| Account / control plane | Email/login identity, subscription, workspace membership, billing consent | Auth0, Paddle, AttackCompass app | Access-controlled account systems; not Client-mode encrypted | Yes |
|---|
| Protected Client-mode secrets | Credential passwords, hashes, and other locked protected values | Encrypted in browser or local proxy before upload | Client-side encryption; passphrase not sent to AttackCompass | No plaintext when locking is enabled |
|---|
| Projected network identifiers | Supported IPv4 addresses and octet-aligned CIDRs (/8, /16, /24, /32) | Client mode projection before or at upload | Replaced with projected labels where supported | Projected labels only for supported fields |
|---|
| Engagement narrative | Usernames, domains, hostnames, ports, findings, notes, metadata | AttackCompass application and storage | Access control and workspace membership; not field-encrypted | Yes |
|---|
| Media library screenshots | Screenshots and engagement media assets | AttackCompass storage | AES-256-GCM at rest with a per-workspace key (server-decryptable) | Yes, after server-side decryption |
|---|
| Ask context | Question, selected workflow-card excerpts, recommendation context | Configured Ollama endpoint for the deployment | Sent only when Ask is used; locality depends on operator config | Visible to the configured Ollama endpoint |
|---|