SiteCtrlSiteCtrl

Security

Last updated: 30 September 2026

SiteCtrl takes the security of your data seriously. We implement industry-standard technical and organisational measures to protect your information throughout its lifecycle — in transit, at rest, and during processing. This page describes our security posture and the measures we have in place.

Infrastructure

The SiteCtrl platform is hosted on Vercel, a leading cloud platform that provides:

  • SOC 2 Type II compliant infrastructure — independent audits validate their security controls
  • ISO 27001 certified data centres
  • Data stored in physically secured facilities with 24/7 monitoring and access controls
  • Redundant network infrastructure with DDoS protection

Data is primarily stored in the [region] region, with cross-region backups for disaster recovery.

Encryption

Data in Transit

  • All traffic between your browser and our servers is encrypted using TLS 1.3.
  • API endpoints enforce HTTPS with strong cipher suites.
  • HSTS (HTTP Strict Transport Security) is enabled to prevent protocol downgrade attacks.

Data at Rest

  • All data stored in our databases is encrypted at rest using AES-256encryption.
  • File attachments and uploaded documents are encrypted using server-side encryption.
  • Database backups are encrypted before leaving the data centre.
  • Encryption keys are managed using a dedicated key management service with automatic rotation.

Access Controls

Application-Level Access

  • Role-Based Access Control (RBAC): Every user action is authorised against a defined set of permissions scoped to System, Company, or Site level.
  • Granular Permissions: Permissions follow the<resource>:<action> format, ensuring users have precisely the access they need and nothing more.
  • Site-Level Isolation: Users can only access data for the specific Sites they are assigned to. Cross-site data access is prohibited by the permission model.

Administrative Access

  • Just-in-Time (JIT) Access: Production infrastructure access is granted on a temporary, request-approved basis with automatic revocation.
  • Multi-Factor Authentication (MFA): Required for all administrative access to production systems.
  • Audit Logging: Every administrative action is logged and monitored. Logs are immutable and retained for security analysis.

Authentication

  • Phone-based Authentication: Users authenticate using their phone number via OTP (one-time password), ensuring that account access is tied to a verified contact.
  • Session Management: Sessions are secured with HTTP-only, SameSite cookies and automatically expire after a period of inactivity.
  • Account Lockout: Repeated failed authentication attempts trigger a temporary account lockout to prevent brute-force attacks.

Data Protection

Data Segregation

Customer data is logically segregated at the application layer. Each Company’s data is isolated through the permission and policy system. Database-level access is restricted to the application service account with no direct customer access to the underlying data store.

Backups

  • Encrypted daily backups with point-in-time recovery capability
  • Cross-region backup storage for disaster recovery
  • Regular backup restoration testing to verify data integrity
  • Retention period in accordance with our data retention policy

Data Deletion

Upon account termination, Customer Data is scheduled for secure deletion. Deletion follows a multi-pass process that renders data irrecoverable. Archived backups containing the data are destroyed at the end of the retention cycle.

Monitoring and Incident Response

Monitoring

  • 24/7 automated monitoring of infrastructure, application performance, and security events
  • Intrusion detection and prevention systems
  • Real-time alerting for anomalous activity patterns
  • Centralised log aggregation with tamper-proof storage

Vulnerability Management

  • Automated dependency scanning for known vulnerabilities (CVE monitoring)
  • Regular penetration testing conducted by independent third-party security firms
  • Prompt patching of identified vulnerabilities based on severity

Incident Response

We maintain a documented incident response plan that covers:

  • Classification and prioritisation of security incidents
  • Containment, eradication, and recovery procedures
  • Communication protocols, including regulatory notification where required
  • Post-incident review and remediation

Application Security

Secure Development

  • Code reviews for every change before deployment
  • Automated security scanning in the CI/CD pipeline
  • Dependency vulnerability scanning
  • Input validation and output encoding to prevent injection attacks
  • CSRF protection on all state-changing endpoints
  • Rate limiting on authentication and API endpoints

Third-Party Dependencies

All open-source dependencies are continuously monitored for known vulnerabilities. We use automated tooling to detect and alert on security advisories affecting our dependency tree.

Organisational Measures

  • All employees and contractors undergo security awareness training on onboarding
  • Access to production systems is granted on a least-privilege basis
  • Background verification checks for employees handling sensitive data
  • Confidentiality agreements binding all team members

Compliance

Our security practices are aligned with:

  • DPDP Act, 2023 — India’s Digital Personal Data Protection Act
  • IT Act, 2000 — India’s Information Technology Act (including IT Rules, 2011)
  • ISO/IEC 27001 — Information security management principles (infrastructure layer)

Reporting a Vulnerability

If you discover a security vulnerability in the SiteCtrl platform, please report it responsibly to our security team:

Security Team

[Email address]

We ask that you:

  • Provide sufficient detail to reproduce and validate the issue
  • Allow us reasonable time to investigate and remediate before public disclosure
  • Act in good faith to avoid privacy violations, data destruction, or service disruption

We acknowledge valid security reports and work to address them promptly.

Contact

For security-related inquiries, please reach out to us:

SiteCtrl

[Email address]

[Registered address]