Privacy Policy — TTX
Effective date: TBD before publish. TTX is in active development; this policy will be finalised before general availability.
TTX is a tabletop-exercise platform for security and incident-response teams. An organization creates an exercise — from a scenario library or a custom scenario — invites participants by email, and runs it with the help of an AI facilitator. This policy explains what TTX stores, how AI is involved, who can access it, and how it’s protected.
Plain-language summary
- What TTX stores: the exercises and scenarios an organization creates, the actions participants take during an exercise, the objective-coverage results, and the after-action reports generated from a run.
- Where it lives: on infrastructure operated by Stratus Studios, scoped to the organization that owns it.
- How AI is involved: exercise facilitation — drafting injects, evaluating participant actions, and suggesting when to steer or end an exercise — is performed by Claude, Anthropic’s AI model, called through Stratus Studios’ own service layer.
- Who can access it: TTX is multi-tenant. Every exercise, participant list, and report belongs to a single organization, and access is scoped to that organization. Participants join through a magic-link invite scoped to one exercise — no standing account, and no access beyond what they were invited to.
- Administration: an organizer creates and runs exercises for their organization, invites participants, and reviews the resulting after-action reports.
Data TTX stores
For each exercise:
- The scenario it’s based on, and the objectives it’s built around.
- The organization that owns it.
- Participant email addresses, used to send magic-link invites.
- The actions participants take during the exercise, and the AI facilitator’s evaluation of each one.
- The injects generated during the run.
- The objective-coverage result and the generated after-action report.
How AI is involved
TTX uses Claude, Anthropic’s AI model, to draft injects, evaluate participant actions against an exercise’s objectives, and suggest when to steer or end an exercise. Scenario details and participant actions are sent to the model to generate this facilitation. TTX does not use exercise content to train models.
Who can access exercise data
- TTX is multi-tenant: every exercise, participant list, and report belongs to a single organization, and access is scoped to that organization.
- A participant joins through a magic-link invite scoped to one exercise. They can’t see other organizations’ exercises, or, without being invited, other exercises inside the same organization.
- An organizer can create and run exercises for their organization and review its after-action reports.
Retention
Exercise data — scenarios, actions, and after-action reports — is retained until deleted by an organization. Concrete retention windows will be documented here before general availability.
Security
Access to exercise data is scoped by organization and, for participants, by the specific exercise they were invited to. Concrete details on encryption and infrastructure will be documented here before general availability.
Changes to this policy
We will update the effective date above and this file’s version-control history when the policy changes.
Contact
- General and privacy enquiries:
[email protected]