AUTOATTACK

Data processing.

Version 2026-07-30. Effective 2026-07-30. Superseded versions are archived and available on request.

This Data Processing Agreement ("DPA") governs AutoAttack's processing of personal data on the Customer's behalf. It is incorporated into and forms part of the Terms of Service at autoattack.ai/terms (the "Terms") and takes effect on the Customer's acceptance of the Terms. No signature is required.

The Terms are a legal agreement between the Customer and AutoAttack, which operates the autoattack.ai platform. Those two parties are the parties to this DPA, and the terms "Customer," "you," "AutoAttack," "we," and "us" carry the meanings given to them in the Acceptance section of the Terms.

1. Definitions and interpretation

1.1 In this DPA:

Account Data means personal data relating to the Customer's account and its use of the Services — email address, email domain, organization name, hashed password, billing details, Stripe customer identifier and subscription status, session identifiers, IP addresses, and audit records of actions performed — for which AutoAttack is the controller as described in the Privacy Policy.

Campaign Data has the meaning given to it in the Intellectual Property section of the Terms: the findings, evidence, and reports generated from campaigns on the Customer's networks.

Customer Personal Data means personal data contained in Campaign Data that AutoAttack processes on the Customer's behalf in providing the Services.

Data Protection Law means Regulation (EU) 2016/679 (the "GDPR") and any national law of an EEA state implementing or supplementing it, in each case to the extent applicable to the processing of Customer Personal Data.

De-identified Data has the meaning given to it in the Intellectual Property section of the Terms.

Personal Data Breach, controller, processor, processing, data subject, supervisory authority, and special categories of personal data have the meanings given to them in the GDPR.

Privacy Policy means the AutoAttack privacy policy at autoattack.ai/privacy, as amended.

SCCs means the standard contractual clauses set out in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, and a reference to a numbered Clause is a reference to a clause of the SCCs.

Services means the service described in the Service Description section of the Terms.

Sub-processor means any processor engaged by AutoAttack to process Customer Personal Data.

1.2 AutoAttack Persons has the meaning given to it in the Acceptance section of the Terms.

1.3 Capitalized terms not defined in this DPA have the meaning given to them in the Terms. A reference to a section of the Terms is a reference to that section as amended from time to time. "Including" and "in particular" do not limit what precedes them. Headings are for convenience and do not affect construction.

2. Roles and scope

2.1 In respect of Customer Personal Data, the Customer is the controller and AutoAttack is the processor. The Customer determines the purpose and scope of that processing through its configuration of campaigns — objectives, targets, network scope, and exclusions — and through its use of the platform.

2.2 In respect of Account Data, AutoAttack is the controller. That processing is governed by the Privacy Policy and is outside the scope of this DPA. Nothing in this DPA makes AutoAttack a processor of Account Data.

2.3 Where AutoAttack processes campaign metadata, agent activity, or platform usage for its own purposes of security, abuse prevention, detection of unauthorized testing, audit logging, service improvement, billing, and compliance with law — as described in the Monitoring and Abuse Detection section of the Terms and in the Privacy Policy — AutoAttack acts as a controller for those purposes, and that processing is outside the scope of this DPA.

2.4 De-identified Data is not personal data and is outside the scope of this DPA. Section 14 applies to it.

2.5 This DPA applies only to the processing described in section 2.1. It does not apply to data the agent processes locally on the Customer's own systems without transmitting it to AutoAttack, nor to the Customer's own processing of Campaign Data after it is exported or downloaded.

3. Customer instructions and warranties

3.1 The Customer instructs AutoAttack to process Customer Personal Data for the purposes set out in Annex 1, and only for those purposes.

3.2 The Customer's documented instructions consist of the Terms, this DPA and its annexes, the Privacy Policy, and the Customer's configuration of and interaction with the platform, including its campaign objectives, network scope, exclusions, re-engagement requests, report and export requests, and account and campaign deletion. Those instructions include the creation of De-identified Data as described in section 14. Together they are the complete and final set of the Customer's instructions. Any further or different instruction requires AutoAttack's written agreement and, where it is not trivial to implement, is subject to section 8.4.

3.3 The Customer warrants and represents that:

(a) it has a lawful basis under Article 6 of the GDPR for every instruction it gives and for all processing of Customer Personal Data it directs, including the processing of personal data belonging to its own employees, contractors, and administrators that is present in discovered assets, findings, and proof-of-exploitation output;

(b) it has given every notice, and provided every item of information, required of it under Articles 12 to 14 of the GDPR to the data subjects whose personal data is or may be present in campaign scope, and has obtained any consent required of it under Data Protection Law or under any other law or agreement binding on it;

(c) it has carried out any assessment required of it under Article 35 of the GDPR before instructing AutoAttack to begin processing;

(d) its instructions comply with Data Protection Law and do not require AutoAttack to act in breach of it; and

(e) the representations it gives in the Authorization to Test and Restricted Environments sections of the Terms are true, and it has the authority described there in respect of every network it places in campaign scope.

