← Back to home

Security Overview

For government IT departments and security reviewers. This page describes how your data is stored, transmitted, and processed.

Hosted on
AWS US-East-1 (N. Virginia)
Encryption
TLS 1.2+ in transit AES-256 at rest
Data residency
United States only

Infrastructure

Website and API: Vercel

The web application and backend API are hosted on Vercel's global edge network, with serverless functions deployed in the US region. Vercel is SOC 2 Type 2 certified and ISO 27001 compliant.

Database: Supabase on AWS US-East-1

All account data, exercise history, and session records are stored in a Supabase PostgreSQL database running on Amazon Web Services in the US-East-1 region (Northern Virginia). Data does not leave US infrastructure. Supabase is SOC 2 Type 2 certified.

Your account and saved workshops are protected by row-level security, so only your account can read or change them. Custom scenarios can only be changed by their owner, but once you host one in a session, its content can be read by anyone with that session's link. Live exercise session data (group boards, evaluator forms, self-assessments, and session debriefs) is not yet restricted to the people in that session. Until it is, use role titles or made-up names during exercises, not real names. Database connections use TLS encryption.

Payments: Stripe

Payment card data is handled entirely by Stripe, a PCI-DSS Level 1 certified payment processor. We never see, transmit, or store raw payment card numbers. We store only the Stripe customer ID and subscription status.

Encryption

  • ✓In transit: All connections to the website and API use TLS 1.2 or higher. Plain HTTP connections are automatically redirected to HTTPS.
  • ✓At rest: Supabase encrypts all database data at rest using AES-256. Backups are also encrypted.
  • ✓Passwords: User passwords are hashed using bcrypt via Supabase Auth. We never store plaintext passwords.

AI Processing: What Anthropic Receives

When a user clicks “Generate AI Debrief,” the following data is sent to Anthropic's API:

  • The titles and descriptions of action cards placed on the exercise board
  • Any notes or justifications the team added to placed cards
  • Player self-assessment text (strengths, improvements, additional notes)
  • Numeric ratings (1–5 scale) from player assessments
  • A list of injects triggered during the exercise
  • Evaluator ratings and observations (for the Improvement Plan)
  • The scenario title, description, and objectives
  • Hot wash notes the facilitator types on the dashboard (for the Improvement Plan)

What we don't send to Anthropic: email addresses, account identifiers, or payment information. Names:the Room Debrief and Improvement Plan can include names typed into player or evaluator fields (for example, a group's Incident Commander or an evaluator's name). Use role titles or made-up names if you don't want names included.

Under Anthropic's current API terms, prompts and responses are not used to train AI models. Anthropic's data processing practices are governed by their privacy policy at anthropic.com/privacy.

Note for government users: We recommend not including classified, FOUO, law enforcement-sensitive, or personally identifiable information in exercise notes, as this content is transmitted to Anthropic when the facilitator generates a debrief or Improvement Plan. AI documents are optional: exercises can be run, evaluated, and documented without them.

Access Controls

  • ✓Row-level security: Account records and saved workshops are restricted to their owner by Supabase row-level security, and custom scenarios can only be edited by their owner. Only the host who created a session can change its settings or its saved Room Debrief and Improvement Plan. Access controls for participant session data are being tightened; see the note under Database.
  • ✓API authentication: Account, billing, Room Debrief, and Improvement Plan endpoints require a signed-in user. Participant devices (joining a session, playing, evaluating, and self-assessing) work without an account by design, using the session code or link. Sign-in tokens are short-lived and refreshed automatically.
  • ✓Admin access: Internal administrative access to the database is restricted to the sole operator and requires multi-factor authentication.

Data Retention and Deletion

  • Active accounts: Data retained for the life of the account.
  • Closed accounts: Deleting your account in the app permanently removes your account and your exercise data: sessions you hosted and their results, AARs, workshops, custom scenarios, and your profile picture. Billing records (name, email, and payment amounts) are kept as needed for accounting. You can also ask us in writing, and we'll delete your data within 30 days.
  • Demo sessions: When a demo game finishes, its after-action review (the board, notes, and any player names and roles typed in) is saved so it can be reopened from its link. Use role titles or made-up names in the demo.
  • Contact form messages: Retained up to 12 months.
  • Data deletion requests: Fulfilled within 30 days of written request.

Incident Response

In the event of a security incident affecting user data, we will notify affected users by email within 72 hours of discovery, as required by applicable law. Notifications will describe the nature of the incident, data affected, and steps taken or recommended.

To report a security vulnerability, contact carleycritser@gmail.com with “Security Report” in the subject line. We take all reports seriously and will acknowledge receipt within 2 business days.

Questions

For security reviews, DPA requests, or questions from IT departments: carleycritser@gmail.com

We are a small operator. We respond to all security and compliance inquiries personally and do not use automated responses for these requests.