Privacy & Terms
Last updated: 9 October 2026
This page explains what data ThinkCNAP processes and the terms for using it. It applies to the website thinkcnap.org, the application app.thinkcnap.org, the ThinkCNAP API, and the submission of reports from the attack-simulation container to ThinkCNAP. In this page, "ThinkCNAP", "we" and "us" refer to the operator of the service; "you" refers to the person using it.
Privacy Policy
1. Data we process
We only process the data needed to run the service:
| Category | What it includes |
|---|---|
| Account | Email address; display name; a hash of your password (email sign-up) or your Google account identifier (Sign in with Google); whether your email is verified; account creation and update timestamps. |
| Assessment data | The impact, effort and initial, present and desired maturity values you set for each security measure. |
| API token | A randomly generated token linked to your account, its expiry date (one year after creation) and whether it has been revoked. |
| Attack simulation reports | The report your attack-simulation deployment submits with your API token. Its content is produced in your environment and may include technical details such as hostnames, IP addresses, cluster, namespace and resource names, and the results of each simulated technique. |
| One-time tokens | Email verification and password reset tokens, which expire after 24 hours and can be used once. |
| Technical data | IP address, browser user agent and request metadata processed by our hosting provider to deliver and protect the service. |
Configure your attack-simulation deployment so that reports do not contain secrets, credentials or personal data.
2. Anonymous mode
If you choose "Continue Anonymously", no account is created. Your scores are stored only in your browser's local storage and are not sent to our servers. Clearing your browser data removes them. API tokens and attack simulation reports are not available in anonymous mode.
3. How we use data
- To create and secure your account, sign you in, and keep you signed in.
- To store and display your assessments and attack simulation reports.
- To authenticate requests made with your API token.
- To send account emails: email verification and password reset. We do not send marketing email.
- To operate, troubleshoot and protect the service against abuse.
We do not sell your data, use it for advertising, or share it with third parties except the service providers listed below. We process account and assessment data to provide the service you request, and technical data for our legitimate interest in keeping the service secure and available.
4. Cookies and browser storage
ThinkCNAP does not use analytics, advertising or tracking cookies. The application uses your browser's local storage for:
- your session token (valid for 24 hours) and basic profile details, such as your email, name and account ID;
- interface preferences, such as the state of the sidebar and the last viewed control;
- your scores, if you use anonymous mode.
Signing out removes the session token. If you use Sign in with Google, Google may set its own cookies under its own policies.
5. Service providers
We use the following providers to run ThinkCNAP. They process data on our behalf, and data may be processed in countries other than your own.
| Provider | Purpose and data |
|---|---|
| Cloudflare | Hosting, network and database (Cloudflare Pages, Functions and D1). Stores all account, assessment, token and report data, and processes technical request data. |
| Resend | Delivers verification and password reset emails. Receives your email address and the email content. |
| Only if you use Sign in with Google. Google authenticates you and shares your email address, name and Google account identifier with us. | |
| jsDelivr and Tailwind CSS CDN | Serve scripts used by the pages. As with any web request, they receive your IP address and browser user agent. |
6. API tokens and AI agents
Anyone holding your API token can read your maturity assessment and change your scores. If you give the token to an AI agent, a CI/CD pipeline or another third-party tool, that tool will access your ThinkCNAP data, and its provider's own terms and privacy policy apply to whatever the tool processes. Data such as your cloud environment details or assessment results that you share with an AI agent is handled by that agent's provider, not by ThinkCNAP. Regenerate your token in the app at any time to revoke access.
7. Retention and deletion
- Account and assessment data are kept while your account exists.
- Attack simulation reports: only the latest report per API token is kept; each new submission replaces the previous one.
- API tokens expire one year after creation, or earlier when you regenerate them.
- Email verification and password reset tokens expire after 24 hours.
- Anonymous mode data stays in your browser until you clear it.
When you ask us to delete your account, we delete your account, assessment data, API tokens and reports. Copies may remain in backups for a limited period until they are overwritten.
8. Security
All traffic to ThinkCNAP is encrypted with HTTPS. Access to your data requires your session or your API token. No system is completely secure. Keep your password and API token confidential, and regenerate the token if you suspect it has been exposed.
