Privacy & Data
Last updated: 22 July 2026
What we store
HACK THE SOC is a training platform. When you create an account we store your email address, your chosen nickname (handle) and display name, and your learning progress — completed rooms and scenarios, scores, XP, and streak. That is the whole of it. We do not collect sensitive information (health, financial, biometric, political, or similar), and the attack data you investigate in the product is entirely synthetic.
Why we store it
Only to run the service: to sign you in, to remember where you are in the curriculum, and to show your rank and progress. We do not sell data, and we do not use it to build advertising profiles.
Who processes it (sub-processors)
- Supabase — hosts the database and handles authentication (your account and progress).
- Vercel — hosts and serves the application.
- AI grading providers (Anthropic / OpenAI) — when you submit a free-text answer or incident report for AI feedback, the text of that answer is sent to the provider to generate the grade. Write your reports about the synthetic scenario only; there is no need to include real personal information, and you should not. Your identity is not sent with the text.
How long we keep it
Account and progress data is kept for as long as your account is active, and is removed when your account or your institution's licence is closed. Records of privileged administrative actions (the audit trail) are kept for at least 24 months, which is the retention the Israeli Privacy Protection (Information Security) Regulations require for access records.
Your rights
Under Israeli privacy law (חוק הגנת הפרטיות והתקנות מכוחו, כולל תיקון 13) you have the right to know what is held about you, and to have it corrected or deleted. We answer such requests within 30 days.
To exercise them: contact your course administrator — the person who issued your invitation. They administer your institution's accounts and can action access, correction and deletion requests, escalating to the platform operator where needed.
Security
Access to your account is protected by authentication, row-level database access controls, and an audit trail of privileged actions. Data is transmitted over HTTPS. No system is perfectly secure; if we ever become aware of a security event affecting your data, we will act on our obligations to notify as required by law.