Security, Privacy & Trust
Built for the moments when everything else needs to hold.
Control-C exists to protect the data your business relies on.
Security, privacy, and operational resilience are not features of our platform; they are the foundation of it.
Every backup, every snapshot, every restore workflow, and every advisory touchpoint is designed with one principle:
If you trust us with your data, we protect it as though we run your business ourselves.
SMB1001 Cyber Security Framework
Silver-aligned controls: working toward certification.
Control-C aligns its security programme with SMB1001 Cyber Security Framework Silver maturity practices. Control-C has not yet applied for or received SMB1001 certification.
SMB1001 is designed specifically for small and mid-size organizations that need security controls with real-world practicality. It maps directly to:
- ACSC Essential Eight
- UK Cyber Essentials
- CMMC
- ISO 27001
- Right Fit for Risk
What Silver means
The Silver control set reflects consistent execution of core security policies and controls across engineering, infrastructure, and business operations.
SMB1001 Tiers (for context)
- Bronze: Foundational protections (firewalls, backups, patching, antivirus, training)
- Silver: Formalized policies with consistent enforcement across the business (the level Control-C aligns to)
- Gold: Enhanced monitoring, proactive incident response, and stronger access controls
- Platinum: Independent audit validation
- Diamond: Highest assurance, advanced threat resilience
Our goal is simple:
build resilience that scales with the organizations we protect.
Defense in Depth
Multiple layers of protection: people, process, and technology.
Security at Control-C is never one control, one tool, or one team. We build overlapping layers that work together.
Governance & Oversight
- Executive-led security council
- Annual risk assessments
- Regular policy reviews aligned to SMB1001
- Clear accountability pathways from engineering to leadership
Training & Human Security
- Company-wide security awareness
- Role-based secure engineering training
- Recurring phishing simulations and testing
- Secure-by-default practices embedded into onboarding
Access Management
- SSO everywhere
- Mandatory MFA
- Device compliance enforcement
- Quarterly access reviews for all production and internal systems
- Least-privilege access by design
Secure Development Lifecycle
Security built into every stage of engineering.
Design
- Threat modeling for new features
- Privacy impact assessments
- Architectural review gates
Build
- Automated dependency scanning
- Static and dynamic code analysis
- Infrastructure-as-code validation
Release
- Mandatory peer review
- Segregation of duties
- Staged deployments with automatic rollback
- Continuous integration with security gates
Outcome:
Features only ship when they meet our standards for security, privacy, and resilience.
Infrastructure & Operations
Secure by default. Resilient under pressure.
Hosting & Network Security
- Control-C has three sovereign data locations. AU backup data is stored in Australia, NZ backup data in New Zealand, and UK backup data in the United Kingdom. Available locations depend on the product.
- NZ service: Primary platform infrastructure hosted in Wellington, New Zealand
- NZ service: Secondary failover infrastructure hosted in Auckland, New Zealand
- Carrier-neutral network design and least-exposure architecture
- Network segmentation and controlled service exposure
- Web Application Firewall (WAF)
- DDoS mitigation and rate-limiting
Observability & Monitoring
- Real-time logging and anomaly detection
- Automated alerts to our Security Operations function
- Proactive monitoring for risky or unusual activity
Backup Integrity
- Data encrypted in transit and at rest
- NZ service: Dual-region replication across Wellington and Auckland for durability
- Downloadable backup exports and In-Control offline access as independent recovery paths
- Quarterly restore tests to validate integrity and recoverability
Vulnerability Management
Find issues early. Fix them fast.
- Weekly scanning of containers, hosts, and dependencies
- Automated patch pipelines
- Remediation targets:
- Critical: 7 days
- High: 14 days
- Medium: 30 days
- Annual third-party penetration tests
- Additional ad-hoc tests for major product changes
Our commitment:
Risks are identified quickly, triaged responsibly, and resolved within strict SLAs.
Incident Response
Clear playbooks. Dedicated responders. Honest communication.
Control-C maintains a structured IR program covering:
- Security events
- Privacy incidents
- Continuity events
- Vendor outages
- Disaster recovery scenarios
During an active incident
- Dedicated responders are on call 24/7
- We communicate via our Trust Center and status page
- Customers are informed early and kept updated
- Containment, investigation, and recovery are run according to formal playbooks
After an incident
- Post-incident reviews
- Documented learnings
- Improvements to controls, automation, and prevention
We treat every incident as an opportunity to strengthen the entire platform.
Reporting & Contact
If you have a concern, you can reach us directly.
Security Issues:
security@control-c.com
(PGP key available in the Trust Center)
Privacy Questions:
compliance@control-c.com
Urgent Escalations:
Trust Hotline: +64 9 555 0192
Last Updated: March 20, 2025
Control-C: Backup that remembers everything.