3.4 The Customer will not instruct AutoAttack to process, and will exclude from campaign scope so far as it is able, special categories of personal data and personal data relating to criminal convictions and offences within Article 10 of the GDPR. AutoAttack does not select the content of Customer Personal Data and cannot know in advance what a discovered asset contains. Where data of either kind is nonetheless present in Customer Personal Data, AutoAttack processes it on the same terms as any other Customer Personal Data, and the Customer remains responsible for the lawful basis and for any further condition Data Protection Law requires for it.

3.5 The Customer is responsible for the accuracy, quality, and lawfulness of the scope it configures, and for the security of the deployment host, the agent container, and its own dashboard credentials.

3.6 AutoAttack will inform the Customer if, in AutoAttack's opinion, an instruction infringes Data Protection Law. AutoAttack may suspend the affected processing until the Customer confirms or withdraws the instruction in writing, and a suspension under this section is not a breach of the Terms or of this DPA and gives rise to no liability, refund, credit, or extension.

4. AutoAttack's processing obligations

4.1 AutoAttack will process Customer Personal Data only on the Customer's documented instructions as set out in section 3, and will not process it for any other purpose.

4.2 AutoAttack may process Customer Personal Data where required to do so by law, including in response to valid legal process. Where it does, AutoAttack will inform the Customer of that legal requirement before processing unless the law prohibits it from doing so, or where AutoAttack reasonably believes notification would jeopardize an investigation or create a risk of harm. This section does not limit the Confidentiality section of the Terms or AutoAttack's right under the Terms to report suspected unauthorized testing and to cooperate with a resulting investigation.

4.3 AutoAttack will comply with the obligations imposed on a processor by Article 28 of the GDPR in respect of Customer Personal Data. This DPA states the whole of AutoAttack's obligations in that respect.

5. Confidentiality of personnel

5.1 AutoAttack will ensure that each person it authorizes to process Customer Personal Data is subject to a duty of confidentiality in respect of it, whether by contract or by statute, and that the duty survives the end of that person's engagement.

5.2 AutoAttack will limit access to Customer Personal Data to those of its personnel who need it to provide the Services, to support the Customer, or to comply with law.

6. Security

6.1 AutoAttack will implement the technical and organizational measures set out in Annex 2 to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, and unauthorized access, having regard to the state of the art, the cost of implementation, the nature, scope, context, and purposes of the processing, and the risk to data subjects.

6.2 AutoAttack may change the measures in Annex 2, provided the change does not materially decrease the level of protection those measures afford to Customer Personal Data. AutoAttack maintains no obligation to implement a measure the Customer requests.

6.3 The Customer is responsible for satisfying itself that the measures in Annex 2 meet its own obligations under Article 32 of the GDPR before it instructs AutoAttack to begin processing, and for the measures it applies to Campaign Data it exports or downloads.

6.4 No method of transmission or storage is completely secure. AutoAttack does not warrant that Customer Personal Data will not be lost, altered, disclosed, or accessed without authorization, and section 6.1 states an obligation of means, not of result.

7. Sub-processors

7.1 The Customer gives AutoAttack general written authorization to engage Sub-processors, as the Confidentiality section of the Terms records. That authorization is general and not specific: the Customer does not approve Sub-processors individually and has no right to veto one.

7.2 The Sub-processors AutoAttack had engaged as at the version date of this DPA are listed in Annex 3. The current list is the one in the Data Sharing section of the Privacy Policy, which prevails over Annex 3.

7.3 AutoAttack will inform the Customer of an intended change to that list, whether by the addition or the replacement of a Sub-processor, at least 30 days before the Sub-processor begins processing Customer Personal Data. Notice is given by email to the address associated with the Customer's account or by publishing the updated Privacy Policy, and the Notices bullet of the General Provisions section of the Terms governs its effectiveness.

7.4 The Customer may object to the change on reasonable grounds relating to data protection by written notice given within 15 days of AutoAttack's notice, stating those grounds. The parties will then discuss the objection in good faith for up to 15 days. If the objection is not resolved, the Customer's sole and exclusive remedy is to terminate its subscription and any affected campaign by written notice given within 30 days of AutoAttack's notice, and to receive a credit for prepaid fees for the unused remainder of the then-current billing period, calculated pro rata from the date the termination takes effect. Termination under this section takes effect on the date AutoAttack receives that notice, or on any later date the Customer states in it. That credit is the Customer's only financial remedy, and save for it the Refunds bullet of the Subscription and Billing section of the Terms applies to fees already paid. The Customer has no other remedy, and an objection does not prevent, delay, or condition the engagement of the Sub-processor.

