Code & Compute
Design, build, test, and ship reliable software.
- Programming and clean code
- Systems, testing, data, and design
Practice cybersecurity as an observable sequence: receive scope, inspect evidence, make the authorized call, and submit for an instant practice grade.
Free graded operation · No signup · Nothing to install
Two weeks on a shared clock with everyone who starts the same day, with a members-only board to talk it through. Free with a learner profile.
Each lane teaches a different system. Full Access opens all three.
Design, build, test, and ship reliable software.
Learn defensive security, testing, research, and response.
Build, evaluate, and secure modern AI systems.
Every claim resolves to work another operator can inspect.
One learner profile and one identity key work with both plans; no email is needed to start. Full Access is a monthly plan at the current monthly price. Cancel anytime.
| What you get | Free | Full Access |
|---|---|---|
| The free operation on this page | Included | Included |
| A campus profile, the feed, and Terminal Chat with end-to-end encrypted private rooms | Included | Included |
| The class directory and the playbook library | Included | Included |
| Starter items: two graded items in each of the three programs | Included | Included |
| Every class, lab, exercise and range objective beyond the starter items | Not included | Included |
| Certification exams and verifiable credentials | Not included | Included |
| Encrypted file sharing inside private rooms | Not included | Included |
| Progress and grades saved to your identity key's server record | Included | Included |
Inspect a simulated response, stay inside written scope, and submit two checks for an instant practice grade. Full Access opens every program, lab, exam, and credential at the current monthly price.
No timed trial. No learner profile is required for the free operation.Restoring your learner record…
Loading the class directory…
Lobby --Enter
Public Room --Enter
Private Room --Enter
Private Room --Create <name>
Private Room --Join <code>
Room --Leave
Say <message>
Who
Status
Whoami
Pwd
Echo <text>
Uptime
Traceroute <host>
Man <page>
Greywatch
Crosstalk
Help
No profile set.
Your name, bio, and colors travel together across rooms, profiles, and the community feed.
Choose the name and introduction people see first.
[b]bold[/b]
[i]italic[/i]
[#ff00ff]color[/]
[marquee]scroll[/marquee]
%n reader name · %d date · %t time
Build a combination that stays readable wherever your persona appears.
These use the real GreyNOC components, so what you see here is what the network sees.
See who is around, start a secure conversation, and keep your closest people within reach.
People waiting to join your circle.
Everyone in your circle.
Set the short signal people see beside your name.
Your status is public to your buddies. Away keeps you connected, but softens your name in lists.
Let GreyNOC update your presence when you step away.
Signal Command is the Academy interface. Persona colors still travel with your profile.
Device-only preferences. Idle timing stays in this browser; your public status follows your signed persona.
—Study on a shared clock. A cohort is a group of learners who start on the same day and finish together: join one, follow its dates, and talk it through on the cohort board.
Loading cohorts…
Every post you have made on any cohort board, including boards you can no longer open. Delete any you want gone.
Checking membership…
Manage what others can see, how this device remembers you, and the security controls tied to your GreyNOC identity.
Five kinds of data, five places. The carries the full retention terms; this card is the short version.
Choose the signals you share with other people. Every change takes effect immediately.
Blocks are tied to identity keys and never uploaded as a social graph.
Your identity, profile appearance, and session controls.
Your plan, the browsers signed in to it, and how to cancel. Cancel anytime: you keep Full Access until the end of the paid period and nothing more is charged.
Sign out any browser you no longer use. To add one, generate a migration code here, then sign in there with your checkout email. Codes work once and expire in 30 minutes. Billing stays with the browser that enrolled unless that browser signs itself out.
Review how GreyNOC handles data and the terms that apply when you use the service.
Permanent actions that cannot be undone.
This removes your saved profiles, identity key, friends, and local settings. You will appear as a new person the next time you enter.
Find quick answers, chat with BB, or send a case to GreyNOC Support.
Open BB Academy, choose a school and course, then start the first available module. Your progress is saved to this device identity as you complete lessons, quizzes, and exercises.
No. BB is not AI.
BB only reads editor code when you explicitly attach it. BB can describe visible patterns and local diagnostics, but it does not execute your program.
BB questions and optionally attached editor code stay in this browser. A human support case is transmitted only when you choose to submit one.
Open a support ticket for Full Access enrollment, billing, grading decisions, lesson content, or a technical issue that needs someone to review your specific case.
