Security and privacy at Control+s
How we protect assessment data, use language models, manage subprocessors, and handle security reports.
Effective 2026-04-18
TLS 1.2 or higher, enforced at the edge
Managed by our infrastructure providers
Authenticator-app 2FA for password accounts; SSO MFA via identity provider
Short-lived, isolated per-job sandboxes
Customer data is never used to train models
Role-based access at assessment and framework level
Application, admin, and access activity logged for operational review
Dedicated instances can store data in Canada, the US, the EU, or Australia
Overview
Control+s handles assessment evidence, control decisions, recommendations, and remediation data. This page explains how we protect that data, how we use language models, which subprocessors support the service, and how to contact us about security.
Data we process
Control+s processes the following categories of customer and account data:
- Customer-uploaded evidence and artifacts.
- Control mappings, maturity scores, recommendations, gaps, and notes.
- Account data, team membership, and authentication metadata.
- Support communications.
- Usage and audit metadata.
Do not upload production secrets, credentials, private keys, or regulated data unless your agreement and workspace configuration permit it.
Security practices
Our current technical and organizational measures include:
- Encryption in transit: TLS 1.2 or higher for all traffic, enforced at the edge.
- Encryption at rest: provided by our managed infrastructure (Convex, Cloudflare) using industry-standard algorithms.
- Authentication: passwordless magic link, password, enterprise SSO (OIDC), and authenticator-app 2FA for password accounts.
- Authorization: role-based access control at assessment and framework level; least-privilege access to production systems.
- Sandbox isolation: evidence analysis runs in short-lived, isolated cloud sandboxes created per job and destroyed on completion.
- Secrets and tokens: scoped, time-bounded callback tokens; no long-lived credentials issued to sandboxes.
- Logging and monitoring: application, admin, and access activity logged for operational review.
- Backups and recovery: managed by our hosting provider, rotated on a standard cycle.
- Secure development: code review, automated dependency monitoring, and separation of development and production environments.
- Vendor management: Subprocessors are contractually bound to equivalent security and privacy obligations (see below).
Model use
- Your data is yours. Customers own the evidence, assessments, and other content they upload. We process it only to provide the Service.
- No model training. Customer Content is not used to train models.
- Enterprise model processing. Language model requests run on Microsoft Azure through ShadeSec’s enterprise account, routed by OpenRouter, which does not store them. On the main instance, fallback providers are limited to Zero Data Retention (ZDR) endpoints. Dedicated instances can be limited to Azure only.
- Tenant isolation. Customer-specific assessment context is scoped to the relevant tenant and analysis job.
- Sandbox execution. Evidence analysis runs in short-lived, isolated E2B sandboxes created per job, with scoped callback tokens.
- Reviewer responsibility. Suggested mappings and scores are draft analysis. Control+s does not treat model output as final assessment evidence. Reviewers remain responsible for accepting mappings, ratings, gaps, and recommendations.
Data residency, export, deletion, and retention are described in the Privacy Policy.
Compliance
We maintain internal security controls and can provide security information for reasonable customer and prospective-customer diligence requests.
If your organization has specific compliance requirements (for example, a Data Processing Agreement, subprocessor review, or security questionnaire), write to contact@controls.run and we will work with you.
Subprocessors
We use a small number of third-party services to operate Control+s. Where data is processed depends on the instance. The table shows where each service runs for the main instance at controls.run, and the locations available to customers with a dedicated instance. We confirm a dedicated instance’s locations in writing when it is set up.
Dedicated instances can also keep evidence files with another S3-compatible storage provider in the customer’s region. A provider not listed here is added to this list before it receives customer data.
| Service | Purpose | Main instance | Dedicated instance options | Added |
|---|---|---|---|---|
| Convex | Application database and backups; evidence file storage on the main instance | United States (AWS US East, Virginia) | United States (Virginia), Canada (Montreal), European Union (Ireland), or Australia (Sydney) | 2026-04-18 |
| OVHcloud | Evidence file storage for dedicated instances | Not used | Canada (Beauharnois, Quebec) or Europe | 2026-07-14 |
| E2B | Short-lived, isolated sandboxes for evidence analysis | United States | United States or European Union | 2026-04-18 |
| Microsoft Azure | Language model processing through ShadeSec's enterprise Azure account. Prompts and outputs are not used to train models. | Global Azure processing | Global, United States or European Union data zone, or a single Azure region where the model is offered | 2026-10-08 |
| OpenRouter | Routes model requests to ShadeSec's Azure account without storing them. On the main instance, if Azure is unavailable, requests can fall back to other providers restricted to Zero Data Retention (ZDR) endpoints. | United States | United States; can be limited to Azure only, with no fallback | 2026-04-21 |
| Cloudflare | Edge routing, static asset hosting, DDoS protection, transactional email (magic links, invites, notifications), and diagnostic logs of analysis runs | Global edge network; diagnostic logs in North America | Global edge network | 2026-04-18 |
| PostHog | Product analytics and error logs | European Union | European Union | 2026-07-14 |
| Stripe | Payment processing and subscription billing | United States and Ireland | United States and Ireland, when card billing is used | 2026-04-18 |
List last reviewed 2026-10-08.
Subprocessor change notices
Customers authorize the subprocessors listed above when they begin using the Service or accept our DPA. We keep this list current and record material additions or replacements in the change log below and in the public Trust updates RSS feed. Customers with an active Data Processing Agreement may object on reasonable grounds as described in the DPA.
Frequently asked questions
Where is my data stored?
Is my data used to train models?
What is your breach notification timeline?
Can I export my data? What happens if I cancel?
Do you offer a Data Processing Agreement (DPA)?
How do you handle access control within my assessment?
How do I get a security questionnaire answered?
Reporting a vulnerability
If you believe you have discovered a security vulnerability in Control+s, please report it to contact@controls.run. Do not publicly disclose the issue until we have had a reasonable opportunity to investigate and respond. We appreciate responsible disclosure and will credit researchers who prefer public acknowledgment. See our security.txt for the machine-readable contact.
Updates
We record material changes to our trust posture here, including subprocessor additions or removals, policy updates, and certification milestones.
- 2026-10-08
- Added Microsoft Azure as a subprocessor. Language model requests run on ShadeSec's enterprise Azure account, routed through OpenRouter.
- The subprocessor list now shows where each service runs for the main instance and the locations available to dedicated instances, including Convex database hosting in Canada (Montreal), the European Union, and Australia.
- Cloudflare's listed purpose now includes diagnostic logs of analysis runs.
- 2026-07-17
- Completed consolidation of all evidence-analysis inference through OpenRouter across environments. The subprocessor description now states that underlying model providers vary by task and remain restricted to ZDR-compliant endpoints, rather than naming a fixed provider list.
- 2026-07-14
- Added PostHog (product analytics) as a subprocessor.
- Added OVHcloud (Canadian cloud hosting and file storage) as a subprocessor.
- 2026-04-21
- Consolidated AI inference through OpenRouter with Zero Data Retention (ZDR) enforced at the account level. Underlying providers (OpenAI, Anthropic, and others on the ZDR list) do not retain prompts or responses, and do not use them for model training.
- Subprocessor change: removed Anthropic (direct API), added OpenRouter (inference layer).
- 2026-04-18
- Initial publication of Terms of Service, Privacy Policy, Data Processing Agreement, and Trust page.
- Published subprocessor list: Convex, Cloudflare, E2B, Anthropic, Stripe.
- Published security.txt for vulnerability disclosure.
Contact
For security, privacy, trust, or compliance questions, email contact@controls.run.