Privacy.
Effective 2026-08-04.
Data Controller and Processor
AutoAttack acts as the data controller responsible for your account information (email address, password, billing details), your acceptance records, and your session data. For campaign data — including discovered network assets, findings, evidence, and reports generated by agents deployed in your network — AutoAttack acts as a data processor on your behalf. You, as the customer who authorized the testing, are the data controller for campaign data and determine its purpose and scope through your agent configuration and campaign settings.
Where campaign data includes personal data, a data processing agreement (DPA) is required under Article 28 of the GDPR. Our Data Processing Agreement is already in place: it is incorporated into the Terms of Service and takes effect when you accept them, so no signature or request is needed. Where you need a countersigned copy, or have a question about it, contact us at security@autoattack.ai.
Information We Collect
- Account information — email address, email domain, organization name, and hashed password when you create an account.
- Acceptance records — the versions of our Terms of Service and of this policy that you accepted, the time of acceptance, and the IP address and browser identification (user agent) from which acceptance was made, retained as evidence of the agreement.
- Agent configurations — deployed agent identifiers, API keys (stored as hashes), agent status, and campaign objectives.
- Campaign data — data generated by deployed agents during attack campaigns, including: discovered network assets (hosts, services, shares, databases), open ports, operating systems, running services, and network topology information.
- Finding evidence — proof of confirmed attack achievements, including attack chain details (techniques used, assets compromised), proof of exploitation output, and impact descriptions. Where offline credential recovery is used, captured password hashes and any recovered plaintext are stored encrypted at rest, are submitted to the GPU compute provider named under "Data Sharing" for the recovery attempt itself, are used only to demonstrate the attack path within your own campaign, and are deleted when your account data is erased 30 days after account deletion. Proof-of-exploitation fields may contain partial or redacted credential references as evidence of successful attack techniques; these are sanitized in campaign reports and are deleted with the rest of your campaign data as described under "Data Retention."
- Payment information — processed and stored by Stripe. We do not store card numbers, CVVs, or full payment credentials on our systems. We receive and store your Stripe customer ID and subscription status.
- Correspondence — if you email us, we receive your email address and whatever you include in your message.
- Session and audit data — IP addresses, session identifiers, and activity logs (including actions performed, timestamps, and associated resource identifiers) to maintain security and prevent abuse.
Legal Basis for Processing (GDPR)
We process your personal data on the following legal bases:
- Contract performance — processing necessary to provide the service, including account management, agent deployment, attack campaign execution, finding delivery, and report generation. This applies to both paid subscriptions and free campaigns, as your acceptance of our Terms of Service constitutes a contract regardless of payment (Article 6(1)(b) GDPR).
- Legitimate interest — security measures, abuse prevention, audit logging, and service improvement where these interests are not overridden by your rights (Article 6(1)(f) GDPR).
- Legal obligation — where we are required by law to retain or disclose data (Article 6(1)(c) GDPR).
How We Use Your Information
- Abuse prevention — rate limiting, audit logging, and detecting unauthorized use.
- Service improvement — we use anonymized and aggregated metadata from campaigns to improve adversary effectiveness across the platform, under our legitimate interest in service improvement (Article 6(1)(f) GDPR). We derive aggregate statistics from campaigns — for example, how often a given technique succeeds in a category of network environment. Before aggregation we remove direct identifiers, including your organization details, network addresses, and hostnames, and we aggregate to a minimum cohort size so that no individual customer or network can be identified from the result. We treat such aggregates as no longer identifying you, and we retain and use them indefinitely to operate and improve the service, to benchmark our performance, for security research, and to publish aggregate statistics in research and marketing materials. Individual findings, evidence, and network-specific data are never shared between customers or published.
Data Sharing
We share information with the following processors, who act on our behalf:
- Stripe (United States) — payment processing and subscription management. We send your email address and internal account identifier to Stripe when you subscribe.
- Resend (United States) — transactional email delivery. Email content may include campaign names, aggregate campaign statistics, and links to the dashboard.
- Cloud hosting provider (France, EEA) — server hosting and data storage. Campaign data, account information, and application data at rest reside on infrastructure located within the European Economic Area.
- RunPod (GPU compute) — offline credential recovery. Where a campaign captures password hashes, the hashes and any recovered plaintext are processed on a GPU instance we rent for the length of the recovery attempt. Every instance is requested with a placement constraint limited to the countries of the EEA, but the provider does not confirm the constraint back to us, so we do not claim the instance sits in the EEA and we treat this as a transfer outside it — see "International Data Transfers." The instance holds the hash material only while the attempt runs and is terminated afterwards.
