Privacy Policy — TTX

Effective date: TBD before publish. TTX is in active development; this policy will be finalised before general availability.

TTX is a tabletop-exercise platform for security and incident-response teams. An organization creates an exercise — from a scenario library or a custom scenario — invites participants by email, and runs it with the help of an AI facilitator. This policy explains what TTX stores, how AI is involved, who can access it, and how it’s protected.

Plain-language summary

Data TTX stores

For each exercise:

How AI is involved

TTX uses Claude, Anthropic’s AI model, to draft injects, evaluate participant actions against an exercise’s objectives, and suggest when to steer or end an exercise. Scenario details and participant actions are sent to the model to generate this facilitation. TTX does not use exercise content to train models.

Who can access exercise data

Retention

Exercise data — scenarios, actions, and after-action reports — is retained until deleted by an organization. Concrete retention windows will be documented here before general availability.

Security

Access to exercise data is scoped by organization and, for participants, by the specific exercise they were invited to. Concrete details on encryption and infrastructure will be documented here before general availability.

Changes to this policy

We will update the effective date above and this file’s version-control history when the policy changes.

Contact