The platform
One system from first phish to measured resilience.
Six capabilities that feed each other. Bought separately they would be six tools that do not talk; the point of them being one platform is that a report becomes an indicator becomes a simulation becomes a training assignment without anyone moving a spreadsheet between them.
Phishing simulations
Realistic, safe campaigns by department and risk profile — click, open, attachment and credential-submission tracking with per-team resilience scoring.
- Campaigns are scheduled or recurring, scoped to groups that can be static or maintained by rule.
- Tracking covers opens, link clicks, attachment opens, simulated macro enablement and credential submission — and submitted values are discarded, only the event is recorded.
- Resilience is scored per team so a result is comparable between quarters rather than a single number for the whole organisation.
Targeted training & LMS
Courses and quizzes assigned from simulation outcomes, not a calendar. Completion and comprehension tracked to the individual.
- Assignment rules turn an outcome into a course, so the person who clicked gets the lesson about what they clicked.
- Quizzes record comprehension rather than attendance, and certificates are verifiable by a third party with only a certificate number.
- Repeat-clickers are surfaced as a cohort, because the same handful of people are usually most of the risk.
Threat intelligence
A living catalogue of vulnerabilities, CISA known-exploited flags and profiled threat actors — matched to the technologies your organisation actually runs.
- Technology watches narrow the catalogue to what you have deployed, so an advisory is about your estate rather than the internet.
- Known-exploited flags come from CISA, and actors are mapped to MITRE ATT&CK techniques and tooling.
- The dashboard distinguishes "nothing observed" from "nothing collected" — on a tile both read as zero and they mean opposite things.
Breach & leak monitoring
Your domains watched across breach and infostealer corpora. Exposed staff surface as alerts and an auto-maintained training group.
- Exposure becomes an alert and a training assignment in the same step, rather than a spreadsheet somebody has to act on.
- Recovered credential values are read only to set an exposure flag and are never written to our systems — only field names survive ingestion.
- Your security team is welcome to walk that redaction boundary with us in the code.
One-click phishing reporting
Outlook and Gmail add-ins put a Report button in every mailbox. Reports land in an analyst Threat Inbox, attributed to your organisation.
- The add-in is sideloaded once and needs nothing from the person using it beyond one click.
- Reports are triaged in a queue with notes and a blocklist, and feed the regional intelligence picture.
- What your people catch is what makes the next simulation realistic — that is the loop closing.
Enterprise readiness
Per-tenant SAML SSO, enforced MFA, org-scoped API keys, full audit logging and hard tenant isolation. Built to pass your security review.
- SAML assertions must be signed by your registered certificate, replay is rejected, and session tokens never travel in URLs.
- The audit log is hash-chained, so altering or deleting a record breaks every hash after it.
- Every record is scoped to its organisation, with a guard layer enforcing that scope on database queries at runtime.
Every statement in capability 06 describes something the platform does today, and each one is checkable — which is why they live in code on this site rather than in the content system where they could be edited as marketing copy. The Trust page sets them out in the detail a reviewer wants, and no compliance badge appears anywhere on this site until one has been earned.
If your security team wants to go deeper than a page can go — the redaction boundary on breach data, the tenant-scoping guard, the audit chain — we would rather walk it with you than describe it.
All six capabilities are in every tier. The rate is published per seat and you can model your own spend without talking to anyone.
If you would rather someone ran the first cycle with you — baseline, scope, hand over — that is an engagement rather than a subscription.