Choose Sign off in the account menu or in Settings › Account & display. It locks your identity on this browser and takes you to the sign-in page; the first time, it asks you to set a passphrase, and after that you sign back in with it. There is no passphrase reset, because GreyNOC has no account to recover it from. If it is forgotten, the sign-in page can start fresh on this browser with a new identity, which cannot be undone. If you have Full Access, sign in on a second browser first so the plan is never stuck behind a forgotten passphrase.
Open Settings › Full Access & billing and choose Cancel subscription. Stripe's billing portal opens; confirm there and the plan ends at the close of the paid period with no further charges. You keep Full Access until then. The receipt email Stripe sent you carries the same billing link.
Yes. On a browser that already has Full Access, open Settings › Full Access & billing and generate a migration code. On the other browser, choose Sign in to Full Access and enter your checkout email with that code. A few browsers can share one plan and any of them can sign the others out. Billing stays with the browser that enrolled; if you retire that browser, sign it out from itself and billing moves to your other browsers.
An in-app ticket needs a live connection and a verified device identity. If either is missing, email [email protected] instead and describe what you were doing when it failed.
GreyNOC occasionally shares two months of Full Access with people who find us through community outreach. Before using a key, note that it binds to your verified device identity, can be redeemed once, and does not stack with active Pro access.
If you arrived through our professional network, use LINKEDIN.
Eligible keys unlock 60 days of Full Access: coursework, Code Lab grading, the GreyPath range, exams, and credentials.
Room messages use identity-bound end-to-end encryption. Use the security guide below for the exact trust model, verification steps, and limitations.
ONE PLAN, EVERY PROGRAM
Study programming and cybersecurity with access to every Academy course, graded lab, range objective, and certification exam. Try the starter lessons before you enroll.
430guided modules
1,453graded exercises
141range objectives
55credentials
ONE CONNECTED ENVIRONMENT
Learn programming in BB Academy, build security foundations in Whitehat, and investigate simulated systems in GreyPath. Each area has lessons, practical work, and assessments.
LEARN WITH STRUCTURE
BB Academy gives you a deliberate path through programming, infrastructure, cryptography, security operations, and emerging technology. Each module combines focused instruction with knowledge checks and practical exercises.
PRACTICE THE WORK
Whitehat Foundations develops defensive habits through six progressive belts of lessons and server-graded labs. GreyPath then places you inside artifact-driven scenarios where evidence, decisions, and outcomes matter.
Read the lesson and understand the scope before testing.
Work through 20 practice tracks and 141 verified objectives.
Use controlled hints, score impact, and server-side feedback to refine your approach.
PROVE WHAT YOU CAN DO
Enrollment opens the training. It does not hand out the result. GreyNOC credentials are awarded only after you meet the associated assessment standard, and each one can be independently verified without exposing your private identity key.
55server-graded exams use randomized questions, protected answer keys, and domain-level performance reporting.
2,335questions measure knowledge across the catalog, including 482 scenario-driven items.
55serial-numbered credentials across 8 programs provide a portable record of achievement.
WHAT FULL ACCESS UNLOCKS
Free access is there so you can evaluate the environment. Full Access removes the limits when you are ready to build depth.
All 33 Academy subjects and 430 guided modules
Six Whitehat Foundations belts with 62 lessons and labs
The full GreyPath range with 141 objectives
55 formal assessments and 55 credentials
Secure file exchange inside encrypted study rooms
Ten community rooms and twenty saved profiles
Ten Code Lab collaborators and ten offline campus messages
A PRO mark beside your campus identity
SECURITY BY DESIGN
Your browser generates the identity key and keeps the private key on your device. Private rooms, direct messages, and calls are peer-to-peer and end-to-end encrypted. The server grades assessments and checks range submissions.
Stripe hosts checkout and receives card details directly. GreyNOC receives billing records and enrollment status. Read the complete .
FULL ACCESS
Learn across the entire catalog, practice in the full range, qualify for every credential, and expand the secure campus tools available to your identity.
Individual enrollment · Cancel anytime in Settings · Access to period end
Hosted checkout by Stripe. Your card details do not reach GreyNOC. Cancel anytime under Settings › Full Access & billing.
Enter the email from your Stripe receipt and a migration code generated on a browser that already has Full Access. Email alone is never enough to sign in.
Open structured coursework, white-team foundations, or the authorized practice range.
Run checks when ready.
Effective 16 August 2026 · Operated by GreyNOC · Contact: [email protected]
GreyNOC operates this service (the Academy campus, Code Lab, training programs, certifications,
DROP advisory board, and the GreyNOC OS arcade) at chat.grey-noc.com. For
anything in this document — questions, data requests, complaints — email
[email protected].