7.5 AutoAttack will impose on each Sub-processor, by written contract, data protection obligations that are no less protective of Customer Personal Data than those in this DPA, to the extent applicable to the nature of the Sub-processor's service, and will remain responsible to the Customer for a Sub-processor's performance of them as if the acts and omissions were AutoAttack's own, subject to section 15.

7.6 Where a Sub-processor is established outside the EEA, or processes Customer Personal Data outside the EEA, section 11.5 applies to that transfer.

8. Data subject requests

8.1 The platform provides the Customer with the means to act on most requests itself: to view findings, targets, and reports through the dashboard; to download campaign reports in PDF and CSV format; and to delete campaigns and its account. The Customer will use those means in the first instance.

8.2 Where AutoAttack receives a request from a data subject that relates to Customer Personal Data, it will not respond to the substance of that request, save to acknowledge it and to direct the data subject to the Customer. AutoAttack will forward the request to the Customer without undue delay.

8.3 Where the Customer cannot give effect to a request under Chapter III of the GDPR using the means described in section 8.1, AutoAttack will provide reasonable assistance, taking into account the nature of the processing and to the extent AutoAttack is able given the information available to it.

8.4 Assistance under section 8.3 that goes beyond trivial effort is provided at the Customer's cost. AutoAttack will notify the Customer of that cost in advance, and it is payable in accordance with the Subscription and Billing section of the Terms. AutoAttack is not obliged to begin the work before the Customer accepts the cost in writing.

8.5 The Customer is solely responsible for verifying the identity of a data subject and for determining whether and how a request must be answered.

9. Personal data breach

9.1 AutoAttack will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

9.2 The notification will describe, to the extent then known to AutoAttack and to the extent AutoAttack is able to determine it: the nature of the breach; the categories and approximate number of data subjects and records concerned; the likely consequences; and the measures taken or proposed to address it and to mitigate its effects. AutoAttack may provide that information in phases as its investigation progresses, and a first notification is not delayed for want of complete information.

9.3 Notification under this section is not an acknowledgment of fault or of liability by AutoAttack or by any AutoAttack Person.

9.4 The Customer is solely responsible for assessing whether a Personal Data Breach must be notified to a supervisory authority under Article 33 of the GDPR or communicated to data subjects under Article 34, for making any such notification or communication, and for its content and timing. AutoAttack does not make, and will not make, a notification or communication of that kind on the Customer's behalf. AutoAttack will provide reasonable assistance with the Customer's assessment on request, on the terms in sections 8.3 and 8.4.

9.5 Nothing in this section restricts AutoAttack from making a notification or disclosure required of it in its own capacity as controller or by law.

9.6 AutoAttack gives notice under this section to the email address associated with the Customer's account. The Customer is responsible for keeping that address current, monitored, and able to receive AutoAttack's mail.

10. Data protection impact assessments and prior consultation

10.1 The Customer is responsible for determining whether the processing requires a data protection impact assessment under Article 35 of the GDPR, and for carrying one out.

10.2 AutoAttack will provide reasonable assistance with that assessment and with any prior consultation under Article 36. That assistance consists of making available this DPA and its annexes, the Privacy Policy, and the information published at autoattack.ai/security, and of answering reasonable written questions about the nature of the processing, in each case taking into account the nature of the processing and to the extent AutoAttack is able given the information available to it.

10.3 Sections 8.4 and 13.1 apply to assistance under this section.

11. International transfers

11.1 Customer Personal Data at rest resides on infrastructure located in France, within the European Economic Area. Offline credential recovery is the exception: where it is used, the hash material described in Annex 1 is submitted to a GPU instance rented from the Sub-processor named in Annex 3 and is written to that instance's own disk for the duration of the recovery attempt. Annex 3 states what AutoAttack does and does not assert about where that instance is placed, and section 11.5 governs the transfer.

11.2 Sections 11.3 to 11.5 apply only to the extent that Customer Personal Data is transferred to, processed in, or accessed from a country outside the EEA that is not the subject of an adequacy decision under Article 45 of the GDPR.

11.3 To that extent, the SCCs, Module Two (transfer controller to processor), are incorporated into this DPA by reference and take effect between the parties on the Customer's acceptance of the Terms, without further action by either party. The Customer is the data exporter and AutoAttack is the data importer. The SCCs are completed as follows:

(a) Clause 7 (the docking clause) does not apply.

