ThinkCNAP.org ← Back to home

Privacy & Terms

Last updated: 9 October 2026

This page explains what data ThinkCNAP processes and the terms for using it. It applies to the website thinkcnap.org, the application app.thinkcnap.org, the ThinkCNAP API, and the submission of reports from the attack-simulation container to ThinkCNAP. In this page, "ThinkCNAP", "we" and "us" refer to the operator of the service; "you" refers to the person using it.

Privacy Policy

1. Data we process

We only process the data needed to run the service:

CategoryWhat it includes
AccountEmail address; display name; a hash of your password (email sign-up) or your Google account identifier (Sign in with Google); whether your email is verified; account creation and update timestamps.
Assessment dataThe impact, effort and initial, present and desired maturity values you set for each security measure.
API tokenA randomly generated token linked to your account, its expiry date (one year after creation) and whether it has been revoked.
Attack simulation reportsThe report your attack-simulation deployment submits with your API token. Its content is produced in your environment and may include technical details such as hostnames, IP addresses, cluster, namespace and resource names, and the results of each simulated technique.
One-time tokensEmail verification and password reset tokens, which expire after 24 hours and can be used once.
Technical dataIP address, browser user agent and request metadata processed by our hosting provider to deliver and protect the service.

Configure your attack-simulation deployment so that reports do not contain secrets, credentials or personal data.

2. Anonymous mode

If you choose "Continue Anonymously", no account is created. Your scores are stored only in your browser's local storage and are not sent to our servers. Clearing your browser data removes them. API tokens and attack simulation reports are not available in anonymous mode.

3. How we use data

We do not sell your data, use it for advertising, or share it with third parties except the service providers listed below. We process account and assessment data to provide the service you request, and technical data for our legitimate interest in keeping the service secure and available.

4. Cookies and browser storage

ThinkCNAP does not use analytics, advertising or tracking cookies. The application uses your browser's local storage for:

Signing out removes the session token. If you use Sign in with Google, Google may set its own cookies under its own policies.

5. Service providers

We use the following providers to run ThinkCNAP. They process data on our behalf, and data may be processed in countries other than your own.

ProviderPurpose and data
CloudflareHosting, network and database (Cloudflare Pages, Functions and D1). Stores all account, assessment, token and report data, and processes technical request data.
ResendDelivers verification and password reset emails. Receives your email address and the email content.
GoogleOnly if you use Sign in with Google. Google authenticates you and shares your email address, name and Google account identifier with us.
jsDelivr and Tailwind CSS CDNServe scripts used by the pages. As with any web request, they receive your IP address and browser user agent.

6. API tokens and AI agents

Anyone holding your API token can read your maturity assessment and change your scores. If you give the token to an AI agent, a CI/CD pipeline or another third-party tool, that tool will access your ThinkCNAP data, and its provider's own terms and privacy policy apply to whatever the tool processes. Data such as your cloud environment details or assessment results that you share with an AI agent is handled by that agent's provider, not by ThinkCNAP. Regenerate your token in the app at any time to revoke access.

7. Retention and deletion

When you ask us to delete your account, we delete your account, assessment data, API tokens and reports. Copies may remain in backups for a limited period until they are overwritten.

8. Security

All traffic to ThinkCNAP is encrypted with HTTPS. Access to your data requires your session or your API token. No system is completely secure. Keep your password and API token confidential, and regenerate the token if you suspect it has been exposed.

9. Your choices and rights

You can change your assessment data, change your password and regenerate your API token in the app at any time. You can also ask us to give you a copy of your data, correct it, or delete your account. Depending on where you live, you may have further rights under data protection law, such as the right to object to processing or to complain to your local data protection authority.

To make a request, contact us via LinkedIn and include the email address of your ThinkCNAP account. We may need to confirm that you own the account before acting on a request.

10. Children

ThinkCNAP is a professional security tool and is not intended for anyone under 16. We do not knowingly collect data from children.

Terms of Use

By creating an account, using the application or API, or deploying the attack-simulation container with a ThinkCNAP token, you agree to these terms.

1. The service

ThinkCNAP provides security maturity assessment for cloud native applications and a way to submit and view attack simulation results. The service is currently free of charge. We may change, suspend or discontinue features, or the service as a whole, at any time. We do not guarantee availability or any particular response time.

2. Accounts and API tokens

3. Attack simulation: authorized use only

The attack-simulation container executes real attack techniques mapped to MITRE ATT&CK, for example reverse shells, access to cloud instance metadata, use of Kubernetes service account tokens, and launching privileged pods. These actions can trigger security alerts, create or change resources, and affect running workloads.

The container is distributed from github.com/aliaksxssv/attack-simulation; its use is also governed by the license in that repository.

4. Acceptable use

You must not:

To report a security vulnerability in ThinkCNAP, contact us privately via LinkedIn instead of testing it against the live service.

5. Your data

You keep all rights to the assessment data and reports you submit. You allow us to store and process them only as needed to provide the service to you, as described in the Privacy Policy above.

6. Assessment results

Maturity scores, recommendations and simulation results are guidance for improving your security. They are not an audit, a certification, legal advice or proof of compliance with any standard or regulation, and they depend on the accuracy of the data you enter. ThinkCNAP is not affiliated with or endorsed by Amazon Web Services, The MITRE Corporation or the Linux Foundation.

7. Third-party content and trademarks

8. Disclaimer and limitation of liability

The service, the attack-simulation container and all content are provided "as is" and "as available", without warranties of any kind, including fitness for a particular purpose, accuracy and non-infringement. To the maximum extent permitted by law, ThinkCNAP is not liable for any indirect, incidental, special or consequential damages, or for loss of data, revenue or business, or for damage to systems, arising from your use of the service or the attack-simulation container. Nothing in these terms limits liability that cannot be limited by law.

9. Ending your use

You can stop using ThinkCNAP at any time and ask us to delete your account. We may suspend or delete accounts that breach these terms or put the service or other users at risk.

10. Changes and contact

We may update this page as the service changes. The "Last updated" date at the top shows the latest version; continuing to use ThinkCNAP after an update means you accept it. For questions or requests, contact us via LinkedIn.