We do not collect names, emails, phone numbers, or passwords to use GreyNOC. Your identity is an Ed25519 key pair generated in your browser on first use. The private key never leaves your device; the server only ever sees the public half, which acts as your pseudonymous handle. Your screen name is whatever you choose — it does not need to be your real name. Because we hold no account record, losing your device key (for example by clearing browser storage without a migration code) is unrecoverable by design.
WebRTC connection setup uses Google's public STUN servers and may reveal network metadata, including IP information, to Google and to the peers you connect with. STUN does not receive the encrypted room, message, or call content.
The Community Lobby, public rooms, and the home feed are not private: what you post there is visible to everyone connected and passes through the server in plaintext. This community content is held in server memory only and is erased whenever the server restarts. DROP advisories you publish are public by intent and persist until you delete them or the bounded advisory store prunes the oldest entries (you can delete your own advisories in-app). Presence — your screen name, online/away status, and the “where in the app” activity badge — is broadcast to other users while you are connected; you can blank the activity badge with Hide my activity in Settings or leave the roster entirely with appear offline. Presence is never written to disk.
Persisted server-side, keyed to your identity key or an opaque vault token your browser holds:
These records survive server restarts. The store has bounded capacity; if a limit is reached, the service may prune the oldest or least-recently-used records before the retention event listed below.
/verify to anyone who has
the certificate's unguessable serial. GreyPath operation certificates may use a separate
name you choose for that credential; it is locked when you connect the completion to your
GreyNOC key. Treat sharing a certificate serial as publishing its printed name.
A full wipe removes your certificates and the locked name.Browser-only state includes your private keys, appearance and preferences, trust pins for buddies' keys, and cached progress, kept on this device only. You can wipe it any time (section 10).
GreyNOC Pro checkout happens on Stripe's hosted payment page. Your card details go directly to Stripe and never touch GreyNOC's servers. We pass Stripe your identity public key as the purchase reference; Stripe returns and we store: your Pro status, Stripe customer and subscription IDs, your checkout email, and the renewal date — keyed to your identity key so your entitlement can be honored and refunds or chargebacks can revoke it. Subscriptions are cancellable any time under Settings › Full Access & billing (which opens Stripe's billing portal) or from the receipt Stripe emails you; access continues until the end of the paid period. Stripe processes your payment data under its own privacy policy.
We use your IP address transiently for rate limiting and abuse defense (connection caps, attack-pattern scoring, temporary bans). This data lives in server memory with short windows (roughly 10-minute scoring, 15-minute automatic bans). High-severity security events (for example, exploit probes) may be written to server console logs with the offending IP. Operator-imposed manual bans store the IP, reason, and timestamps until they expire or are lifted, and may be permanent; placing one also disconnects any connection already open from that address. Bounded administrative-control and GreyPath-deletion audit records also store the operator's IP. The administrative console can display the connection IP of a live session alongside the screen name on it, for as long as that connection is open: the pairing is read from the open connection when an authorised operator loads the page, is never written to disk, and is never sent to other users — the buddy list and every other client-facing view continue to carry no address information at all. If an operator then bans or unbans an address, that action is written to a bounded administrative audit trail that records the address, the operator's own address, the duration, and the reason they gave — and when the ban was placed from a session, that reason may name the screen name it was placed for. Those audit entries persist after the ban itself expires or is lifted, until they age out of the trail.
The core messenger sets no cookies and GreyNOC embeds no third-party analytics, ad, or fingerprinting
scripts. GreyPath Operations sets signed, functional HttpOnly cookies: one remembers acceptance
of its authorization statement (normally 30 days), and separate cookies resume in-progress
Black Glass, Quiet Meridian, and Last Light runs (normally 12 hours). They are scoped to the
relevant /greypath routes, use SameSite=Strict, and are marked
Secure in production. Client state such as identity keys, preferences, progress,
the 18+ confirmation, and trust pins are kept in browser local
storage to make the app function. Our edge provider (Cloudflare) may set its own operational
cookies as part of serving the site.
Our own Academy usage counters record visits, free-operation steps, enrollment steps, and confirmed purchases as daily aggregate totals retained for up to 120 days. Browser events send only a predefined event name; the counters do not store a visitor identifier, identity key, URL, referrer, user agent, or raw IP address. Requests still pass through normal IP-based rate limiting and our edge provider. Browser-only receipts prevent the same event from being counted repeatedly in one day and are pruned after 35 days when updated. The counters start on your first public page view, before any confirmation or profile exists, and do not submit lesson answers or code.
