Site information

Privacy and Data Handling

This page describes the behavior of the public 1200km.com website and its browser-based research tools. It does not replace the privacy or security documentation for a separately deployed AdversaryGraph instance.

Effective date: 21 July 2026. Last updated: 21 July 2026.

Static pages and hosting

The main research site is published as static files through GitHub Pages. As with any website, the hosting and network providers involved in delivering a request may process ordinary connection information such as an IP address, requested URL, timestamp, browser user agent, and diagnostic logs under their own policies.

Site search uses a statically generated Pagefind index loaded into the browser. Search terms are evaluated in the browser rather than submitted to a dedicated 1200km search API. The full search page can place a query in the page URL, so it may remain in browser history and appear in ordinary hosting or analytics request data. Loading the index also requires normal requests for site assets.

Analytics and browser storage

Pages configured for measurement defer Google Analytics until visitor interaction or 30 seconds after load. Google may then receive usage, device, referral, network, and page information and may use its own cookies or browser storage according to its terms. The 1200km application stores the selected light or dark theme in localStorage; it does not operate a user account or first-party advertising profile.

Public tools and demonstrations

Do not submit confidential, customer, regulated, privileged, or unpublished material to a public demonstration. Threat Matrix is a public, browser-based ATT&CK workspace; the full self-hosted AdversaryGraph platform has separate deployment and data-handling boundaries documented with that software.

The AdversaryGraph feedback form processes text and an optional image locally. It does not upload either item to 1200km. Choosing email or GitHub opens the relevant third-party draft, and the visitor decides whether to submit it. Screenshot previews use a temporary browser object URL that is revoked locally.

Links to GitHub, Medium, LinkedIn, MITRE, Google, and other external services are governed by those services. Contact initiated through the site is handled by the visitor’s email provider and the receiving mailbox.

For privacy, correction, or deletion requests concerning information directly controlled by 1200km, use the public contact section. Requests concerning GitHub, Google, Medium, LinkedIn, hosting logs, or another external provider must also follow that provider’s process.

Policy boundary

This is a factual data-handling notice, not a representation of GDPR, CCPA, SOC 2, ISO 27001, or another certification or legal-compliance status. Legal obligations and consent requirements depend on jurisdiction and should receive professional review.

Behavior verified against the static site, Pagefind integration, analytics loader, feedback script, and public workspace on 21 July 2026.