Platform security and data handling
How the Range platform protects your data, and why training never requires connecting it to your production identity systems.
Range is a training platform, so the most important security property is simple: you do not have to connect it to your production identity systems to use it. You train against realistic, self-contained scenarios, not your live environment.
You train against simulations, not production
Scenarios are modeled on documented attacks, but they run inside the platform. There is no need to grant Range access to your real Active Directory, Entra ID, cloud, or SaaS tenants to get value from it. That keeps the blast radius of training at zero.
Data protection
The platform follows standard security practices: data is encrypted in transit, access is restricted, and accounts are scoped to what each user needs. We collect the data required to run scenarios, score decisions, and issue completion records, and nothing more than the service needs.
Access and accounts
Access is managed per user, with roles for individual responders, team members, leads, and presenters. We support modern authentication practices for sign-in.
Questions
For specifics on data handling, hosting, or a security review as part of an evaluation, ask when you request access and our team will follow up. General questions can go through support.