We count visits and enrollment steps from your first public page view onward (the age and policy confirmation comes later, at the campus door) using our own daily aggregate counters, retained for up to 120 days. These counters store event names and totals, not identity keys, names, URLs, referrers, user agents, raw IP addresses, lesson answers, or code. Ordinary request rate limits and our edge provider still process connection information. Browser-local receipts prevent duplicate counts: dated receipts are pruned after 35 days when updated, while the first-dashboard receipt remains until browser storage is cleared.
chat.grey-noc.com
transits Cloudflare, which sees client IPs and request metadata and keeps edge logs under its
own policy.stun.l.google.com and stun1.l.google.com, which can receive IP and
connection metadata but not encrypted room, message, or call content.We do not sell personal information, and we do not share it for advertising. Ever.
The KEEP / WIPE switch in Settings' Danger Zone erases your local identity and settings, and deletes your server-side saved profiles, training progress, exam records, and certificates (including the locked certificate name). Because of how the system is built, a wipe does not remove: your Pro billing record (including the checkout email), sealed offline messages queued for you, buddy-list entries, published encryption prekeys, GreyNOC OS, FRAGNET, and GreyNet Browser records, promotion records, Academy support tickets, minimal exam-attempt counters and locks, security/ban/audit records, or DROP advisories you published (delete those in-app first). To have those residuals removed — or to request a copy of the data we hold against your identity key — email [email protected]. We verify such requests by asking you to prove control of the identity key (and, for billing records, the checkout email), since that key is the only thing that ties data to you.
If you are in the EU/UK (GDPR) or California (CCPA/CPRA), the rights to access, correct, delete, and port your data apply as described above; we honor them regardless of where you live. California residents: section 11 is your full California Privacy Notice, including the categories we collect, how to exercise each right, and our response times. We cannot produce end-to-end encrypted content in response to any request — we do not hold the keys. We process the little personal data we have to provide the service you request (contract), and to keep the service secure (legitimate interest).
This section is the notice California residents are entitled to under the California Consumer Privacy Act as amended by the CPRA. GreyNOC is available to California residents. We honor everything below regardless of whether the CCPA's business-size thresholds actually apply to us — we would rather meet the standard than argue about it.
You see a short version of this notice on the age & policy confirmation, which we show before a first-time visitor creates a learner profile or enters the community campus. Loading the public page still means your request reaches our edge provider and server, which see your IP address, and the limited aggregate counters and browser receipt described in section 8 begin with that public-page visit. The real-time service connection and locally generated identity keypair are deferred until the campus boots — when you ask to enter, return as an onboarded visitor, or open a campus deep link. The private key remains on your device; the public identity is used by campus services as described in sections 3, 7, and 9. Sections 3–9 above are the long version; the statutory categories map onto them like this:
We do not collect Social Security or government ID numbers, financial account numbers (Stripe holds those, not us), biometric information, precise device geolocation from the app, education records as defined by FERPA, or inferences drawn to build a profile about you. We run no ads, no third-party analytics, and no fingerprinting.
We keep each category only as long as section 5 describes: pending buddy requests and results expire after 30 days, uncollected sealed messages after 7 days, IP scoring within roughly 10–15 minutes (longer only for manual bans and audit records), and community content until the next server restart. Saved profiles, training progress, exam records, and certificates persist until you wipe them. Records a wipe does not reach — your Pro billing record and checkout email, promotion records, buddy-list entries, published prekeys, arcade and range records, support tickets, and the rest of the section 10 list — persist until you ask us to remove them; security, ban, and audit records are kept for as long as they serve that purpose, and an operator-imposed ban may be permanent (section 7). The store has bounded capacity, so the oldest or least-recently-used records may be pruned sooner. We do not keep personal information for longer than needed for these purposes.
We have not sold personal information, and we have not shared it for cross-context behavioral advertising, in the preceding 12 months — nor will we. We do not sell or share the personal information of anyone, including minors under 16. Because there is nothing to opt out of, GreyNOC does not run a “Do Not Sell or Share My Personal Information” link; if that ever changes, this section changes with it and the link appears. The service providers in section 9 (Stripe, Cloudflare) process data on our behalf under contract, which is not a sale or a share.
We do not use or disclose sensitive personal information for any purpose beyond what is necessary to provide the service you asked for. We do not use it to infer characteristics about you. Your identity private key — the credential that would unlock everything — never leaves your device, so we never hold it. Because we make no use of sensitive personal information that the CPRA lets you limit, the “Limit the Use of My Sensitive Personal Information” right would not change how we handle your data; you can exercise it anyway and we will confirm it in writing.
