Product Use Cases Pricing Guides About Log in Start free
Security

A platform about trust has to earn it too. Here's how we keep you safe.

In plain language: how accounts are made, why we can only check websites you've proven are yours, how your data is protected, and what we deliberately don't claim. No badges to wave around — just the actual protections, so you can judge them for yourself.

Proof before anything runs

Nothing happens until you prove who you are — and what's yours

The two things most open to abuse on a scanning tool are creating accounts and the scanners themselves. TrustCtrl puts both behind proof.

Nothing created until you confirm

No account and no data exist until you confirm your email address — through a one-time link that's valid for 24 hours. The sign-up process is rate-limited and built so it can't be used to fish for which email addresses exist.

You prove the website is yours

Full checking only starts once you've shown you own a website, with a single small setting we guide you through (a DNS record). Until then it gets light, passive checks only — so nobody can point TrustCtrl at a website they don't own.

Watched from the outside

TrustCtrl looks at your website from the outside, the way your customers and attackers see it. There's nothing to install on your servers and no access for you to hand over.

Your account

Strong logins, and access only where it's needed

Access to your findings is access to a map of your weak spots — so it's protected accordingly.

Two-factor login

Two-factor login (2FA) with an authenticator app is built in, and an administrator can require it for everyone in your organisation — so no account can skip it.

The right access for each person

You can give each person access to only the part they need — the web team gets SiteControl, the mail team gets MailControl, and administration stays separate (role-based permissions). People see what their role needs, no more.

A respectful inbox

We only email you when something needs action now — your site down, a broken login or checkout, a fake site impersonating you, an invalid certificate, a blacklist listing. Routine findings stay in the dashboard and weekly summary, so an urgent alert still means something.

Your data & our scanners

Protected where it's stored, careful where it reaches

A platform that checks other people's websites has a duty in both directions: protect what it stores, and make sure its own scanners can't be turned into a weapon.

Your data is encrypted

Sensitive data is encrypted when it's stored (AES-256-GCM) and protected while it travels (TLS) — nothing sensitive sits around in plain text.

EU hosted, GDPR-aligned

TrustCtrl is hosted in the EU and run by Certiva ApS, a Danish company (CVR 46450965). Data processing is GDPR-aligned, and a data processing agreement is available.

Scanners that can't be tricked

Our scanners are hardened so they can't be fooled into reaching into private or internal systems (protection against SSRF and DNS-rebinding attacks) — a check stays a check.

What we don't claim

Honest about where we are

TrustCtrl doesn't currently hold ISO 27001 or SOC 2 certification, and we won't pretend otherwise. What's on this page is how the platform is actually built — described plainly enough that you can judge it on the real protections, not on badges. If you have questions for a purchase decision, just ask us.

Frequently asked questions

Security questions, answered plainly

Can someone use TrustCtrl to check a website they don't own?

No. Full checking only starts once the account has proven it owns the website, with a single small setting we guide you through. Until then a website gets light, passive checks only — so nobody can point TrustCtrl at a website they don't own.

How is my account protected?

With two-factor login using an authenticator app, which an administrator can require for everyone, plus the ability to give each person access to only the part they need. And nothing is created until you confirm your email through a one-time link valid for 24 hours.

Is TrustCtrl ISO 27001 or SOC 2 certified?

No. TrustCtrl doesn't currently hold ISO 27001 or SOC 2 certification, and we don't claim accreditations we don't have. Instead we describe the real protections openly — confirm-first sign-up, proving you own a website before checking, two-factor login, per-person access, encrypted data, and scanners that can't be tricked into internal systems — so you can assess them directly.

See it in practice

The sign-up is the first protection you'll meet

Create an account and you'll see the confirm-first sign-up and the prove-you-own-it step for yourself — free during early access, no credit card.