(b) In Clause 9(a), Option 2 (general written authorisation) applies. The list of Sub-processors is Annex 3, and the period of prior notice is 30 days, as provided in section 7.3.

(c) The optional paragraph of Clause 11(a) does not apply.

(d) The competent supervisory authority for the purposes of Clause 13(a) is the authority that clause identifies on the Customer's circumstances, and Annex I.C of the SCCs is completed accordingly. The Customer will identify that authority to AutoAttack in writing on request.

(e) For the purposes of Clause 17, Option 1 applies and the SCCs are governed by the law of France.

(f) For the purposes of Clause 18(b), the courts of France are the chosen forum for a dispute arising from the SCCs.

(g) Annex I.A of the SCCs is completed by the party details recorded under "Party details" below, by the Customer's account information, and, for the four items of AutoAttack's details that record no value, by the information AutoAttack provides under paragraph (i); Annex I.B by Annex 1 of this DPA; Annex I.C as provided in paragraph (d); Annex II by Annex 2; and Annex III by Annex 3, read with the Data Sharing section of the Privacy Policy as section 7.2 provides.

(h) Where a provision of the SCCs contradicts a provision of this DPA or of the Terms, the SCCs prevail to the extent of the contradiction, and only in respect of a transfer to which the SCCs apply under section 11.2.

(i) Four items of AutoAttack's party details are not stated in this DPA: its registered legal entity name and type, its registered address, its registration number, and a named contact person. The table below records each of them as to be completed rather than stating a value, and this DPA does not assert that the table completes Annex I.A of the SCCs in respect of those four items. AutoAttack will provide them to the Customer in writing on request at security@autoattack.ai, and on a countersigned copy under section 17.3. The parties intend that their absence from this document neither delays nor conditions the taking effect of the SCCs under this section, and a Customer that requires them before it accepts the Terms should request them first.

11.4 AutoAttack may replace or supplement the SCCs with another mechanism that lawfully permits the transfer, including an adequacy decision, a certification under an applicable data transfer framework, or a successor to the SCCs adopted by the European Commission. AutoAttack will notify the Customer of the change under section 7.3, and the Customer will provide such cooperation as is reasonably necessary to give it effect.

11.5 Where AutoAttack transfers Customer Personal Data to a Sub-processor established or processing outside the EEA, AutoAttack will ensure that the transfer is made under a mechanism permitted by Chapter V of the GDPR — including the SCCs, Module Three (transfer processor to processor), where the Sub-processor acts as a processor, or the recipient's reliance on an adequacy decision or on a certification under an applicable data transfer framework.

12. Deletion and return

12.1 On termination or expiry of the Terms, on deletion of the Customer's account, or on the Customer's earlier written request, AutoAttack will delete Customer Personal Data or return it to the Customer, at the Customer's election notified in writing. Absent an election, AutoAttack will delete it. AutoAttack will complete the deletion or return within 30 days of the end of the provision of the Services, subject to sections 12.3 to 12.5.

12.2 Return is effected by making the Customer's campaign reports available for download in PDF and CSV format, and, on written request, by providing a machine-readable export. AutoAttack has no obligation to return Customer Personal Data in a format the platform does not produce, nor to reconstruct data the Customer has already deleted.

12.3 AutoAttack may retain Customer Personal Data after the period in section 12.1 where and for so long as retention is required by law, or is necessary for legal compliance, dispute resolution, or the establishment, exercise, or defence of legal claims — including where the data is subject to a legal hold, a preservation order, or an actual or reasonably anticipated dispute, claim, or investigation. Data retained under this section remains subject to sections 5, 6, and 7, is processed for no other purpose, and is deleted or irreversibly anonymized promptly once the purpose for which it was retained ends. This section is the carve-out permitted by Article 28(3)(g) of the GDPR.

12.4 Where Customer Personal Data persists in an archive or backup medium after the period in section 12.1, it is deleted or overwritten in the ordinary course of that medium's retention cycle rather than individually, and remains subject to sections 5, 6, and 7 until it is.

12.5 Section 12.1 does not apply to De-identified Data. Section 14 applies to it.

12.6 The Customer is solely responsible for exporting any Campaign Data it wishes to retain before its account is deleted or its subscription ends, as the Account Deletion section of the Terms provides. AutoAttack has no obligation to retain Customer Personal Data beyond the periods in this section and no liability for data that becomes inaccessible or is deleted in accordance with it.

