an agreed escalation path with timely communication to the buyer where relevant. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Configuration and change management follows documented, supplier-defined controls. Service components are tracked through their lifecycle using version control and configuration management tooling. Changes are assessed for operational and security impact, reviewed and approved prior to deployment, and implemented using controlled release processes with rollback where appropriate. Changes to production are logged and auditable.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Vulnerabilities are managed through a documented process combining monitoring, assessment, remediation and verification. Potential threats are identified using vendor security advisories, automated scanning of systems and dependencies, and review of security-relevant logs and alerts. Findings are risk-assessed and prioritised based on severity, exploitability, exposure, and potential impact. Patching is deployed on a risk-based basis: critical vulnerabilities follow an expedited change process as soon as practicable, with mitigations applied where immediate patching is not possible; lower-severity updates are released through planned maintenance windows using controlled deployment and rollback procedures. Threat intelligence sources include vendor notifications, reputable advisory feeds and CVE reporting.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Protective monitoring is implemented through centralised logging and alerting on security-relevant events across the service. Potential compromises are identified through automated detections and periodic review of alerts and audit logs. When a potential compromise is detected, it is triaged by severity, containment actions are taken as appropriate (for example restricting access, isolating affected components, or disabling credentials), and an investigation is initiated to determine scope and remediation. Incidents are escalated through defined channels and handled under documented incident response procedures. Critical incidents are responded to on an expedited basis as soon as practicable.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We maintain documented incident management procedures, including playbooks for common events (for example suspected account compromise, service outage, vulnerability exploitation, and data integrity concerns). Incidents can be reported by users via support channels, and are triaged and prioritised by severity with escalation where required. We provide incident communications and reports to buyers in line with contractual requirements, including a summary of impact, actions taken, and recommended mitigations. For high-severity incidents, updates are provided during the incident as appropriate, followed by a post-incident report and, where applicable, root cause analysis once the incident is resolved.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- In coordination with prospective customers, Anomaly Six offer a limited trial access to the service for evaluation purposes. This is usually for a two week period, but can be arranged on a case-by-case basis.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 10%
- Between £250,000 and £500,000
- 11%
- Between £500,001 and £1,000,000
- 12%
- Between £1,000,001 and £2,500,000
- 13%
- Between £2,500,001 and £5,000,000
- 14%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 35bbcb65-5871-4881-bb22-b3c9aa5a03b9
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 9bc9c65e-ed94-4202-9a52-f95323d6b0d3
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
-