Cyber and Physical Security Policy
Ctrl maintains a unified security program aligned to the frameworks below. Each policy governs how we protect customer data, mission data, and government information across our platforms and field operations.
Effective date: January 1, 2026 · Last reviewed: July 2026
1. Cyber and Physical Security Policy
Ctrl's overarching security policy governing physical access to facilities and equipment, protection of data captured in the field, backup and retention of customer data, and privacy protection within Ctrl's datasets.
Physical Security
- Facility access is controlled by electronic key fobs issued to authorized personnel only; fob access is logged, reviewed, and revoked immediately upon role change or offboarding.
- Lost or stolen fobs must be reported within 24 hours and are deactivated on report.
- Server rooms, equipment lockers, and drone hardware storage require secondary fob or key authorization restricted to designated staff.
- Visitors are escorted at all times and signed in/out; field equipment (drones, docks, sensors, storage media) is secured in locked cases or vehicles when unattended.
Data Backup
- Customer data, mission data, and imagery are backed up automatically on a daily cadence to geographically redundant cloud storage.
- Backups are encrypted at rest (AES-256) and access-restricted to authorized operations personnel.
- Restore procedures are tested at least annually to verify backup integrity and recovery time objectives.
Data Retention
- Customer data is retained for the duration of the customer relationship plus the period required by contract, law, or regulation.
- Raw field captures not attached to a deliverable are retained for 12 months by default, then securely deleted unless otherwise agreed.
- Upon contract termination or verified deletion request, customer data is securely destroyed within 30 days, including from backups on their normal expiry cycle.
Privacy Protection in Ctrl Datasets
- Unless otherwise stated in a customer agreement or required by lawful authority, faces, license plates, and other personal identification captured in Ctrl's datasets are blurred or redacted before data is published, shared, or used for analytics and model training.
- Redaction is applied through automated detection with human review for sensitive deliverables.
- Incidental capture of bystanders, private property interiors, and identifying documents is minimized through flight planning and, where captured, treated as personal information subject to this policy.
- Unredacted source material is access-restricted, retained only as long as operationally necessary, and never included in shared or open datasets.
2. SOC 1 — Internal Controls over Financial Reporting
Governs controls at Ctrl that are relevant to our customers' financial reporting (billing, subscription management, payment processing).
Scope
- Billing, invoicing, and subscription systems (including Stripe payment processing).
- Access controls over financial data and transaction records.
- Change management for systems that process customer financial transactions.
Control Objectives
- Transactions are authorized, complete, accurate, and recorded in the correct period.
- Logical access to financial systems is restricted to authorized personnel and reviewed quarterly.
- System changes affecting transaction processing are tested and approved before deployment.
- Processing exceptions are identified, logged, and resolved in a timely manner.
Assurance
- Ctrl aligns its controls to the SSAE 18 / CSAE 3416 attestation standards.
- A Type II examination (design and operating effectiveness over a review period) is targeted as the company scales; bridge letters are provided between report periods on request.
3. SOC 2 — Security, Availability, Confidentiality
Defines how Ctrl protects customer data across the Trust Services Criteria: Security (common criteria), Availability, Confidentiality, and — where in scope — Processing Integrity and Privacy.
Security (Common Criteria)
- Role-based access control with least privilege; MFA enforced on all administrative and production access.
- Encryption in transit (TLS 1.2+) and at rest (AES-256) for all customer data, imagery, and telemetry.
- Continuous logging and monitoring of production systems; alerts triaged on defined severity SLAs.
- Vulnerability management: dependency scanning, patching cadence, and annual penetration testing.
- Formal incident response plan with defined roles, escalation paths, and customer notification commitments.
Availability
- Redundant cloud infrastructure with automated backups and tested restore procedures.
- Business continuity and disaster recovery plans reviewed and exercised annually (RTO/RPO targets documented per system).
Confidentiality
- Customer geospatial data, mission data, and imagery are segregated by organization and never used across tenants.
- Confidential data is retained only as long as contractually required and securely destroyed on offboarding.
- All personnel and subcontractors sign confidentiality agreements before access is granted.
4. HIPAA Readiness Policy
Where Ctrl services touch protected health information (PHI) — e.g., emergency response or public-safety deployments involving U.S. covered entities — Ctrl operates as a Business Associate under the Health Insurance Portability and Accountability Act.
Safeguards
- Administrative: designated security official, workforce training, sanction policy, and access authorization procedures.
- Physical: controlled facility and device access; media disposal and re-use controls for any hardware holding PHI.
- Technical: unique user IDs, automatic session timeout, audit logging, integrity controls, and encryption of PHI in transit and at rest.
