TotalCtrl
Subprocessors Vulnerability Disclosure Bug Bounty Compliance

Compliance

Last updated: August 2026

Formal compliance certification is in progress for 2026. For current information, or to request our security documentation, contact security@totalctrl.app.

We are engaging an external auditor and will publish our certification status here as that work completes. In the meantime we would rather point you at what already exists than at a badge we have not earned — if you are evaluating TotalCtrl and need to complete a security review, write to us and we will work through your questionnaire directly.

Available today

  • Privacy Policy — what we collect, how we use it, retention periods, and your rights, including our commitments on AI and model training.
  • Subprocessors — every third party that processes customer data on our behalf, what each does, and where it operates.
  • Vulnerability Disclosure Policy — how to report a security issue, and what we commit to doing about it.
  • Terms & Conditions, and a Data Processing Agreement on request.

How the platform is built

A summary, offered so that a security review has somewhere to start. We are happy to go into detail on any of it:

  • Hosting. Amazon Web Services, US East (us-east-1), on Amazon ECS behind an Application Load Balancer.
  • Encryption. TLS in transit. Amazon RDS for PostgreSQL with encryption at rest and Multi-AZ replication; Amazon S3 for file storage. Third-party credentials and signing secrets carry a second layer of application-level encryption before they are written to the database, so they are not readable from a database dump alone.
  • Tenant separation. Every record carries a workspace identifier and every query is scoped to the authenticated user's workspace.
  • Authentication. Email and password with mandatory two-factor authentication, Google, Microsoft and Apple sign-in, and per-workspace SAML/OIDC single sign-on. Signing out revokes the session server-side rather than only in the browser.
  • Access control. Role-based permissions per workspace, with a restricted guest tier for outside collaborators, and an audit log of administrative actions.
  • Backups. Encrypted automated backups with point-in-time recovery, plus retained snapshots. See our disclosure policy for how to reach us about anything you find in the above.
  • AI features. Customer data is not used to train models, ours or a vendor's. The Privacy Policy states this, and our Google Workspace integrations additionally adhere to Google's Limited Use requirements.

Security questionnaires, DPA requests and architecture questions all go to security@totalctrl.app.

← Back to TotalCtrl  ·  Privacy Policy  ·  Terms & Conditions