This page is maintained by the CtrlApp team to answer common security and privacy questions about the CtrlApp control plane and its mobile SDKs. It describes controls that are enabled today. It is not an independent audit and is not a compliance certification.
Private beta: CtrlApp is currently in private beta. Terms of Service, Privacy Policy, and DPA are under legal review; contact us for the current draft before onboarding regulated workloads.
CRON_SECRET bearer token; the public anon key is not accepted for privileged endpoints.End users of apps built on CtrlApp should submit privacy requests to the operator of that app in the first instance — the app owner is the controller of end-user data. CtrlApp acts as a processor and will assist app owners in fulfilling deletion, export, and rectification requests.
To request deletion of your CtrlApp account data, email privacy@ctrlapp.krdcode.com.
We appreciate coordinated disclosure. Please email security@ctrlapp.krdcode.com with a description, reproduction steps, and any proof-of- concept. Do not run automated scanners against production traffic and do not access data belonging to other tenants.
A more formal disclosure policy will be published at /.well-known/security.txt when the private beta concludes.
CtrlApp does not currently claim SOC 2, ISO 27001, HIPAA, or PCI compliance. Statements about GDPR, CCPA, or other regulatory frameworks will be added here after review by qualified counsel; contact us for the current state before onboarding regulated workloads.
Real-time operational status is at /status. Uptime monitors can poll /api/public/ready for a deep DB check or /api/public/health for a lightweight liveness check.
Last reviewed: 2026-09-03. This page describes controls in effect on the current CtrlApp production build and is edited by the CtrlApp team as the product evolves.