Security
Last updated: 30 September 2026
SiteCtrl takes the security of your data seriously. We implement industry-standard technical and organisational measures to protect your information throughout its lifecycle — in transit, at rest, and during processing. This page describes our security posture and the measures we have in place.
Infrastructure
The SiteCtrl platform is hosted on Vercel, a leading cloud platform that provides:
- SOC 2 Type II compliant infrastructure — independent audits validate their security controls
- ISO 27001 certified data centres
- Data stored in physically secured facilities with 24/7 monitoring and access controls
- Redundant network infrastructure with DDoS protection
Data is primarily stored in the [region] region, with cross-region backups for disaster recovery.
Encryption
Data in Transit
- All traffic between your browser and our servers is encrypted using TLS 1.3.
- API endpoints enforce HTTPS with strong cipher suites.
- HSTS (HTTP Strict Transport Security) is enabled to prevent protocol downgrade attacks.
Data at Rest
- All data stored in our databases is encrypted at rest using AES-256encryption.
- File attachments and uploaded documents are encrypted using server-side encryption.
- Database backups are encrypted before leaving the data centre.
- Encryption keys are managed using a dedicated key management service with automatic rotation.
Access Controls
Application-Level Access
- Role-Based Access Control (RBAC): Every user action is authorised against a defined set of permissions scoped to System, Company, or Site level.
- Granular Permissions: Permissions follow the
<resource>:<action>format, ensuring users have precisely the access they need and nothing more. - Site-Level Isolation: Users can only access data for the specific Sites they are assigned to. Cross-site data access is prohibited by the permission model.
Administrative Access
- Just-in-Time (JIT) Access: Production infrastructure access is granted on a temporary, request-approved basis with automatic revocation.
- Multi-Factor Authentication (MFA): Required for all administrative access to production systems.
- Audit Logging: Every administrative action is logged and monitored. Logs are immutable and retained for security analysis.
Authentication
- Phone-based Authentication: Users authenticate using their phone number via OTP (one-time password), ensuring that account access is tied to a verified contact.
- Session Management: Sessions are secured with HTTP-only, SameSite cookies and automatically expire after a period of inactivity.
- Account Lockout: Repeated failed authentication attempts trigger a temporary account lockout to prevent brute-force attacks.
Data Protection
Data Segregation
Customer data is logically segregated at the application layer. Each Company’s data is isolated through the permission and policy system. Database-level access is restricted to the application service account with no direct customer access to the underlying data store.
Backups
- Encrypted daily backups with point-in-time recovery capability
- Cross-region backup storage for disaster recovery
- Regular backup restoration testing to verify data integrity
- Retention period in accordance with our data retention policy
Data Deletion
Upon account termination, Customer Data is scheduled for secure deletion. Deletion follows a multi-pass process that renders data irrecoverable. Archived backups containing the data are destroyed at the end of the retention cycle.
Monitoring and Incident Response
Monitoring
- 24/7 automated monitoring of infrastructure, application performance, and security events
- Intrusion detection and prevention systems
- Real-time alerting for anomalous activity patterns
- Centralised log aggregation with tamper-proof storage
Vulnerability Management
- Automated dependency scanning for known vulnerabilities (CVE monitoring)
- Regular penetration testing conducted by independent third-party security firms
- Prompt patching of identified vulnerabilities based on severity
Incident Response
We maintain a documented incident response plan that covers:
- Classification and prioritisation of security incidents
- Containment, eradication, and recovery procedures
- Communication protocols, including regulatory notification where required
- Post-incident review and remediation
Application Security
Secure Development
- Code reviews for every change before deployment
- Automated security scanning in the CI/CD pipeline
- Dependency vulnerability scanning
- Input validation and output encoding to prevent injection attacks
- CSRF protection on all state-changing endpoints
- Rate limiting on authentication and API endpoints
Third-Party Dependencies
All open-source dependencies are continuously monitored for known vulnerabilities. We use automated tooling to detect and alert on security advisories affecting our dependency tree.
Organisational Measures
- All employees and contractors undergo security awareness training on onboarding
- Access to production systems is granted on a least-privilege basis
- Background verification checks for employees handling sensitive data
- Confidentiality agreements binding all team members
Compliance
Our security practices are aligned with:
- DPDP Act, 2023 — India’s Digital Personal Data Protection Act
- IT Act, 2000 — India’s Information Technology Act (including IT Rules, 2011)
- ISO/IEC 27001 — Information security management principles (infrastructure layer)
Reporting a Vulnerability
If you discover a security vulnerability in the SiteCtrl platform, please report it responsibly to our security team:
Security Team
[Email address]
We ask that you:
- Provide sufficient detail to reproduce and validate the issue
- Allow us reasonable time to investigate and remediate before public disclosure
- Act in good faith to avoid privacy violations, data destruction, or service disruption
We acknowledge valid security reports and work to address them promptly.
Contact
For security-related inquiries, please reach out to us:
SiteCtrl
[Email address]
[Registered address]