Agents operate locally inside your network and communicate with the AutoAttack cloud dashboard.
Findings, evidence, and reports from your campaigns are never shared with other customers. We disclose data to law enforcement in two situations: in response to valid legal process (such as a court order or subpoena), and where we report suspected unauthorized testing or other abuse of the service under our Terms of Service and cooperate with any resulting investigation, which may include providing account information, campaign data, and audit logs.
International Data Transfers
Where personal data is transferred outside the EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, or reliance on the recipient's adequacy decision or certification under an applicable data transfer framework. For campaign data you control, the SCCs relied on are the ones incorporated into our Data Processing Agreement. Where we are the controller of the transfer, the mechanism relied on for a given recipient, and a copy of any clauses relied on, are available from us at security@autoattack.ai.
Data Security
- Data in transit is encrypted.
- Passwords and the tokens used to verify an email address or reset a password are stored in hashed form.
- Access to your campaign data, including finding evidence and proof-of-exploitation fields, is restricted to your own account.
- We implement administrative and technical safeguards, including physical security measures maintained by our infrastructure providers, designed to protect your data. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Breach notification — in the event of a security breach that affects your personal data, we will notify the relevant supervisory authority, and any affected individual, only where and to the extent applicable law requires that notification of us as controller. We will notify affected customers without undue delay.
Data Retention
- Active accounts — all data is retained for the duration of your subscription.
- Account deletion — upon deletion, your account is immediately soft-deleted (inaccessible, agents deactivated, no further campaigns). After 30 days, your email address and password hash are permanently and irreversibly overwritten.
- Campaign data after deletion — campaign data (agent configurations, discovered assets, findings, evidence, and reports) may be retained for a limited period after your email address and password hash are erased. This retention is solely for legal compliance and dispute resolution purposes, after which it is permanently deleted or irreversibly anonymized. Aggregates created as described under "How We Use Your Information" are treated as no longer identifying you and are retained indefinitely.
- Acceptance records — the IP address and browser identification recorded with your acceptance are overwritten together with your email address and password hash after 30 days. The document versions you accepted and the time of acceptance are retained after that, as evidence that the agreement was formed.
- Audit logs — retained for security and abuse prevention purposes. Records may persist after account deletion, after which they are permanently deleted.
- Third-party retention — Stripe, Resend, and RunPod retain data according to their own privacy policies. We do not control their retention periods. The GPU instance used for credential recovery is terminated when the attempt ends, but we do not control what its provider retains about the instance itself.
- Grounds for extended retention — where data is subject to a legal hold, a preservation order, or an actual or reasonably anticipated dispute, claim, or investigation, we retain it for as long as necessary for that purpose, review that retention at least annually, and delete or anonymize it promptly once the purpose ends. Data under such a hold is excluded from the account-deletion timelines described above. For routine abuse investigation not connected to a dispute, we retain data for no more than one additional year beyond the standard retention period.
Cookies
We use essential cookies only (CSRF protection and session management). No tracking, analytics, or advertising cookies are used.
Your Rights
Depending on your location, you may have the following rights regarding your personal data.
Where we are the controller — your account, acceptance, billing, session, and audit data — exercise these rights with us using the contact details below. Where we act as your processor — campaign data, findings, and evidence generated by an agent deployed in your network — we cannot action a request from an individual whose personal data appears in that data, because you are the controller and determine the purpose of that processing. We will forward any such request to you without undue delay and will assist you in responding.
- Access — view your data anytime through your dashboard, including findings, targets, and reports. You may also request a copy of the personal data concerning you that we hold in our controller capacity, in a standard electronic format. That request is not a substitute for campaign reports or exports, which are provided under your subscription.
- Rectification — update your email address from Settings.
- Deletion — delete your account from Settings. If a campaign is actively running, it is terminated before the deletion process begins.
- Export / Portability — read each campaign's full report, with the evidence behind every step, on its campaign page. For a copy you can take with you, request a machine-readable export of your campaign data, or of the personal data concerning you, by contacting us at security@autoattack.ai.
- Restriction and objection — you may request that we restrict processing of your data or object to processing based on legitimate interest. Contact us at security@autoattack.ai.
- Supervisory authority — if you are in the EEA, you have the right to lodge a complaint with your local data protection authority.
Changes to This Policy
We may update this policy from time to time. We will provide at least 30 days notice of material changes via email at the address associated with your account.
Contact
For privacy-related questions or to exercise your rights, contact us at security@autoattack.ai.