13. Audit and information

13.1 AutoAttack will make available to the Customer the information necessary to demonstrate its compliance with Article 28 of the GDPR and with this DPA. That obligation is satisfied by this DPA and its annexes, the Privacy Policy, the information published at autoattack.ai/security, and AutoAttack's written response to the Customer's reasonable questions about that compliance. AutoAttack will respond to one such set of questions in any 12-month period, and sections 8.3 and 8.4 apply to a request that goes beyond trivial effort.

13.2 Where AutoAttack holds a certification or a third-party audit report covering the Services, it will make a copy or a summary of it available to the Customer under the Confidentiality section of the Terms. AutoAttack does not represent that it holds any certification or third-party audit report, and nothing in this DPA is a representation that it does.

13.3 Where Data Protection Law requires AutoAttack to allow an audit or inspection that cannot be satisfied under sections 13.1 and 13.2, the Customer may conduct one, subject to each of the following:

(a) the Customer gives at least 30 days prior written notice;

(b) no more than one audit or inspection is conducted in any 12-month period;

(c) it is conducted during AutoAttack's normal business hours and lasts no more than one business day;

(d) it is conducted in accordance with a scope, plan, and method agreed in writing in advance, and it does not disrupt the Services or AutoAttack's operations;

(e) it is conducted by the Customer's own personnel or by an independent auditor that is not a competitor of AutoAttack, in either case bound by written confidentiality obligations at least as protective as the Confidentiality section of the Terms;

(f) it does not extend to any facility or data centre operated by a third party, to any other customer's data, or to any AutoAttack Confidential Information as defined in the Terms — including the source code, internal logic, or contents of the agent binary or container, AutoAttack's attack methodology, and its non-public technical and operational information — and nothing in this section limits the Intellectual Property section of the Terms;

(g) it does not include penetration testing, vulnerability scanning, red-team activity, or any other active testing of AutoAttack systems, and does not involve access to a production system, without AutoAttack's prior written consent; and

(h) it is at the Customer's cost, including AutoAttack's reasonable costs of preparing for, supporting, and supervising it.

13.4 The results of an audit or inspection are AutoAttack Confidential Information. The Customer will use them only to verify AutoAttack's compliance with this DPA and will disclose them only to its own supervisory authority or where required by law.

13.5 AutoAttack may decline an audit or inspection, or a part of it, where conducting it would breach applicable law or an obligation AutoAttack owes to a third party.

13.6 Nothing in this section limits the powers of a supervisory authority acting under Data Protection Law.

14. De-identified data

14.1 The Customer instructs AutoAttack to create De-identified Data from Campaign Data. AutoAttack does so by removing identifiers of the Customer, its personnel, and its networks — including organization details, network addresses, and hostnames — and by aggregating the result to a minimum cohort size, so that no individual customer, network, or person can be identified from it.

14.2 De-identified Data is not personal data. It is not Campaign Data and it is not Customer Personal Data. It is outside the scope of this DPA, and the obligations in sections 8, 9, 12, and 13 do not apply to it.

14.3 AutoAttack may retain and use De-identified Data indefinitely, for the purposes and under the licence granted in the Intellectual Property section of the Terms, including operating and improving the Services, benchmarking, security research, and publishing aggregate statistics. That right survives termination of the Terms, termination of this DPA, and deletion of the Customer's account.

14.4 AutoAttack will not attempt to re-identify De-identified Data, and will not combine it with other information for the purpose of identifying the Customer, a data subject, or a network.

15. Liability

15.1 The Limitation of Liability section of the Terms applies to this DPA as if it were set out in it, and applies to all liability arising under or in connection with this DPA, whether in contract, tort (including negligence and breach of statutory duty), misrepresentation, restitution, equity, or otherwise. It applies for the benefit of each AutoAttack Person.

15.2 All claims under this DPA and all claims under the Terms are aggregated for the purposes of the single cap in that section. This DPA does not create a separate cap, an additional cap, a further liability, or any liability that is not subject to that cap. The exclusions in that section — including the exclusion of indirect, incidental, special, consequential, and punitive damages, and the exclusion of liability for loss, corruption, alteration, or unavailability of data, for the cost of restoring or recreating data or systems, and for business interruption — apply to claims under this DPA.

15.3 AutoAttack is not liable under this DPA for loss to the extent it is caused by the Customer's instructions, by the Customer's campaign configuration or scope, by the Customer's failure to establish a lawful basis or to give a notice or obtain a consent required of it, or by the content of data the Customer placed within campaign scope. Where both parties are responsible, each bears liability to the extent of its own responsibility.

15.4 The Customer will bring any claim arising from or related to this DPA solely against AutoAttack and not against any other AutoAttack Person, as the Third parties bullet of the General Provisions section of the Terms provides.

