AI Offensive Security Certification
AU · CA · NZ · UK · US
StrikeOps Academy
CurriculumPathwaysCertificationsPricing
Search/Start learning
Legal

Privacy Policy

Last updated 2 August 2026

This policy explains what we collect, how we use it, and the choices you have. It applies to everyone who uses StrikeOps Academy.

01Who we are

StrikeOps Academy is an online offensive-security learning and certification platform operated by StrikeOps Inc., a company incorporated in the United States (“StrikeOps Academy”, “we”, “us”). This policy covers strikeopsacademy.com and the StrikeOps Academy learning platform.

For the purposes of the UK and EU GDPR, StrikeOps Inc. is the data controller for the personal data described here. You can reach our privacy team at privacy@strikeopsacademy.com.

02Information we collect

Account and profile data you provide: your name, email address, password or sign-in method, organisation, and country or region (which drives applicable terms and tax).

Billing data: subscriptions and certification exams are processed by our payment provider, Stripe. Stripe handles your card details directly; we receive limited billing metadata (for example, the last four digits, plan, and transaction status) and never store full card numbers.

Learning data: your enrolments, module progress, knowledge-check and lab activity, exam attempts, and issued credentials.

Communications: messages you send us through the contact form, support requests, and related correspondence.

Technical data: IP address, device and browser information, approximate location derived from IP, and usage collected through cookies and privacy-respecting analytics.

03Cookies and analytics

We use strictly necessary cookies to keep you signed in and to remember preferences such as your theme. We use privacy-respecting, aggregate analytics (including Vercel Web Analytics and Speed Insights) to understand traffic and performance; these do not build advertising profiles of you.

You can control cookies through your browser settings. Blocking strictly necessary cookies may prevent parts of the platform, such as sign-in, from working.

04How we use your information

To deliver the courses, labs, and assessments; process payments; issue, display, and verify credentials; personalise and improve the content; communicate with you about your account and the service; secure the platform and prevent abuse; and meet our legal and regulatory obligations.

05Legal bases (UK/EU GDPR)

Where the GDPR applies, we rely on: performance of our contract with you (to provide the courses, labs, exams, and credentials); our legitimate interests (to secure, maintain, and improve the platform, and to prevent abuse), balanced against your rights; your consent (for optional marketing, which you can withdraw at any time); and compliance with legal obligations (such as tax and accounting).

06When we share information

With service providers who process data on our behalf under contract (see Sub-processors below). When you choose to display or share a credential, the linked verification page is public by design so that others can confirm it.

In connection with a corporate transaction such as a merger or acquisition, and where required by law, legal process, or to protect the rights, safety, and security of the platform and its users.

We do not sell your personal data, and we do not share it for cross-context behavioural advertising.

07Sub-processors

We use a small set of vetted providers to run the service: cloud hosting and delivery (Vercel), our application database (Neon, Postgres), authentication (WorkOS), payments and tax (Stripe), and analytics (Vercel). Each processes personal data only on our instructions and under appropriate data-protection terms.

08International transfers

We operate across the Five Eyes markets (Australia, Canada, New Zealand, the United Kingdom, and the United States) and our providers may process data in those and other countries. Where data leaves your region, we rely on appropriate safeguards, such as the UK/EU Standard Contractual Clauses or an adequacy decision, as applicable.

09Data retention

We keep personal data only as long as needed for the purposes above or as the law requires. Account and learning data are retained while your account is active and for a reasonable period afterwards. Credential records are retained so that issued badges remain verifiable. Billing records are kept for the periods required by tax law.

10Your rights

Subject to applicable law, you can request access to, correction of, deletion of, or a portable copy of your personal data; object to or restrict certain processing; and withdraw consent where processing is based on it.

We honour rights under the UK and EU GDPR, the Australian Privacy Act 1988 (and the Australian Privacy Principles), Canada’s PIPEDA, New Zealand’s Privacy Act 2020, and US state privacy laws including the California Consumer Privacy Act, where they apply to you.

To exercise any right, email privacy@strikeopsacademy.com. We will respond within the timeframe your law requires and may need to verify your identity first. We will not discriminate against you for exercising a right.

11Marketing communications

We send account and service messages that are necessary to provide the platform. Any optional marketing is sent only with your consent or where otherwise permitted, and every marketing message includes an unsubscribe link. Opting out of marketing does not stop essential service messages.

12Security

We use technical and organisational measures appropriate to the risk, including encryption in transit, access controls, and managed authentication. No method of storage or transmission is perfectly secure, so we cannot guarantee absolute security. If you believe you have found a vulnerability, please contact security@strikeopsacademy.com.

13Children

The platform is intended for professionals and is not directed to children. You must meet the age of digital consent in your jurisdiction to create an account. If we learn that we have collected a child’s data without a lawful basis, we will delete it.

14Complaints

If you have a concern, contact us first at privacy@strikeopsacademy.com and we will try to resolve it. You also have the right to complain to your data-protection authority. Examples include the UK Information Commissioner’s Office (ICO), the Office of the Australian Information Commissioner (OAIC), the Office of the Privacy Commissioner of Canada, or the Office of the Privacy Commissioner in New Zealand.

15Changes and contact

We may update this policy from time to time and will post the revised version here with a new date; material changes will be highlighted. Questions or requests can be sent to privacy@strikeopsacademy.com.

Ready when you are

Certify the dual mandate.

Start free, learn on subscription, and earn a verifiable credential recognised across the Five Eyes.

Start learningCompare certifications
STRIKEOPS ACADEMYPROFESSIONALSOCPCERTIFIED
StrikeOps Academy

The certification for operators who wield AI in offensive engagements and attack the AI systems inside every target.

Recognised across
AUCANZUKUS
Learn
  • Curriculum
  • Learning pathways
  • Search
Certify
  • Certifications
  • Pricing
  • Certification exams
Credentials
  • Associate · Silver
  • Professional · Gold
  • Expert · Platinum

Questions, or planning a team rollout?

Talk to our team and we will point you to the right track or credential.

Contact us

© 2026 StrikeOps Academy. A StrikeOps company. All rights reserved.

Privacy PolicyTerms of Service

The offensive techniques taught here are for authorised security testing only. The StrikeOps Academy labs are the sole sanctioned target unless you hold explicit written authorisation.