9. Your choices and rights
You can change your assessment data, change your password and regenerate your API token in the app at any time. You can also ask us to give you a copy of your data, correct it, or delete your account. Depending on where you live, you may have further rights under data protection law, such as the right to object to processing or to complain to your local data protection authority.
To make a request, contact us via LinkedIn and include the email address of your ThinkCNAP account. We may need to confirm that you own the account before acting on a request.
10. Children
ThinkCNAP is a professional security tool and is not intended for anyone under 16. We do not knowingly collect data from children.
Terms of Use
By creating an account, using the application or API, or deploying the attack-simulation container with a ThinkCNAP token, you agree to these terms.
1. The service
ThinkCNAP provides security maturity assessment for cloud native applications and a way to submit and view attack simulation results. The service is currently free of charge. We may change, suspend or discontinue features, or the service as a whole, at any time. We do not guarantee availability or any particular response time.
2. Accounts and API tokens
- Provide a valid email address you control.
- You are responsible for activity under your account and for everything done with your API token.
- Keep your password and API token secret. Regenerate the token immediately if it may have been exposed.
3. Attack simulation: authorized use only
The attack-simulation container executes real attack techniques mapped to MITRE ATT&CK, for example reverse shells, access to cloud instance metadata, use of Kubernetes service account tokens, and launching privileged pods. These actions can trigger security alerts, create or change resources, and affect running workloads.
- Deploy it only in Kubernetes clusters and cloud accounts that you own, or that you have explicit written permission to test.
- Follow your cloud provider's security testing policies and inform the teams responsible for monitoring the target environment.
- Run it in a non-production environment first and review its configuration before every deployment.
- You are solely responsible for deploying and running it and for any consequences. ThinkCNAP only receives and displays the reports it submits.
The container is distributed from github.com/aliaksxssv/attack-simulation; its use is also governed by the license in that repository.
4. Acceptable use
You must not:
- use ThinkCNAP or the attack-simulation container against systems you are not authorized to test;
- attempt to access other users' data or accounts, or probe, scan or attack the ThinkCNAP service itself;
- overload the service or the API, or interfere with its operation;
- submit malware, unlawful content, or other people's personal data without a lawful basis;
- use the service in breach of applicable law.
To report a security vulnerability in ThinkCNAP, contact us privately via LinkedIn instead of testing it against the live service.
5. Your data
You keep all rights to the assessment data and reports you submit. You allow us to store and process them only as needed to provide the service to you, as described in the Privacy Policy above.
6. Assessment results
Maturity scores, recommendations and simulation results are guidance for improving your security. They are not an audit, a certification, legal advice or proof of compliance with any standard or regulation, and they depend on the accuracy of the data you enter. ThinkCNAP is not affiliated with or endorsed by Amazon Web Services, The MITRE Corporation or the Linux Foundation.
7. Third-party content and trademarks
- MITRE ATT&CK® is a registered trademark of The MITRE Corporation. ATT&CK content is © The MITRE Corporation and is reproduced and distributed with the permission of The MITRE Corporation.
- AWS and AWS Well-Architected are trademarks of Amazon.com, Inc. or its affiliates. Security domains are based on the publicly available AWS Well-Architected Framework Security Pillar.
- Kubernetes® is a registered trademark of the Linux Foundation.
- Other product names are trademarks of their respective owners.
8. Disclaimer and limitation of liability
The service, the attack-simulation container and all content are provided "as is" and "as available", without warranties of any kind, including fitness for a particular purpose, accuracy and non-infringement. To the maximum extent permitted by law, ThinkCNAP is not liable for any indirect, incidental, special or consequential damages, or for loss of data, revenue or business, or for damage to systems, arising from your use of the service or the attack-simulation container. Nothing in these terms limits liability that cannot be limited by law.
9. Ending your use
You can stop using ThinkCNAP at any time and ask us to delete your account. We may suspend or delete accounts that breach these terms or put the service or other users at risk.
10. Changes and contact
We may update this page as the service changes. The "Last updated" date at the top shows the latest version; continuing to use ThinkCNAP after an update means you accept it. For questions or requests, contact us via LinkedIn.