15.5 No limitation in this DPA or in the Terms applies to the Customer's obligations under the Indemnification section of the Terms, which extends to any investigation, inquiry, or enforcement action by a supervisory or regulatory authority, and to any claim by a data subject, arising from personal data present in campaign scope, discovered assets, or finding evidence, or from the Customer's instructions as controller.

15.6 Nothing in this DPA excludes or limits liability that cannot lawfully be excluded or limited, or affects a data subject's rights under Article 82 of the GDPR.

15.7 Where the SCCs apply under section 11.2, and only to the extent Clause 12 of the SCCs is engaged and is inconsistent with this section, the SCCs prevail as Clause 5 requires. The parties intend that this section otherwise applies in full.

16. Term, amendment, and survival

16.1 This DPA takes effect on the Customer's acceptance of the Terms, or if later, when AutoAttack first processes Customer Personal Data, and continues for as long as AutoAttack processes Customer Personal Data.

16.2 This DPA terminates on the later of the termination or expiry of the Terms and the completion of AutoAttack's obligations under section 12.

16.3 AutoAttack may amend this DPA on 30 days notice given under the Notices bullet of the General Provisions section of the Terms, where the amendment is required to reflect a change in Data Protection Law, a decision or guidance of a supervisory authority or court, a new or replacement transfer mechanism, a change to the Sub-processor list, or a change to the Services, provided the amendment does not materially reduce the protection this DPA affords to Customer Personal Data. The Changes to These Terms section of the Terms governs the effect of continued use after an amendment takes effect.

16.4 Sections 1, 2, 5, 12, 14, 15, and 17 survive termination of this DPA, together with any provision that by its nature is intended to survive.

17. Miscellaneous

17.1 Relationship to the Terms. This DPA is incorporated into and forms part of the Terms. Where a provision of this DPA conflicts with a provision of the Terms, the Terms prevail, except that this DPA prevails (a) to the extent Data Protection Law requires it to, in respect of the processing of Customer Personal Data, and (b) as section 11.3(h) provides. Nothing in this DPA varies the Limitation of Liability, Indemnification, Intellectual Property, Governing Law, or Dispute Resolution sections of the Terms.

17.2 Sole data processing agreement. This DPA is the entire agreement between the parties on the processing of Customer Personal Data and supersedes any prior agreement, addendum, or understanding on that subject. Any data processing agreement, data processing addendum, standard clauses, security schedule, questionnaire response, or similar document issued by the Customer or by a third party on the Customer's behalf — including one contained in or referenced by a purchase order, vendor onboarding or registration form, procurement or supplier portal, or supplier code of conduct — is void and of no effect under the Entire agreement and precedence bullet of the General Provisions section of the Terms, even if AutoAttack signs, acknowledges, or references it or accepts payment under it.

17.3 No signature required. The Customer's acceptance of the Terms is its acceptance of this DPA and, where section 11.2 applies, its entry into the SCCs. Where the Customer requires a countersigned copy, AutoAttack may provide one; it takes effect on the terms of this DPA without variation, and a variation requires AutoAttack's express written agreement identifying the provision varied.

17.4 Notices. The Notices bullet of the General Provisions section of the Terms governs notices under this DPA. A notice to AutoAttack is effective only on actual receipt at security@autoattack.ai.

17.5 Governing law and forum. This DPA is governed by the laws of Singapore, and the Governing Law and Dispute Resolution sections of the Terms apply to it — including the informal resolution condition precedent, the exclusive jurisdiction of the courts of Singapore for a claim the Customer brings, the class action waiver, and the one-year time limitation. Sections 11.3(e) and 11.3(f) apply to the SCCs alone, and only where they apply under section 11.2.

17.6 Third parties. The Third parties bullet of the General Provisions section of the Terms applies to this DPA, save that where the SCCs apply under section 11.2 they confer on data subjects the third-party beneficiary rights stated in Clause 3, and to that extent only the exclusion of the Contracts (Rights of Third Parties) Act 2001 does not apply.

17.7 Severability, waiver, and assignment. The Severability, Waiver, and Assignment provisions of the Terms apply to this DPA.

Party details

Recorded for the purposes of Annex I.A of the SCCs and of any countersigned copy under section 17.3. A row marked as to be completed states no value: section 11.3(i) governs AutoAttack's four unstated items and the effect of their absence, and the Customer's own rows are completed on a countersigned copy or on the account details the Customer provides.

