Skip to main content
← Back to ThreatCast

Privacy Policy

Last updated: April 2026

1. Information We Collect

Account data: Name, email, password (hashed), organisation name. Usage data: Exercise completions, scores, performance metrics. Integration data: SIEM/XDR API credentials (encrypted), alert metadata (titles, severities — not full event payloads). Technical data: IP address, browser type, access timestamps.

2. How We Use Your Data

To provide the Service: generating exercises, tracking performance, producing reports and certificates. To improve the platform: aggregated, anonymised analytics. To communicate: service emails, weekly reports (opt-out available). We never sell your data to third parties.

3. SIEM/XDR Data

When you connect security tools, we access alert metadata only (titles, severities, timestamps). We do not store raw event data. Credentials are encrypted at rest using AES-256. Alert data is used solely to generate exercise scenarios and is not shared with other clients or third parties.

4. AI Processing

Exercise scenarios are generated using Anthropic's Claude API. Your company profile, tool stack, and alert metadata may be included in AI prompts to personalise scenarios. Anthropic does not use API inputs to train models. No personally identifiable information is sent to the AI.

5. Data Retention

Account data: retained while your account is active + 30 days after deletion. Exercise data: retained for the duration of your subscription. Certificates: 1 year from issuance. SIEM credentials: deleted immediately when you disconnect a connector.

6. Data Security

All data encrypted in transit (TLS 1.3) and at rest. Hosted on Vercel (SOC 2 Type II) and Neon PostgreSQL (SOC 2 Type II). Passwords hashed with bcrypt (12 rounds). MFA available via TOTP.

7. Your Rights

Under UK GDPR, you have the right to: access your data, rectify inaccuracies, request deletion, restrict processing, data portability, and object to processing. Contact support@threatcast.io to exercise these rights.

8. Cookies

We use essential cookies for authentication (NextAuth session token). We do not use advertising or tracking cookies. No third-party analytics cookies.

9. International Transfers

Data is processed in the EU/US via Vercel and Neon. Anthropic API calls are processed in the US under their data processing agreement.

10. Contact

Data Controller: ThreatCast Ltd, Glasgow, Scotland. Email: privacy@threatcast.io. ICO registration: [pending].