The Control-C Trust Center provides real-time visibility into our security, privacy, and compliance posture. Use this page to access independent attestations, review policies, and subscribe to updates affecting your business continuity programs.
Platform Security
- Sovereign data storage: AU, NZ and UK: Control-C has three sovereign data locations. AU backup data is stored in Australia, NZ backup data in New Zealand, and UK backup data in the United Kingdom. Available locations depend on the product. Encryption at rest (AES-256) and in transit (TLS 1.2+) is enforced by default.
- Identity & Access: Single sign-on (SAML, OIDC), SCIM provisioning, and mandatory MFA for privileged roles. Role-based access control enables least-privilege assignments.
- Secure Development: Integrated secure SDLC, static analysis, dependency scanning, and peer-reviewed pull requests. Production deployments require automated and manual approvals.
Compliance and Security Alignment
- SMB1001 Cyber Security Framework: controls aligned with Silver maturity practices; certification has not yet been applied for or awarded.
- Control mappings maintained against Essential Eight, UK Cyber Essentials, CMMC, ISO 27001, and Right Fit for Risk to simplify evidence crosswalks.
- HIPAA Business Associate Agreement requests can be reviewed for applicable workloads.
- SMB1001-aligned control mapping is available for NIST CSF, CIS Critical Security Controls, and FFIEC due diligence discussions.
Request compliance documentation or complete due diligence questionnaires by emailing [email protected].
Data Protection and Privacy
- Privacy Policy and GDPR Statement outline lawful bases, rights management, and supervisory contacts.
- Control-C has three sovereign data locations. AU backup data is stored in Australia, NZ backup data in New Zealand, and UK backup data in the United Kingdom. Available locations depend on the product.
- Annual third-party penetration tests, quarterly tabletop exercises, and simulated phishing campaigns strengthen incident readiness.
Incident Response
- 24/7 security operations with defined playbooks for vulnerability handling, data breaches, and platform outages.
- Customer notifications delivered via the status page, email, and in-product alerts.
- Post-incident reviews are shared with impacted customers, including root cause, remediation, and prevention steps.
Business Continuity
- NZ service: Primary infrastructure in Wellington with geographically independent failover capability in Auckland.
- NZ service: Dual-region replication, downloadable backup exports, optional customer-controlled storage, and In-Control offline access provide multiple independent recovery paths.
- Disaster recovery tests and continuity exercises are conducted regularly, with executive summaries available under NDA where appropriate.
- Vendor risk management program evaluates critical suppliers quarterly, aligning with our Subprocessor Registry.
Infrastructure Framework
- Infrastructure & Business Continuity — See the regional storage information and independent recovery options in our infrastructure overview.
Stay Informed
- Subscribe to trust bulletins:
[email protected] - Report a vulnerability:
[email protected] - Media or analyst inquiries:
[email protected]
View live operational metrics and maintenance updates on the Control-C Status Page.
Last updated: May 18, 2026


