Plainly, and in full
How we handle your data.
We sell digital-security rehearsal to organizations that are right to be careful about what they hand over. So this page says what is stored, where it lives, what leaves the server, and — at the bottom — what we cannot honestly claim yet.
What we store
- Your organization
- Name, rough size, and area of work, from the one-screen setup.
- Your account
- Name and email for whoever facilitates. Passwords are stored hashed, never in the clear.
- Who was in the room
- First names or initials and the role each person played, entered by the facilitator.
- Setup answers
- The five preparation questions — whether a plan exists, whether backups have been restore-tested, and so on.
- What was decided
- Each decision, the role that made it, and the minute it was made. Against a role, never a name.
- The debrief and the report
- Your answers to the debrief questions, the drafted report, your edits to it, and the corrective actions with their owners and dates.
What we don't
- Your incident-response plan
- If you paste sections of it at setup, they are read once, in memory, and discarded. Only the short quotes shown in your brief are kept, and they go when the drill does.
- Anything from your systems
- Nothing is installed, no account is connected, no credential is requested. The drill is a discussion — there is nothing to plug in.
- Personal data about the people you serve
- A scenario invents its own caseloads and beneficiary lists. There is never a reason to put real ones in.
- Analytics or tracking
- There is no analytics script, no tag manager, no third-party pixel. The only cookie is the one that keeps you signed in.
Where it lives, and who can reach it.
The database is in London
A managed Postgres database in AWS eu-west-2. The application runs on Vercel.
One organization cannot read another
Isolation is enforced in the database itself by row-level security, not only by the application. The role the app connects with has no ability to bypass it, and an automated check proves that on every change.
Support access is visible
If we ever sign in as your account to reproduce a problem, a red banner says so on every screen — including on anything printed or exported while it is happening.
Where a language model is involved.
Three jobs, all of them narrow, and all of them off the critical path of a running drill. Text is sent to Anthropic's API for processing and nowhere else. It is never used to write a scenario, set a deadline, or decide when something happens during your hour.
- 01
Drafting your report
The decisions your team recorded and your debrief answers, turned into the first draft of the After-Action Report. You edit it afterwards; the draft is a starting point, not the final word.
- 02
Wording the updates
Rewriting an update so it names the systems your organization actually uses. It cannot change a number, a time, or what the moment is testing — and anything that tries is rejected automatically and falls back to the original.
- 03
Reading your own plan
Only if you choose to paste part of it. Email addresses and long numbers are stripped before anything is sent, and every line it returns is dropped unless it can be matched word for word against what you submitted.
What we can't claim yet
This is a young product. Some of what a careful buyer looks for does not exist here yet, and you should hear it from us rather than find out in a procurement review.
- No SOC 2, ISO 27001 or equivalent certification.
- No independent penetration test has been carried out.
- No published data-processing agreement yet. Ask and we will talk it through.
- Deletion is on request rather than self-service. Email us and it is done.
The safest version of this feature is the one where you send us nothing sensitive.
Every optional field in the product is optional for a reason. A drill runs exactly the same without your plan, without real names, and without any detail about the people you serve — it just cannot quote you. If in doubt, leave it out; nothing downstream breaks.