genai
SECURITY LAB
Trust & security

Built by security people, for security reviews

This page lays out our posture, standards alignment, and disclosure policy honestly, including what's on the roadmap versus done today.

Authentication

SSO / SAML and OAuth (Google, GitHub). Role-based admin with least-privilege access for team owners, admins, and members.

Data handling

Lab runtimes are isolated per session and torn down after use. Assessment runtime secrets are never persisted to the browser.

Infrastructure

Hosted on major cloud infrastructure with encryption in transit (TLS 1.2+) and at rest. Per-tenant logical isolation.

Privacy

We collect the minimum needed to run training and reporting. Data export and deletion on request. We don't sell personal data.

Standards

Aligned and mapped to

OWASP LLM Top 10
Every lab is mapped to a category; coverage is reportable.
NIST AI RMF
Curriculum aligned to Govern / Map / Measure / Manage functions.
MITRE ATLAS
Adversary techniques referenced in offensive scenarios.
ISO/IEC 42001
Training maps to AI management-system control areas.

We describe our curriculum as aligned and mapped to these frameworks.

AI commitments

How we handle AI specifically

Grading is server-side

Exploits are validated by replay on our servers — there is no copyable flag, and validator logic is never exposed to the client.

PII redaction in logs

We detect and redact personal data from lab transcripts and operational logs where technically feasible.

Isolation

Lab & tenant isolation

Per-session lab runtimes

Each lab and exam target runs in an isolated, ephemeral runtime spun up for that session and torn down after — no cross-session bleed of payloads, secrets, or state.

Tenant data separation

One customer's team, candidate, and submission data is logically separated from every other tenant's, with access enforced server-side by role and ownership.

Data

What we collect and how long we keep it

CategoryWhatRetention
Account dataName, email, role, orgLifetime of account; deleted on request.
Progress & coverageLab status, scores, OWASP coverageLifetime of account; exportable.
Lab & exam submissionsTranscripts, evidence, payloadsRetained for grading & audit; redacted of PII where detected.
Operational logsAuth events, admin actionsTime-limited retention for security & audit.

Data export and deletion are available on request. Lab and exam submissions may be sent to our model provider for grading.

Subprocessors

Infrastructure & third parties

FunctionProviderPurpose
Cloud hostingMajor cloud provider (US / EU regions)Application, database, and lab runtime hosting.
LLM providerFoundation-model APIPowers live lab targets and auto-grading of submissions.
EmailTransactional email providerSign-in links, invitations, and notifications.
AnalyticsPrivacy-respecting product analyticsAggregate usage; no sale of personal data.

A current subprocessor list with named vendors is available under NDA for team and enterprise customers.

Operations

Account security & access

SSO & MFA

SSO / SAML and OAuth sign-in; enforce SSO for your org on team and enterprise plans.

Audit logging

Admin actions — invites, role changes, exports — are recorded in a reviewable audit log.

Least privilege

Role-based access (owner / admin / billing / auditor / member) scoped to what each role needs.

FAQ

Security questions, answered

Where is our data stored?

On major cloud infrastructure in US or EU regions, encrypted in transit (TLS 1.2+) and at rest. Region preferences can be discussed for team and enterprise plans.

Can we get a DPA?

Yes — a Data Processing Agreement is available for enterprise customers on request.

How do you handle candidate PII?

We collect the minimum needed (name, email, results). Assessment runtime secrets are never persisted to the browser, and PII is redacted from logs where detectable.

Are lab environments isolated?

Yes. Each lab/exam runtime is isolated per session and torn down after use, so there's no cross-session or cross-tenant data bleed.

Responsible disclosure

Report a vulnerability

Found an issue in our platform? We welcome reports and will respond quickly. Please give us reasonable time to remediate before public disclosure. We don't pursue legal action against good-faith research that respects user privacy and avoids service disruption.

/.well-known/security.txt