Privacy
Privacy Policy
How AttackCompass handles account, billing, analytics, and engagement-related information on the marketing site and in the product.
Effective date: October 10, 2026
Field-level engagement protections are detailed in the Security Model.
Overview
What this policy covers
This Privacy Policy describes how AttackCompass collects, uses, and shares information when you visit www.attackcompass.com, create an account, start a trial, or use the AttackCompass application.
Engagement security details — what Client mode protects, what remains server-readable, and how Ask works — are documented on the Security Model page. This policy focuses on account, billing, and marketing-site data.
Who we are
AttackCompass and processors
AttackCompass operates the marketing site and application. We use specialized processors for authentication, billing, and optional analytics.
Auth0 handles authentication and account identity. Paddle is merchant of record for checkout, tax, invoices, cancellation, and refunds. Optional product analytics may use PostHog Cloud EU after you consent.
Data
Information we collect
Account data may include email and authentication identifiers from Auth0, subscription and entitlement state from Paddle, workspace metadata such as names and sharing mode, and billing-consent records when you choose a paid plan.
Engagement data may include scope, hosts, services, credentials, findings, notes, evidence, report content, and related workspace state you choose to enter. How that data is protected depends on Lab vs Client mode — see the Security Model.
Marketing-site analytics, when enabled after consent, may include pages viewed, approximate location derived from IP, device/browser information, and conversion events such as trial start. We do not send Auth0 profile fields, Paddle payloads, or payment details to PostHog.
Analytics
PostHog Cloud EU and consent
If analytics are enabled, they run on PostHog Cloud EU. We do not contact PostHog before you consent, and we honor applicable Do Not Track signals where implemented.
You can withdraw consent through site cookie controls when available. Withdrawal stops analytics capture and clears related first-party analytics persistence for that browser.
Use
How we use information
We use account and billing data to provide the service, run trials, process payments through Paddle, enforce entitlements, and provide support.
We use engagement data to operate the workspace you create — recommendations, reporting, export, and related product features.
We use consented analytics to understand product and site usage and improve the experience. Analytics are not required to use AttackCompass.
Sharing
When we share information
We share data with processors that help us run the product: Auth0, Paddle, hosting and storage providers, and PostHog when analytics consent is active.
We may share information if required by law, to protect rights and safety, or in connection with a corporate transaction. We do not sell personal information.
Retention
Retention and deletion
Account and billing records are retained as needed to provide the service, meet legal and accounting obligations, and resolve disputes.
Deleting a workspace hard-deletes its database records and associated media files. For field-level protection and export options, see the Security Model.
Rights
Your choices
Depending on where you live, you may have rights to access, correct, delete, or export personal information, or to object to certain processing.
Contact support@attackcompass.com for privacy requests. For security vulnerabilities, use security@attackcompass.com and the Responsible Disclosure policy.
Updates
Changes to this policy
We may update this Privacy Policy as the product and legal requirements change. The updated page will show the revised effective date.