A platform about trust has to earn it too. Here's how we keep you safe.
In plain language: how accounts are made, why we can only check websites you've proven are yours, how your data is protected, and what we deliberately don't claim. No badges to wave around — just the actual protections, so you can judge them for yourself.
Nothing happens until you prove who you are — and what's yours
The two things most open to abuse on a scanning tool are creating accounts and the scanners themselves. TrustCtrl puts both behind proof.
Nothing created until you confirm
No account and no data exist until you confirm your email address — through a one-time link that's valid for 24 hours. The sign-up process is rate-limited and built so it can't be used to fish for which email addresses exist.
You prove the website is yours
Full checking only starts once you've shown you own a website, with a single small setting we guide you through (a DNS record). Until then it gets light, passive checks only — so nobody can point TrustCtrl at a website they don't own.
Watched from the outside
TrustCtrl looks at your website from the outside, the way your customers and attackers see it. There's nothing to install on your servers and no access for you to hand over.
Strong logins, and access only where it's needed
Access to your findings is access to a map of your weak spots — so it's protected accordingly.
Two-factor login
Two-factor login (2FA) with an authenticator app is built in, and an administrator can require it for everyone in your organisation — so no account can skip it.
The right access for each person
You can give each person access to only the part they need — the web team gets SiteControl, the mail team gets MailControl, and administration stays separate (role-based permissions). People see what their role needs, no more.
A respectful inbox
We only email you when something needs action now — your site down, a broken login or checkout, a fake site impersonating you, an invalid certificate, a blacklist listing. Routine findings stay in the dashboard and weekly summary, so an urgent alert still means something.
Protected where it's stored, careful where it reaches
A platform that checks other people's websites has a duty in both directions: protect what it stores, and make sure its own scanners can't be turned into a weapon.
Your data is encrypted
Sensitive data is encrypted when it's stored (AES-256-GCM) and protected while it travels (TLS) — nothing sensitive sits around in plain text.
EU hosted, GDPR-aligned
TrustCtrl is hosted in the EU and run by Certiva ApS, a Danish company (CVR 46450965). Data processing is GDPR-aligned, and a data processing agreement is available.
Scanners that can't be tricked
Our scanners are hardened so they can't be fooled into reaching into private or internal systems (protection against SSRF and DNS-rebinding attacks) — a check stays a check.
Honest about where we are
TrustCtrl doesn't currently hold ISO 27001 or SOC 2 certification, and we won't pretend otherwise. What's on this page is how the platform is actually built — described plainly enough that you can judge it on the real protections, not on badges. If you have questions for a purchase decision, just ask us.
Security questions, answered plainly
Can someone use TrustCtrl to check a website they don't own?
No. Full checking only starts once the account has proven it owns the website, with a single small setting we guide you through. Until then a website gets light, passive checks only — so nobody can point TrustCtrl at a website they don't own.
How is my account protected?
With two-factor login using an authenticator app, which an administrator can require for everyone, plus the ability to give each person access to only the part they need. And nothing is created until you confirm your email through a one-time link valid for 24 hours.
Is TrustCtrl ISO 27001 or SOC 2 certified?
No. TrustCtrl doesn't currently hold ISO 27001 or SOC 2 certification, and we don't claim accreditations we don't have. Instead we describe the real protections openly — confirm-first sign-up, proving you own a website before checking, two-factor login, per-person access, encrypted data, and scanners that can't be tricked into internal systems — so you can assess them directly.
The sign-up is the first protection you'll meet
Create an account and you'll see the confirm-first sign-up and the prove-you-own-it step for yourself — free during early access, no credit card.