Most of it you can do yourself, instantly, without asking us: the KEEP / WIPE switch in Settings' Danger Zone deletes your local identity and your server-side profiles, progress, exam records, and certificates. For anything the wipe leaves behind (section 10), email [email protected] with the request you are making. That mailbox is the designated method for all California requests.
How we verify you. GreyNOC has no accounts, so the only thing that ties data to you is your identity key: we ask you to prove control of it by signing a challenge we send (and, for billing records, to confirm the checkout email). We cannot honor a request we cannot verify to this standard, and the law does not require us to re-identify data we hold in a form that cannot be linked to a real person — but we will always tell you which of the two it was rather than going quiet. An authorized agent may submit a request for you with your written permission; we will still need the key-control proof.
Timing. We confirm receipt within 10 business days and respond within 45 calendar days. If we need more time we will tell you before the 45 days are up and take at most another 45 (90 total). We do not charge a fee to handle these requests, unless one is manifestly unfounded or excessive, in which case we will explain before doing anything.
What we cannot produce. End-to-end encrypted content — private rooms, direct messages, calls, and sealed offline mail — is not something we can hand over, correct, or read on request. We do not hold the keys. That is a design property of the service, not a refusal.
We do not disclose personal information to third parties for those parties' own direct marketing purposes. If you want that confirmed in writing, email us and we will send it.
GreyNOC is an 18+ service (section 12) and is not directed to minors. If content was nonetheless posted here by someone under 18, that person — or a parent or guardian — may email us to have it removed. Removal takes the post out of public view; it may not erase copies other users already saw, and public community content is erased on server restart in any event.
GreyNOC's free features cost nothing; the current Full Access price is shown on the Full Access page before you check out. To file a complaint about the service, email [email protected]. California residents may also contact the Complaint Assistance Unit of the Division of Consumer Services of the California Department of Consumer Affairs in writing at 1625 North Market Blvd., Suite N 112, Sacramento, CA 95834, or by telephone at (800) 952-5210.
Creating a learner profile and using the community campus require you to be 18 or older, self-attested on the age & policy confirmation shown before either one (that confirmation is the only place we ask). Public course information, the free operation, pricing and the playbook library are open to read without it. The service is not directed to children, and we do not knowingly collect personal information from anyone under 18 — if you believe we hold such data, email us and we will delete it promptly.
Beyond end-to-end encryption, the service uses signed identities, post-quantum sealing for offline mail, a hardened content-security policy, and active abuse monitoring. No system is perfect: if a breach affects personal data we hold, we will notify affected users where feasible and any supervisory authority as required by law (including within 72 hours where GDPR applies). Security researchers: responsible disclosure is welcome — see the project's security policy before testing anything.
We may update this document as the service evolves. Material changes will be posted here with a new effective date; continuing to use GreyNOC after a change takes effect means you accept the updated version.
By using GreyNOC you agree to this User Agreement and the Privacy Policy above. You must be at least 18 years old.
GreyNOC is offered to California residents on the same terms as everyone else. Section 11 of the Privacy Policy is your California Privacy Notice: it lists what we collect, states that we neither sell nor share personal information, and explains how to exercise your CCPA/CPRA rights. We will not deny service, change your price, or degrade your experience because you exercised those rights. Nothing in this agreement waives a right California law gives you, and where any term here conflicts with California law as it applies to you, California law controls and the rest of this agreement stays in effect.
Access, entitlements, and credentials are bound to your device identity key. Keep your device and browser storage safe. If you lose the key without a Pro migration code, we cannot restore what was bound to it — there is no account-recovery back door, on purpose.
You keep ownership of what you post. You grant GreyNOC the limited license needed to display and relay it to other users (that is what a chat service does). Public posts are public; community content is ephemeral and vanishes on server restart, so keep your own copies of anything you care about.
Certificates are earned by passing open-book, server-graded exams and are issued under the name you lock, verifiable by anyone holding the certificate serial. Cheating, sharing exam content, or gaming the grader voids the credential.
The service, including all training content, is provided “as is”, without warranty of any kind. Educational material is not professional, legal, or career advice. We do not guarantee uptime — community data does not survive restarts, and the service may change or end at any time.
To the maximum extent permitted by law, GreyNOC's total liability for any claim arising from the service is limited to the amount you paid us in the twelve months before the claim, and we are not liable for indirect, incidental, or consequential damages.
You can stop using GreyNOC at any time (see section 10 for erasure). We may suspend or terminate access for violations of this agreement.
This agreement is governed by the laws of the United States. If any provision is found unenforceable, the rest remains in effect.
Questions about this agreement or your data: [email protected].