TID-CMM Threat-Informed Detection Capability Maturity Model
HomePrivacy

Privacy

No cookies. No analytics. No accounts. Nothing you enter into the assessment is transmitted anywhere, because there is nowhere for it to go — this site has no backend.

Why this matters more here than on most sites. A completed TID-CMM assessment is a precise description of where an organisation cannot see an attacker. That is exactly the document an adversary would most like to read. It should never be uploaded to a third party, and this tool makes that impossible rather than merely promising it.

What is stored, and where

WhatWhereLeaves your device?
Your assessment — environment, crown jewels, adversaries, scores, evidence notesYour browser's localStorage, under the key tid-cmm-v11No
Light or dark theme preferencelocalStorage, key tid-cmm-themeNo
Search queriesNowhere. The index is downloaded once and matched in memoryNo
Server logsCloudflare records the request metadata any web server sees — IP, time, path, user agent. No account, no cookie, nothing tying requests togetherStandard request metadata only

How to erase everything

Clear site data for this domain in your browser, or use the tool's own Reset control. Both remove the two keys above completely. There is no copy anywhere else to request the deletion of, which is why this site has no data subject request process — it holds no personal data to be the subject of one.

The controls that enforce this, not just claim it

A privacy statement nobody can verify is a promise. These are the mechanisms, all inspectable from your browser's network tab:

Contact

Security or privacy concerns: hello@tid-cmm.com, or see security.txt. This site is operated by Reza Adineh; there is no company, no processor and no sub-processor.