Security
Last updated: September 30, 2026
CONTROL is built on the principle that intelligence is only useful if it can be trusted. That means knowing where information came from, who is allowed to see it, and what was done with it. This page describes how we approach security for CONTROL and this website.
Security by design
Security controls are part of CONTROL's architecture, not added afterward:
- Policy: defined rules, data boundaries, retention, and approved models.
- Authority: role-based access control, visibility rules, and approvals.
- Evidence: source pointers, provenance, timestamps, and confidence on every intelligence packet.
- Execution: approved skills, tools, and routing, with cost limits.
- Audit: an append-only record of inputs, decisions, and actions.
Data protection
Data is encrypted in transit using TLS and encrypted at rest. Access to customer data is restricted to authorized personnel on a least-privilege basis and is logged.
Permission-aware intelligence
CONTROL respects the permissions of the systems it connects to. Intelligence packets are released only through authorized views. Private profiles are never shared, and signals you are not permitted to see are never surfaced to you.
Model and AI safeguards
Customer data is not used to train third-party foundation models. Model access is governed by policy, and every model-assisted action runs within defined boundaries and is recorded for audit.
Early Access Program
CONTROL is in early access. Security controls are actively developed and reviewed with EAP participants. Details of the current controls are shared as part of the EAP agreement.
Reporting a vulnerability
If you believe you have found a security vulnerability in CONTROL or this website, please report it to control@gatewaydata.ca with "Security" in the subject line. Please give us reasonable time to investigate and fix the issue before making it public. We will not take legal action against good-faith research that follows this approach.