Your staff see the phish first. Make that your advantage.
Every suspicious email your people report becomes regional threat intelligence — and every simulation and training assignment is shaped by it. Seraph CTI closes the loop between the attack and the awareness programme, at Kenyan granularity.
Essentials · $2.50 per seat / month · self-serve available
Action required: your VAT refund of KSh 84,200
Dear customer, our records show a pending refund. Verify your bank details within 24 hours via the secure portal to avoid forfeiture…
- Infrastructure first seen
- 2 days ago · KE
- Reported by
- 3 organisations
- Sector concentration
- Financial services
What this one report produced
Illustrative — not a client's record
How it works
One loop, four moves
The platform is a closed circuit: report, analyse, simulate, train — each pass raises your resilience score.
Report
A Report button in Outlook and Gmail. One click sends the full message to an analyst Threat Inbox, attributed to the organisation that caught it.
Analyse
Reports meet the catalogue: known-exploited flags, profiled threat actors, and breach-exposure monitoring of your domains.
Simulate
Campaigns modelled on what is actually circulating here this quarter — safe, measured, department by department.
Train
The people who clicked get the course that closes their specific gap. Completion tracked, repeat-clickers surfaced.
The platform
One system from first phish to measured resilience
Six capabilities that feed each other: what your staff report becomes intelligence, intelligence shapes the next simulation, simulations target the training that closes the gap.
Phishing simulationsSimulate
Realistic, safe campaigns by department and risk profile — click, open, attachment and credential-submission tracking with per-team resilience scoring.
02Targeted training & LMSTrain
Courses and quizzes assigned from simulation outcomes, not a calendar. Completion and comprehension tracked to the individual.
03Threat intelligenceAnalyse
A living catalogue of vulnerabilities, CISA known-exploited flags and profiled threat actors — matched to the technologies your organisation actually runs.
04Breach & leak monitoringMonitor
Your domains watched across breach and infostealer corpora. Exposed staff surface as alerts and an auto-maintained training group.
05One-click phishing reportingRespond
Outlook and Gmail add-ins put a Report button in every mailbox. Reports land in an analyst Threat Inbox, attributed to your organisation.
06Enterprise readinessGovern
Per-tenant SAML SSO, enforced MFA, org-scoped API keys, full audit logging and hard tenant isolation. Built to pass your security review.
Why Seraph CTI
Global vendors see Kenya as a region. We see it as the dataset.
Local granularity, by design
Client phishing reports from East African organisations are intelligence no global feed replicates — the lures, brands and infrastructure targeting this market specifically.
Simulations informed by real campaigns
Templates derive from what is actually landing in Kenyan inboxes this quarter, not a global library’s greatest hits.
Evidence for your board
Resilience rate, repeat-clicker tracking and time-to-report trends — numbers a CISO can put in front of an audit committee.
Numbers a CISO can take to the board
Resilience rate, click-rate trend, repeat-clicker cohorts and time-to-report — measured continuously and exportable for audit. Awareness stops being a compliance checkbox and becomes a security control with a graph behind it.
- Per-tenant SAML SSO and enforced MFA
- Hard tenant isolation, enforced at query time
- Hash-chained audit log, exportable by your admins
- Terms, privacy notice and a real DPA in the footer
No compliance badge appears on this site until one has been earned. The Trust page describes how the system actually behaves instead.
Start anywhere
Watch one phish become intelligence
Thirty minutes with your team: the lures currently landing in your sector, and the intelligence view your organisation would see on day one.