AUTOATTACK
Deploy

Breaks in. Breaks nothing.

Yes. Run properly, an autonomous adversary is safe on a production network. It runs the same attacks a real one would and nothing else: throttling to your lockout policy, installing nothing, changing nothing, and leaving nothing on disk.

Deploy

safe inside your network

no lockouts Credential attempts are throttled to your domain’s lockout policy. No account gets locked out.
no disruption No service installs. No policy changes. No payload that trips antivirus.
no footprint Nothing is written to disk on your hosts. Proof streams straight to your dashboard as each step lands.
ephemeral Each campaign runs in a fresh, ephemeral container that lives only for the engagement, then is destroyed.
stop on demand Stop any running campaign from your dashboard at any time.

where your data lives

residency Campaign data, captured proof, and account information are hosted within the European Economic Area (France). One exception: offline credential recovery runs on rented GPU compute that we ask to be placed in the EEA without the provider confirming it, so we treat that as a transfer outside the EEA — see our privacy policy.
in transit All data in transit is encrypted with TLS. The adversary reaches the dashboard only over an encrypted API.
isolation Multi-tenant isolation keeps your campaign data (including captured evidence and proof) out of every other customer's account.
processors We use Stripe for payments, Resend for email, an EEA cloud provider for hosting, and RunPod for the GPU compute behind offline credential recovery. Where personal data leaves the EEA, Standard Contractual Clauses apply. Every processor and what it receives is listed in our privacy policy.

incident & disclosure

breach notice If a breach affects your personal data, we notify the relevant supervisory authority within 72 hours where required, and affected customers without undue delay.
report an issue Found a security issue in AutoAttack itself? Email security@autoattack.ai. Our machine-readable contact is at /.well-known/security.txt.

data retention & deletion

deletion Delete your account from Settings. It becomes inaccessible immediately; your email and password hash are permanently overwritten after 30 days.
running campaigns If a campaign is still running when you delete, it is terminated first.
Deploy