We teach security for a living, so we hold ourselves to the practices we teach. This page explains how we protect your account and your team's training data — written plainly, and kept honest about what we do and don't yet have.
All payments are processed by Stripe, a PCI-DSS Level 1 service provider. We never see or store your card number — our systems only hold a Stripe customer/subscription reference so we can manage your plan. You can manage or cancel your subscription anytime from the Stripe billing portal.
HACKIN'GAMES runs on Cloudflare's edge platform. We use a small, deliberate set of subprocessors:
| Subprocessor | Purpose | Data it touches |
|---|---|---|
| Cloudflare | Hosting, database (D1), key-value store, CDN/TLS | All application data, encrypted in transit |
| Stripe | Subscription billing & payment processing | Billing details; card data handled by Stripe, never by us |
| Cloudflare Email | Transactional email (verification, team invites), when enabled | Recipient email address |
Want a copy of your data, or want your account and training records deleted? Email support@hackingames.com and we'll take care of it.
Found a security issue? Please report it to security@hackingames.com before disclosing it publicly, and give us a reasonable window to fix it. We welcome good-faith research and won't pursue action against researchers who act responsibly and avoid harming users or data.
We describe the controls we actually operate today. HACKIN'GAMES does not yet hold a third-party security certification (such as a SOC 2 attestation) for our own platform — and we won't claim one until it's real. What we offer is the training and the per-employee completion evidence your auditor needs for your security-awareness-training control; your auditor makes the final determination. See how that maps to SOC 2, ISO 27001 and HIPAA.