Trust centre
Security and privacy
How secctl.io handles your data, what you control yourself, and what we don't have yet. Written for the person who has to check it before you start.
Where your data is stored
We host in the European Union, and in the Netherlands only if you prefer.
Tell us when you request your environment, and your environment runs in a data centre in the Netherlands.
The parties that process data on our behalf, such as hosting, are on our list of sub-processors, which we send you on request. The data processing agreement covers how we work with them.
Each customer is kept separate
Each customer gets a separate environment with its own database. Your data is never stored in the same database as another customer's.
If your organisation is a group with several companies, each company gets its own schema in the database within your environment. Group administrators can report across all companies.
Signing in
You sign in with your password and a second factor: a code from an authenticator app, or a passkey.
- An authenticator app on your phone shows a code that keeps changing.
- A passkey lets you sign in with your fingerprint, face or PIN, without typing a code.
- A passkey works on the web address of your own environment.
What employees can do themselves
Employees exercise their GDPR rights in Awareness themselves, without needing you or us.
- See which data Awareness holds about them (Article 15 GDPR).
- Download that data as a file (Article 20 GDPR).
- Delete their own data (Article 17 GDPR).
For Awareness, your organisation is the controller of your employees’ data and secctl.io processes it on your instructions. The data processing agreement sets this out.
During the Active Directory assessment
We only test with your written permission and within the scope we agree together.
- The tooling refuses any target outside the agreed scope. An empty scope means nothing is tested.
- Every action goes into an append-only log, including actions that were refused.
This website
This website sets no cookies and does not track who visits.
- Everything your browser loads comes from secctl.io itself. No fonts, scripts or images from other parties.
- A form on this site sends your message to us by email.
What secctl is still working on
secctl.io started in 2026. This is still open, and it says so here.
- secctl.io does not hold an ISO 27001 certificate itself.
- We don’t quote an availability percentage. We haven’t measured it yet.
Found a vulnerability?
Please report it to us. Tell us what you did and what you saw.
Email security@secctl.io. The responsible disclosure page explains how we handle your report. Our reporting address is also in security.txt.
Documents
The agreements in writing. These are drafts that are still being reviewed by a lawyer.
Try it with your own team for 30 days
You won't need payment details. Rather talk first? Pick a time that suits you.