FAQ
Straight answers for a security buyer.
Compliance products earn trust by refusing over-claims. Here is what ControlDrill is, what it is not, and how your plan is handled.
Product and honesty
Do you certify compliance?
No. ControlDrill produces the exercise and the evidence of it. Whether that satisfies a given control is between you and your auditor. We report facts. We do not issue a pass, grade, certification, or compliance verdict.
Does this replace a disaster-recovery (DR) test?
No. A ControlDrill session is a tabletop exercise: a structured walkthrough of decisions under a scenario. It does not replace live failover, restore rehearsal, or any technical DR test, and we never imply it does. The business-continuity regional-outage exercise type is a facilitated BC/DR tabletop only.
What exercise types do you offer?
Six: ransomware with data exfiltration; business email compromise and wire fraud; cloud credential compromise; data subject rights under incident conditions; AI incident; and business continuity regional outage (tabletop). Many security and AI-governance policies mandate specific annual tabletops (IR plan test, BC/DR tabletop, DSAR-within-IR, AI-incident, AI-provider availability). ControlDrill runs the tabletop and produces evidence of that exercise. It does not by itself satisfy a control, and the BC/DR option does not replace a live failover or backup-restoration test.
What do I hand my auditor?
A self-contained HTML evidence packet: scenario context, attendance, timed injects and decisions, gaps with remediation owners, and control cross-references as citations only. Ready minutes after the session ends.
Why do you refuse to grade controls?
Some tools print per-control Tested / Partial / Untested scores. A self-serve product is not in a position to grade your controls; an auditor will puncture that claim. We cite what the exercise surfaced and leave the verdict to your auditor. That is a feature, not a gap.
Your IR plan and data handling
Where does my IR plan go?
Your plan is never sent to an outside AI vendor. Reading and tailoring happen on the same platform that serves the app, so there is no third-party AI provider in the path for your document. Plans are used only to tailor your own exercises and are never used to train models.
Can I delete my plan?
Yes. Delete on request: the upload surface removes R2 originals and the extracted corpus for that purchase. Otherwise documents are held under our stated retention policy (12 months from upload). We do not claim automatic expiry as a live product feature beyond that stated policy.
What file types do you accept?
Paste text, .txt, .md, PDF, Word (.docx), and OpenDocument (.odt). PDF and Office files are converted to text on the same platform that serves the app, so your plan is never sent to an outside AI vendor. Scanned or image-only PDFs may not extract cleanly; if conversion fails, paste the text instead.
Who else can see my plan?
Disclosed infrastructure and payment subprocessors are listed in Privacy and the DPA (Cloudflare, Stripe, and WorkOS for buyer sign-in). No external LLM vendor is in the path. Your plan is not shopped to a sales team; purchase is self-serve.
Running the exercise
What if the AI is unavailable mid-exercise?
The moderator falls back to the prepared script. The server-side clock and the attributed record are unaffected. Live generation is assistance, not a single point of failure for the exercise.
Does AI make decisions for us?
No. AI assists facilitation (prompts, injects, structure). Your team makes the calls. We never require AI to decide containment, notification, or recovery for you.
How do participants join?
Each participant gets a personal magic link by email. No account is required for participants. Buyer checkout uses signed-in identity so purchases are bound to a real buyer.
Who should attend?
Typically: incident commander or security lead, on-call engineering, communications, and legal or privacy when notification clocks matter. Observers can join. An empty critical role (for example Legal) is often a useful finding and is recorded honestly.
How long does it take?
About 60 minutes for the live session, plus short intake and optional plan upload before you schedule. Evidence is available minutes after the session ends.
Pricing
How much does it cost?
$299 per exercise, one-time. Self-serve. No security-sales call required to buy.
Can I run it for my clients?
Yes. vCISOs and MSPs use ControlDrill to deliver exercises without building or scheduling each one from scratch. Buy an exercise per client run as needed.
Frameworks
Which frameworks do you support?
The packet can cross-reference controls commonly cited for incident-response exercises under SOC 2 (for example CC7.4 / CC7.5), ISO 27001 A.5.24 to A.5.27, PCI DSS 12.10.x, and HIPAA 164.308(a)(6). Citations are context for your auditor, never a grade from ControlDrill.