Effective date: August 14, 2026
Last updated: August 14, 2026
This privacy policy applies to Breachwright, an open-source, local-first penetration test management application published by Advent Cybersecurity LLC. It also covers information you provide directly to Advent when requesting Breachwright support. It does not replace the privacy terms of Microsoft, GitHub, an AI provider, or another service that you choose to use with the application.
Information Breachwright processes
Breachwright processes information that an operator enters, imports, generates, or attaches to a local assessment workspace. Depending on how the application is used, that information may contain personal information or confidential client data.
- Assessment information, including engagement and client names, scope, targets, findings, affected systems, evidence, remediation notes, retest status, and report content.
- Files selected by the operator, including scanner output, Active Directory assessment data, evidence attachments, notebook attachments, report-template assets, imports, and generated reports.
- Local configuration, including the selected AI provider, models, custom endpoint settings, and API credentials supplied by the operator.
- Local technical information, including application logs, version information, diagnostic state, backup metadata, and file-integrity results.
Breachwright does not include Advent-operated advertising, behavioral analytics, or product telemetry. The application does not automatically upload the contents of the local workspace to Advent Cybersecurity.
How information is used
Breachwright uses workspace information to provide functions requested by the operator, including:
- Managing assessments, findings, evidence, checklists, retests, and reports.
- Importing, correlating, searching, exporting, backing up, and restoring assessment records.
- Running operator-selected security tools against operator-specified targets.
- Preparing optional AI-assisted analysis, drafts, narratives, and report content.
- Producing local diagnostics and a support snapshot that excludes logs, credentials, workspace content, and the local data path.
Local storage and retention
On Windows, Breachwright stores its default workspace under%USERPROFILE%\.breachwright. This includes a local SQLite database, assessment files, reports, backups, logs, and a configuration file. The application does not operate an Advent cloud account or hosted workspace for this data.
Workspace information remains on the device until the operator deletes individual records and files or removes the workspace. Uninstalling the Microsoft Store or ZIP distribution does not delete the workspace, which allows data to remain available for a later reinstall. To remove all local Breachwright data on Windows, close the application and delete the%USERPROFILE%\.breachwright folder after preserving any required backup.
Backups, exports, reports, and other copies saved outside the workspace remain wherever the operator places them. Deletion may also be subject to operating-system backups or organizational retention controls. Advent cannot access or delete local copies that it does not possess.
External services and disclosures
Optional AI providers
AI features are optional. Manual findings, evidence management, checklists, imports, exports, backups, and non-AI reporting can be used without configuring an AI provider.
When an operator configures and invokes an external AI provider, Breachwright sends the prompt and assessment context needed for that requested operation directly to the selected provider. Supported options include Anthropic, OpenAI, Azure OpenAI, and AWS Bedrock. Operators may instead configure a compatible local or self-hosted model endpoint.
Common credential patterns are redacted locally before AI context is sent by default. Redaction reduces accidental disclosure but cannot guarantee that every sensitive value or item of personal information will be detected. Operators should review the data, provider configuration, and the selected provider's privacy, security, and retention terms before using an external model. Provider processing is governed by the operator's account and agreement with that provider, not by this policy.
Update checks
When Breachwright starts, it requests public release information from the GitHub releases API to determine whether an update is available. The request does not include assessment content. As with an ordinary internet request, GitHub may receive network and request metadata under its own privacy terms.
Microsoft Store
Microsoft operates Store distribution, downloads, installation, and updates. Information processed by Microsoft for those services is governed by Microsoft's privacy terms. Breachwright does not receive Microsoft account credentials through the application.
Support communications
If you contact Advent for support, Advent may receive your name, email address, company name, technical description, and any files or diagnostic information you choose to provide. Advent uses that information to respond, troubleshoot, maintain security records, and meet applicable legal obligations. Support information may be handled by service providers that operate Advent's email and business systems. Do not send assessment content, credentials, or other sensitive information unless Advent has asked for it and an appropriate transfer method has been agreed.
Advent does not sell or rent Breachwright workspace information or use it for third-party advertising.
Security
The packaged desktop application binds its local service to the loopback interface and does not provide a remote Advent account or application login. Anyone who can use the operating-system account may be able to access Breachwright data and run configured tools. Protect the device with operating-system authentication, current security updates, appropriate file permissions, and disk encryption.
Breachwright does not apply separate application-level encryption to the SQLite database or workspace files. AI API credentials are stored in the local configuration file and are excluded from Breachwright backups and support snapshots. Managed AI providers are contacted through their supported client libraries and endpoints. The operator is responsible for the transport and access controls of a custom or self-hosted endpoint.
Your choices and controls
- Use Breachwright without configuring an AI provider.
- Choose a managed, local, or self-hosted AI provider.
- Keep local credential redaction enabled and review context before external AI use.
- View, edit, export, back up, and delete locally stored records using the application and file system.
- Delete provider credentials from the local configuration and stop using the provider.
- Contact the selected external provider about data it processed under that provider's terms.
Because Advent does not receive the local workspace through Breachwright, requests to access or delete that workspace must be completed on the operator's device. For personal information in support communications held by Advent, contact Advent using the address below.
Children
Breachwright is designed for security professionals and organizational users. It is not directed to children, and Advent does not knowingly use Breachwright to collect personal information from children.
Changes to this policy
Advent may update this policy when Breachwright features, data flows, or legal requirements change. The effective and last updated dates at the top of this page identify the current version.
Contact
Questions or requests concerning this policy may be sent to contact@adventcybersecurity.com.
Product information and source code are available on the Breachwright product page.