genai
SECURITY LAB
Legal

Privacy Policy

Last updated August 17, 2026

This policy explains what we collect, why we collect it, how long we keep it, and the choices you have. It covers the training platform, the labs and exam runtimes, and the team administration features.

What we collect

We collect four kinds of data, and no more than we need to run the Service:

  • Account data — your name, email address, password hash, and where applicable your organization, team, role and group membership.
  • Training data — labs and paths started and completed, evidence and payloads you submit, guardrail and eval artifacts you write, assessment and certification results, scores, bands, and timestamps.
  • Billing data — plan, seat count, licence counts, invoices and billing contact. Card details are captured and stored by our payment processor; we never see or store full card numbers.
  • Technical data — IP address, browser and device type, pages visited, and cookies (see our Cookie Policy). Lab runtimes also produce short-lived session logs used for grading.

If you sit a proctored exam, we additionally process the identity check and session records needed to establish exam integrity.

How we use it

  • To deliver the training: run labs, launch and tear down runtimes, grade submissions, and track your progress.
  • To issue and verify credentials, including the public verification page for a credential you have earned.
  • For team plans, to give your administrator coverage, assignment and completion reporting for the members of their own workspace.
  • To take payment, manage seats and licences, and produce invoices.
  • To keep the Service secure and available: abuse prevention, rate limiting, incident investigation, and the administrative audit log.
  • To communicate about your account, and — only with consent where the law requires it — about product updates.

What we do not do

We do not sell your personal data, and we do not share it for advertising.

Lab and exam targets are seeded with synthetic data. The secrets, tenants, documents and users you attack are fabricated for the exercise, so nothing you extract in a lab is a real person's data.

Legal bases

Where data-protection law requires a legal basis, we rely on: performance of a contract (delivering the Service you signed up for), legitimate interests (securing the platform, preventing abuse, improving the product), consent (optional marketing email and non-essential cookies), and legal obligation (tax and accounting records).

Who we share it with

  • Processors that operate the Service — cloud hosting, the lab runtime environment, payments, transactional email, error monitoring and analytics — each under a written contract limiting them to our instructions.
  • Model providers, where a lab or exam requires a request to a live model. Prompt content is sent to complete that request.
  • Your team administrator, for accounts that belong to a team or enterprise workspace — they can see assignment, progress, coverage and certification status for their own members.
  • Anyone you choose to share a credential link with, which shows only the fields on the public verification page.
  • Authorities, where we are legally required to disclose, and an acquirer in the event of a merger or sale, subject to this policy.

How long we keep it

  • Account and training records: for as long as your account is active.
  • Certification records: retained after account closure so an issued credential stays verifiable, unless you ask us to revoke it.
  • Billing records: as long as tax and accounting law requires.
  • Lab runtime data: runtimes are ephemeral and torn down after the session; associated logs are short-lived.
  • Backups: deleted data may persist in encrypted backups for a limited period before being overwritten.

How we protect it

Data is encrypted in transit and at rest. Access to production systems is least-privilege, authenticated and logged, and administrative actions are recorded in an audit log. Lab and exam runtimes are isolated per session, so one learner's environment cannot reach another's.

Your rights

Depending on where you live, you may have the right to access, correct, export, delete or restrict the processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent. Write to [email protected] and we will respond within the period the applicable law allows.

If your account belongs to a team workspace, some requests may need to go through your administrator, who controls that workspace. You can also complain to your local data-protection authority.

International transfers

We may process data outside your country, including in the United States and the EU. Where we do, we rely on appropriate safeguards such as standard contractual clauses. Contact us for details of the mechanism that applies to you.

Children

The Service is not intended for children. You must be at least 16, or the age of digital consent in your jurisdiction, to hold an account.

Changes and contact

We will update this page when our practices change and, for material changes, notify you in-product or by email. Questions and requests go to [email protected].