Processor / data importer

NameAutoAttack, which operates the autoattack.ai platform
Legal entity name and type[TO BE COMPLETED BY AUTOATTACK]
Registered address[TO BE COMPLETED BY AUTOATTACK]
Registration number[TO BE COMPLETED BY AUTOATTACK]
Contact for data protection matterssecurity@autoattack.ai
Contact person, name and position[TO BE COMPLETED BY AUTOATTACK]
Activities relevant to the data transferredProvision of the Services, as described in Annex 1
RoleProcessor; data importer
Signature and date (countersigned copy only)[TO BE COMPLETED]

Controller / data exporter

NameThe Customer, as identified by the account and organization details it provides on registration
Registered address[TO BE COMPLETED BY THE CUSTOMER]
Contact person, name and positionThe email address associated with the Customer's account, and [TO BE COMPLETED BY THE CUSTOMER]
Activities relevant to the data transferredConfiguring and running campaigns on networks the Customer owns or is authorized to test
RoleController; data exporter
Signature and date (countersigned copy only)[TO BE COMPLETED]

Annex 1 — Details of processing

This annex is the description of the processing required by Article 28(3) of the GDPR and completes Annex I.B of the SCCs.

Subject matter. AutoAttack's processing of Customer Personal Data contained in Campaign Data in the course of providing the Services.

Duration. For as long as the Terms are in effect and AutoAttack processes Customer Personal Data, and thereafter for the period in section 12.1, extended by any retention under sections 12.3 and 12.4.

Nature of the processing. Receiving Campaign Data submitted by the agent deployed in the Customer's network over an encrypted API; hosting, storing, transmitting, organizing, structuring, and displaying it; generating findings, evidence, attack chains, and reports from it; rendering campaign reports in PDF and CSV format and making them available for download; sending transactional email relating to campaigns; submitting captured hash material to the GPU compute Sub-processor named in Annex 3 for a recovery attempt and receiving any recovered plaintext back from it; creating De-identified Data; retaining data under sections 12.3 and 12.4; and deleting or irreversibly anonymizing it.

Purpose of the processing. To provide the Services to the Customer — to run the campaigns the Customer configures, to deliver confirmed attack achievements with their evidence and proof chains to the Customer's dashboard, to produce the Customer's reports and exports, to support re-engagement of a finding at the Customer's request, and to comply with law.

Frequency of the transfer. Continuous for the duration of a campaign. The agent submits findings and discovered assets to the platform while the campaign runs, and the resulting data is retained afterwards as described above.

Categories of data subjects. Individuals whose personal data is present on, or is capable of being associated with, a network the Customer places within campaign scope, including the Customer's employees, contractors, and administrators; holders of accounts on the Customer's networks and directory services; and any other individual whose personal data is present in a discovered asset or in proof-of-exploitation output. AutoAttack does not select these categories: they follow from the scope the Customer configures and from the content of the systems in it.

Categories of personal data.

  • Asset and network identifiers that identify or relate to an individual — hostnames, IP addresses, operating systems, running services, open ports, shares, databases, and network topology information — including where an asset is named after or assigned to a person.
  • Authentication identifiers present in campaign evidence, including account names and credential references. Proof-of-exploitation fields may contain partial or redacted credential references as evidence of a successful technique; these are sanitized in campaign reports.
  • Where offline credential recovery is used, captured password hashes and any recovered plaintext, stored encrypted at rest in a dedicated processing queue and a per-organization cache, used only to demonstrate the attack path within the Customer's own campaign.
  • Attack chain details, including the techniques used and the assets compromised, and impact descriptions.
  • Proof-of-exploitation output, which may contain any personal data present on the affected asset at the time of the campaign. AutoAttack does not select or control that content.

Special categories of personal data. None requested and none required. The Customer instructs AutoAttack to process no data within Article 9 or Article 10 of the GDPR. Section 3.4 governs data of that kind that is nonetheless present.

Sensitivity and applicable restrictions. Credential material and proof-of-exploitation output are treated as the most sensitive categories of Customer Personal Data and are subject to the measures in Annex 2, to the sanitization described above, and to the retention limits in the Data Retention section of the Privacy Policy.

Retention. As stated under "Duration" and in section 12, and as described in the Data Retention section of the Privacy Policy.

Sub-processor processing. The subject matter, nature, and duration of processing by each Sub-processor is as stated in Annex 3, and in each case is limited to what is necessary for the service that Sub-processor provides.

Annex 2 — Technical and organizational measures

This annex completes Annex II of the SCCs. Every measure below is a measure AutoAttack applies and states in its Privacy Policy. AutoAttack may change these measures under section 6.2, provided the change does not materially decrease the level of protection.

Encryption in transit. All data in transit is encrypted using TLS. The agent deployed in the Customer's network reaches the platform only over an encrypted API.

