Security & Trust
Purple Edge runs offensive-security training on real infrastructure - so the platform is engineered, operated and attacked by people who break systems for a living. Here is how we protect yours.
Isolated lab environments
Every lab runs in its own isolated network segment with per-environment firewall rules. Machines are dedicated to your session - labs never share targets across customers, and teardown is automatic.
EU-hosted infrastructure
The platform runs on AWS in the European Union (eu-west-3, Paris). Bring-Your-Own-Cloud deployments run labs inside YOUR AWS account, so lab data never leaves your perimeter.
Encryption in transit
All traffic between your browser, the platform and lab gateways is encrypted with TLS. Remote desktop sessions are brokered through an authenticated gateway - lab machines are never exposed directly to the internet by default.
Role-based, consent-based access
Organisation, instructor, student and member roles are enforced server-side on every request. Joining an organisation always requires the invitee's explicit acceptance - accounts are never silently claimed or converted.
Payments handled by Stripe
All card data is handled entirely by Stripe (PCI-DSS Level 1). Card numbers never touch Purple Edge servers; invoices and receipts are available through the Stripe customer portal.
Built and tested by penetration testers
Purple Edge is built by a practicing penetration testing team, and the platform itself undergoes recurring internal penetration tests. Findings are triaged and fixed with the same discipline we sell.
For your security review
- Data processing agreement (DPA): available on request - we sign a DPA with every enterprise customer.
- Sub-processors: AWS (infrastructure, EU), Stripe (payments). A current list is included with the DPA.
- Data deletion: lab environments are destroyed on teardown; account deletion removes personal data from the platform.
- Single sign-on (SAML/OIDC) & SCIM: on our enterprise roadmap - talk to us about your identity provider and timeline.
- Vulnerability reports: found something? We want to know - report it responsibly and we will respond quickly.
Security questions, DPA requests and disclosures: info@purpleedge.io
Put this into practice
Spin up real Kali, Ubuntu and Windows labs in your browser and learn by doing. Guided, hands-on, no setup.