Your business runs on this site.
We treat it that way.
SiteCTRL hosts real businesses' websites, domains, email, and analytics — so security isn't a feature tier, it's the default on every plan, including free. This page describes what we actually do today, in plain English. We only claim what's true.
Encrypted in transit, everywhere
Every SiteCTRL surface — your dashboard, your published sites, your custom domains — is served over HTTPS with automatically managed TLS certificates. Origin servers sit behind Cloudflare tunnels and are never exposed to the public internet directly.
Your site's data is isolated to your site
Each site gets its own database schema and its own directory tree on our servers — not rows in a shared pool. Your visitor analytics are stored in yoursite's own tables, never shared with or visible to other customers. Custom-backend (Studio) workloads run in isolated containers with their own dedicated databases, resource limits, and no network path to other tenants.
The AI can't publish by itself
Every AI edit lands on a private draft first. Before anything reaches your live site, a second, independent AI review checks the change — links, SEO tags, tracking pixels, brand consistency — and youmake the final call. A full snapshot is taken before every publish, so one click restores exactly what was there before. Each editing turn is also checkpointed, so “undo what that last message did” is always available.
Secrets and credentials
Credentials you connect (like a Shopify Admin token) are encrypted at rest with a dedicated key-encryption key and decrypted only at the moment of use. Mailbox passwords are write-through to the mail system — we never store a copy. Payments run entirely through Stripe; card numbers never touch our servers.
Access control, enforced server-side
Site roles (owner, editor, view-only) are checked on the server on every request — a view-only member physically cannot submit edits, and only owners can publish, manage domains, or delete a site. Free accounts must verify their email before a site can be created. Google sign-in is supported and verified by Google.
AI processing and your content
AI editing runs on Anthropic's Claude models via their API. Anthropic does not use API data to train its models by default. Your site content is sent to the model only to perform the edits you ask for, scoped to the site you're editing — agents on one site cannot modify another site, and can never see other customers' sites at all.
Backups and recoverability
Hosted sites are backed up on a schedule to encrypted, append-only repositories, and destructive operations take a safety snapshot first. Deleting a site archives its data before removal. Pre-publish snapshots mean rollback is one click for the life of the site.
Platform hardening
Internal APIs are double-filtered (application allowlist + edge rules), admin operations are token-gated, agent tools run behind guardrails with per-class error handling, rate limits protect AI-facing endpoints, and bot traffic is filtered out of analytics at ingest. The customer-site serving plane is separated from the platform plane, so platform deploys don't touch live customer traffic.
Certifications & roadmap
SiteCTRL does not currently hold SOC 2 or ISO 27001 certification, and we won't pretend otherwise. Formal SOC 2 examination is on our roadmap as the platform grows; the controls described above are the foundation it will audit. If your organization needs security documentation for review, email us and we'll walk you through our architecture directly.
Reporting a vulnerability
Found something? We want to know, fast. Email [email protected] with “Security” in the subject. We read every report, respond quickly, and credit researchers who report responsibly.
See also our Privacy Policy and Terms of Service. This page is updated whenever our practices change.