Encryption at rest. Captured password hashes and any recovered plaintext are stored encrypted at rest, in a dedicated processing queue and a per-organization cache. Where a recovery attempt is dispatched, the hash material is decrypted only to serve it to the GPU instance described in Annex 3, and any recovered plaintext is encrypted again on return.

One-way hashing. Passwords are hashed using industry-standard one-way algorithms before storage. Verification and reset tokens are cryptographically hashed before storage. Agent and campaign API keys are stored as hashes.

Tenant isolation and access control. Multi-tenant data isolation ensures that campaign data — including finding evidence and proof-of-exploitation fields — is accessible only to the Customer's own account. Access by AutoAttack personnel is limited as section 5.2 provides. Dashboard access is controlled by session identifiers and protected against cross-site request forgery; only essential cookies are used, for that protection and for session management.

Logging, monitoring, and abuse prevention. AutoAttack maintains activity logs recording actions performed, timestamps, and associated resource identifiers, and applies rate limiting and detection of unauthorized use, in each case to maintain security and prevent abuse.

Data residency. Campaign data, account information, and application data at rest reside on infrastructure located within the European Economic Area, in France. Offline credential recovery is the exception stated in section 11.1 and in Annex 3.

Data minimization and redaction. Proof-of-exploitation fields containing partial or redacted credential references are sanitized in campaign reports. Direct identifiers are removed and the result aggregated before any data is used as De-identified Data.

Retention and deletion. Data is retained and deleted as described in the Data Retention section of the Privacy Policy and in section 12: account deletion takes effect immediately as a soft deletion, with agents deactivated and no further campaigns; the email address and password hash are permanently and irreversibly overwritten after 30 days; campaign data retained under section 12.3 is deleted or irreversibly anonymized once the purpose of that retention ends, and that retention is reviewed at least annually.

Physical security. Physical security measures at the facilities where Customer Personal Data is stored are maintained by AutoAttack's infrastructure providers.

Administrative and organizational measures. AutoAttack implements administrative and technical safeguards designed to protect Customer Personal Data. Personnel authorized to process it are bound by confidentiality obligations under section 5. Sub-processors are bound by written data protection obligations under section 7.5. Personal Data Breaches are notified to the Customer under section 9.

Measures to assist the controller. AutoAttack's measures for assisting the Customer with data subject requests, with security, breach, and impact-assessment obligations, and with demonstrating compliance are those set out in sections 8, 9, 10, and 13.

No absolute assurance. No method of transmission or storage is completely secure. These measures are designed to protect Customer Personal Data; they are not a guarantee of absolute security, and section 6.4 applies.

Annex 3 — Approved sub-processors

The Customer's general authorization under section 7.1 covers each Sub-processor below. The current list is the one in the Data Sharing section of the Privacy Policy, which prevails over this annex.

Sub-processorLocationServiceData processedCustomer Personal Data under this DPA
Cloud infrastructure provider, named to the Customer in writing on requestFrance (EEA)Server hosting and data storageCampaign data, account information, and application data at restYes
RunPodGPU instances requested within the EEA, subject to the note belowGPU compute for offline credential recoveryCaptured password hashes submitted for a recovery attempt, and any recovered plaintext returnedYes. This is the most sensitive category of Customer Personal Data described in Annex 1.
ResendUnited StatesTransactional email deliveryEmail content, which may include campaign names, aggregate campaign statistics, and links to the dashboardYes, to the extent campaign names or campaign statistics constitute Customer Personal Data
StripeUnited StatesPayment processing and subscription managementAccount email address and internal account identifierNo. Stripe receives Account Data only, for which AutoAttack is the controller. Listed for completeness.

Where a Sub-processor above is located outside the EEA, section 11.5 governs the transfer.

Offline credential recovery. Every credential-recovery instance is requested with a placement constraint limited to the countries of the EEA, and each request is logged with the constraint it carried, so that what was asked for can be audited against where the instance ran. AutoAttack does not represent that the constraint is applied: it is asserted in the request AutoAttack sends and is not confirmed back by the provider. Customer Personal Data submitted for offline credential recovery is therefore treated as transferred outside the EEA, and section 11.5 governs it. The instance receives the hash material over a signed URL that expires 15 minutes after it is issued, holds it on its own disk for the duration of the attempt, returns any recovered plaintext to AutoAttack over a second signed URL, and is terminated once the results are collected or the attempt fails. Recovery is used only to demonstrate the attack path within the Customer's own campaign.

Agents operate locally inside the Customer's network and communicate with the AutoAttack cloud dashboard over an encrypted API. An agent is not a Sub-processor: it runs on the Customer's own infrastructure, under the Customer's control, at the Customer's instruction.