This page lays out our posture, standards alignment, and disclosure policy honestly, including what's on the roadmap versus done today.
SSO / SAML and OAuth (Google, GitHub). Role-based admin with least-privilege access for team owners, admins, and members.
Lab runtimes are isolated per session and torn down after use. Assessment runtime secrets are never persisted to the browser.
Hosted on major cloud infrastructure with encryption in transit (TLS 1.2+) and at rest. Per-tenant logical isolation.
We collect the minimum needed to run training and reporting. Data export and deletion on request. We don't sell personal data.
We describe our curriculum as aligned and mapped to these frameworks.
Exploits are validated by replay on our servers — there is no copyable flag, and validator logic is never exposed to the client.
We detect and redact personal data from lab transcripts and operational logs where technically feasible.
Each lab and exam target runs in an isolated, ephemeral runtime spun up for that session and torn down after — no cross-session bleed of payloads, secrets, or state.
One customer's team, candidate, and submission data is logically separated from every other tenant's, with access enforced server-side by role and ownership.
| Category | What | Retention |
|---|---|---|
| Account data | Name, email, role, org | Lifetime of account; deleted on request. |
| Progress & coverage | Lab status, scores, OWASP coverage | Lifetime of account; exportable. |
| Lab & exam submissions | Transcripts, evidence, payloads | Retained for grading & audit; redacted of PII where detected. |
| Operational logs | Auth events, admin actions | Time-limited retention for security & audit. |
Data export and deletion are available on request. Lab and exam submissions may be sent to our model provider for grading.
| Function | Provider | Purpose |
|---|---|---|
| Cloud hosting | Major cloud provider (US / EU regions) | Application, database, and lab runtime hosting. |
| LLM provider | Foundation-model API | Powers live lab targets and auto-grading of submissions. |
| Transactional email provider | Sign-in links, invitations, and notifications. | |
| Analytics | Privacy-respecting product analytics | Aggregate usage; no sale of personal data. |
A current subprocessor list with named vendors is available under NDA for team and enterprise customers.
SSO / SAML and OAuth sign-in; enforce SSO for your org on team and enterprise plans.
Admin actions — invites, role changes, exports — are recorded in a reviewable audit log.
Role-based access (owner / admin / billing / auditor / member) scoped to what each role needs.
On major cloud infrastructure in US or EU regions, encrypted in transit (TLS 1.2+) and at rest. Region preferences can be discussed for team and enterprise plans.
Yes — a Data Processing Agreement is available for enterprise customers on request.
We collect the minimum needed (name, email, results). Assessment runtime secrets are never persisted to the browser, and PII is redacted from logs where detectable.
Yes. Each lab/exam runtime is isolated per session and torn down after use, so there's no cross-session or cross-tenant data bleed.
Found an issue in our platform? We welcome reports and will respond quickly. Please give us reasonable time to remediate before public disclosure. We don't pursue legal action against good-faith research that respects user privacy and avoids service disruption.