IncidentKitBuild Your Exercise

Security & AI Use

We take a deliberately conservative approach to how AI is used in this product. Here's exactly how it works.

A hybrid content system, not free-form AI

Every exercise starts from a carefully written, human-reviewed base template for its scenario. AI is used only to tailor specific, pre-approved sections — like phrasing an executive overview for your organization type — never to invent the exercise structure, the number of injects, or the overall content strategy from scratch.

Structured, validated output

The AI is required to return a structured response matching a strict schema. Every response is validated before it's used; malformed or non-conforming responses are automatically rejected and retried. A layer of automated content checks also screens for content that shouldn't appear in an exercise (like exploit code) before anything is rendered into your package.

Your input can't hijack the system

The only free-text field you can fill in is treated strictly as background flavor text, never as instructions to the AI. It's length-limited and sanitized, and the system is explicitly instructed to ignore anything in it that looks like an attempt to change its behavior.

What the AI will never produce

Our system prompt and content checks are designed to prevent real exploit code, working attack payloads, malware source code, or step-by-step system-compromise instructions from appearing in any package — regardless of what scenario or context you provide.

No guarantee of compliance

IncidentKit content is educational material only — not legal, regulatory, or incident-response advice. It does not guarantee compliance with any law, regulation, contract, or standard. NIST CSF references included in your package are high-level and illustrative, not a compliance mapping.

Data handling

Your exercise configuration is sent to Anthropic's API solely to generate your tailored content. We don't use your data to train models. Download links use cryptographically strong, hashed, expiring tokens, and file access is strictly scoped to your own order — one customer can never access another customer's files.

Spend and abuse controls

We enforce a configurable monthly AI spending ceiling, rate limits on preview and generation endpoints, and input size limits throughout, to keep the service reliable and to prevent abuse.