auto/attack

Privacy.

Data Controller and Processor

AutoAttack acts as the data controller responsible for your account information (email address, password, billing details) and session data. For campaign data — including discovered network assets, findings, evidence, and reports generated by agents deployed in your network — AutoAttack acts as a data processor on your behalf. You, as the customer who authorized the testing, are the data controller for campaign data and determine its purpose and scope through your agent configuration and campaign settings.

Where campaign data includes personal data, a data processing agreement (DPA) is required under Article 28 of the GDPR. Our standard DPA is available on request at security@autoattack.ai. For other privacy-related inquiries, contact us at the same address.

Information We Collect

  • Account information — email address, email domain, organization name, and hashed password when you create an account.
  • Agent configurations — deployed agent identifiers, API keys (stored as hashes), agent status, and campaign objectives.
  • Campaign data — data generated by deployed agents during attack campaigns, including: discovered network assets (hosts, services, shares, databases), open ports, operating systems, running services, and network topology information.
  • Finding evidence — proof of confirmed attack achievements, including attack chain details (techniques used, assets compromised), proof of exploitation output, and impact descriptions. Captured credentials and password hashes are not persisted in dedicated stores. Proof-of-exploitation fields may contain partial or redacted credential references as evidence of successful attack techniques; these are sanitized in campaign reports and purged upon account deletion.
  • Payment information — processed and stored by Stripe. We do not store card numbers, CVVs, or full payment credentials on our systems. We receive and store your Stripe customer ID and subscription status.
  • Contact and inquiry data — if you submit our contact form, we collect your name, email address, company name, and approximate network size. This data is delivered to us via email and is not stored in our application database.
  • Session and audit data — IP addresses, session identifiers, and activity logs (including actions performed, timestamps, and associated resource identifiers) to maintain security and prevent abuse.

Legal Basis for Processing (GDPR)

We process your personal data on the following legal bases:

  • Contract performance — processing necessary to provide the service, including account management, agent deployment, attack campaign execution, finding delivery, and report generation. This applies to both paid subscriptions and free campaigns, as your acceptance of our Terms of Service constitutes a contract regardless of payment (Article 6(1)(b) GDPR).
  • Legitimate interest — security measures, abuse prevention, audit logging, and service improvement where these interests are not overridden by your rights (Article 6(1)(f) GDPR).
  • Legal obligation — where we are required by law to retain or disclose data (Article 6(1)(c) GDPR).

How We Use Your Information

  • Abuse prevention — rate limiting, audit logging, and detecting unauthorized use.
  • Service improvement — we use anonymized and aggregated metadata from campaigns (such as which attack techniques succeed in general network environment categories) to improve adversary effectiveness across the platform, under our legitimate interest in service improvement (Article 6(1)(f) GDPR). Anonymization removes all customer-identifying information, network addresses, hostnames, and organization-specific details before aggregation. Once anonymized, this data is no longer personal data within the meaning of the GDPR and may be retained and used indefinitely. Individual findings, evidence, and network-specific data are never shared between customers.

Data Sharing

We do not sell, rent, or trade your personal data. We share information only with the following processors who act on our behalf:

  • Stripe (United States) — payment processing and subscription management. We send your email address and internal account identifier to Stripe when you subscribe.
  • Resend (United States) — transactional email delivery. Email content may include campaign names, aggregate campaign statistics, and links to the dashboard.
  • Cloud infrastructure provider (France, EEA) — server hosting and data storage. Campaign data, account information, and all application data reside on infrastructure located within the European Economic Area.

Agents operate locally inside your network and communicate with the AutoAttack cloud dashboard via encrypted API. Attack campaign data, findings, and evidence are transmitted to our platform for display and reporting.

Findings, evidence, and reports from your campaigns are never shared with other customers. We will only disclose data to law enforcement in response to valid legal process (such as a court order or subpoena). Where legally permitted, we will attempt to notify you before disclosing your data in response to legal process, unless we are prohibited from doing so by law or court order, or where we believe notification would jeopardize an investigation or create a risk of harm.

International Data Transfers

Our primary infrastructure is hosted in the European Economic Area (France). Some of our processors — Stripe and Resend — are located in the United States. Where personal data is transferred outside the EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, or reliance on the recipient's adequacy decision or certification under an applicable data transfer framework.

Data Security

  • All data in transit is encrypted via TLS.
  • Passwords are hashed using industry-standard one-way algorithms before storage. Hashed passwords cannot be recovered or reversed.
  • Verification and reset tokens are cryptographically hashed before storage.
  • Multi-tenant data isolation ensures campaign data — including finding evidence and proof-of-exploitation fields — is accessible only to your account.
  • We implement administrative and technical safeguards, including physical security measures maintained by our infrastructure providers, designed to protect your data. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

Breach notification — in the event of a security breach that affects your personal data, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach where required by applicable law. We will notify affected customers without undue delay.

Data Retention

  • Active accounts — all data is retained for the duration of your subscription.
  • Account deletion — upon deletion, your account is immediately soft-deleted (inaccessible, agents deactivated, no further campaigns). After 30 days, your email address and password hash are permanently and irreversibly overwritten.
  • Campaign data after deletion — campaign data (agent configurations, discovered assets, findings, evidence, and reports) may be retained for a limited period after your email and password are erased. This retention is solely for legal compliance and dispute resolution purposes (such as investigating pending Terms of Service violations), after which it is permanently deleted or irreversibly anonymized. Anonymized aggregate metadata extracted prior to deletion is no longer personal data and may be retained indefinitely as described under "How We Use Your Information."
  • Audit logs — retained for security and abuse prevention purposes. Audit log records may persist after account deletion as they are used for platform security monitoring, after which they are permanently deleted.
  • Third-party retention — Stripe and Resend retain data according to their own privacy policies. We do not control their retention periods.
  • Grounds for extended retention — we may retain data beyond the periods stated above where required by law, to comply with a legal hold or preservation order, to resolve pending disputes, or to enforce our Terms of Service (including investigating suspected unauthorized testing or Intellectual Property violations), for a maximum of one additional year beyond the standard retention period.

Cookies

We use essential cookies only (CSRF protection and session management). No tracking, analytics, or advertising cookies are used.

Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access — view your data anytime through your dashboard, including findings, targets, and reports. You may also request a copy of the personal data we hold about you.
  • Rectification — update your email address from Settings.
  • Deletion — delete your account from Settings. If a campaign is actively running, it is terminated before the deletion process begins. Your account is immediately inaccessible; identifying information is permanently and irreversibly overwritten after 30 days.
  • Export / Portability — download your campaign reports in PDF and CSV formats from the campaign page. You may also request a machine-readable export of your personal data by contacting us at security@autoattack.ai.
  • Restriction and objection — you may request that we restrict processing of your data or object to processing based on legitimate interest. Contact us at security@autoattack.ai.
  • Supervisory authority — if you are in the EEA, you have the right to lodge a complaint with your local data protection authority.

Changes to This Policy

We may update this policy from time to time. We will provide at least 30 days notice of material changes via email at the address associated with your account.

Contact

For privacy-related questions or to exercise your rights, contact us at security@autoattack.ai.