Business Associate Obligations
- Ctrl executes Business Associate Agreements (BAAs) with covered entities before receiving PHI.
- PHI is used or disclosed only as permitted by the BAA and the HIPAA Privacy Rule (minimum necessary standard).
- Breach notification to the covered entity without unreasonable delay and no later than 60 days after discovery.
- Subcontractors handling PHI are bound by equivalent downstream BAAs.
5. GDPR Compliance Policy
Governs Ctrl's processing of personal data of individuals in the European Economic Area and the United Kingdom under the EU GDPR and UK GDPR.
Principles & Lawful Basis
- Personal data is processed lawfully, fairly, and transparently, for specified purposes, minimized, accurate, storage-limited, and secured (Art. 5).
- Processing relies on documented lawful bases: contract performance, legitimate interests (balancing-tested), consent, or legal obligation (Art. 6).
Data Subject Rights
- Access, rectification, erasure, restriction, portability, and objection requests are honoured within one month.
- Requests may be sent to data@goctrl.ca; identity is verified before disclosure.
Transfers, Processors & Accountability
- International transfers rely on adequacy decisions or Standard Contractual Clauses with transfer impact assessments.
- Data Processing Agreements (Art. 28) are executed with all processors; a Record of Processing Activities (Art. 30) is maintained.
- Data Protection Impact Assessments are conducted for high-risk processing, including aerial imagery that may capture individuals; supervisory authorities are notified of eligible breaches within 72 hours.
- Drone-captured imagery is planned, minimized, and where required, blurred or redacted to protect bystander privacy.
6. ISO/IEC 27001 — Information Security Management System
Ctrl operates an Information Security Management System (ISMS) aligned to ISO/IEC 27001:2022, providing the governance framework under which all other security policies operate.
ISMS Governance
- Defined ISMS scope covering the Ctrl platform, data pipelines, and supporting infrastructure.
- Leadership-approved information security policy, objectives, and risk acceptance criteria.
- Annual risk assessment and risk treatment plan mapped to Annex A controls.
- Statement of Applicability maintained; internal audits and management reviews conducted at least annually.
Key Control Domains (Annex A, 2022)
- Organizational: policies, roles, threat intelligence, supplier security, incident management, and compliance.
- People: screening, terms of employment, awareness training, and disciplinary process.
- Physical: secure areas, equipment protection, and clear desk/clear screen.
- Technological: access control, cryptography, logging and monitoring, backup, secure development, and vulnerability management.
Certification Path
- Controls are implemented to certification-ready standard; formal certification by an accredited body is targeted as contractual demand requires.
7. CMMC — Cybersecurity Maturity Model Certification
Applies where Ctrl supports U.S. Department of Defense contracts involving Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). Ctrl aligns to CMMC 2.0.
Level Alignment
- Level 1 (Foundational): 15 basic safeguarding requirements of FAR 52.204-21 for FCI — implemented across all Ctrl systems by default.
- Level 2 (Advanced): 110 controls of NIST SP 800-171 for CUI — implemented in scoped enclaves when handling CUI, with a System Security Plan (SSP) and Plan of Action & Milestones (POA&M).
Key Practices
- CUI is stored and processed only in designated, access-controlled enclaves with FIPS-validated cryptography.
- Flow-down of DFARS 252.204-7012 requirements to subcontractors; cyber incident reporting to DIBNet within 72 hours where required.
- Media, mobile device, and physical protection controls for field operations and drone data handling.
- Annual self-assessment with scores submitted to SPRS where contractually required; third-party (C3PAO) assessment pursued for Level 2 certification when bidding covered work.
8. CPCSC — Canadian Program for Cyber Security Certification
Canada's counterpart to CMMC for defence procurement. Where Ctrl supports Government of Canada / DND contracts, it aligns to the Canadian Program for Cyber Security Certification and CAN/DGSI 104 (based on NIST SP 800-171).
Program Alignment
- Level 1: annual self-assessment of basic cyber hygiene controls for contracts involving unclassified government information.
- Level 2: implementation of CAN/DGSI 104 controls with third-party certification for contracts involving sensitive unclassified information.
- Contract Security Program (CSP) requirements — personnel screening (reliability status) and organization clearances — maintained as required by contract.
Canadian Data Handling Commitments
- Sensitive Government of Canada data is stored in Canadian regions where contractually required (data residency).
- Compliance with PIPEDA for personal information and provincial equivalents where applicable.
- Alignment with CCCS (Canadian Centre for Cyber Security) ITSG-33 guidance for security control profiles on government work.
- Controlled Goods Program registration maintained where work involves controlled goods or technical data.
Questions, security disclosures, or requests for compliance documentation: data@goctrl.ca
These policies are reviewed annually by Company leadership.