Formal compliance certification is in progress for 2026.
For current information, or to request our security documentation,
contact security@totalctrl.app.
We are engaging an external auditor and will publish our certification
status here as that work completes. In the meantime we would rather point
you at what already exists than at a badge we have not earned — if you are
evaluating TotalCtrl and need to complete a security review, write to us and
we will work through your questionnaire directly.
Available today
Privacy Policy — what we collect,
how we use it, retention periods, and your rights, including our
commitments on AI and model training.
Subprocessors — every
third party that processes customer data on our behalf, what each does,
and where it operates.
A summary, offered so that a security review has somewhere to start. We are
happy to go into detail on any of it:
Hosting. Amazon Web Services, US East
(us-east-1), on Amazon ECS behind an Application Load
Balancer.
Encryption. TLS in transit. Amazon RDS for PostgreSQL
with encryption at rest and Multi-AZ replication; Amazon S3 for file
storage. Third-party credentials and signing secrets carry a second layer
of application-level encryption before they are written to the database,
so they are not readable from a database dump alone.
Tenant separation. Every record carries a workspace
identifier and every query is scoped to the authenticated user's
workspace.
Authentication. Email and password with mandatory
two-factor authentication, Google, Microsoft and Apple sign-in, and
per-workspace SAML/OIDC single sign-on. Signing out revokes the session
server-side rather than only in the browser.
Access control. Role-based permissions per workspace,
with a restricted guest tier for outside collaborators, and an audit log
of administrative actions.
Backups. Encrypted automated backups with
point-in-time recovery, plus retained snapshots. See our
disclosure policy for
how to reach us about anything you find in the above.
AI features. Customer data is not used to train models,
ours or a vendor's. The
Privacy Policy
states this, and our Google Workspace integrations additionally adhere to
Google's Limited Use requirements.
Security questionnaires, DPA requests and architecture questions all go to
security@totalctrl.app.