Pricing
Priced per seat, shaped to your programme
Every tier includes the simulation engine, the training platform and the Report add-in. One published rate per seat whatever your tier — Enterprise scope is quoted.
Seat calculator
Monthly
$250.00$290.00 incl. 16% VATAnnual
Save 20%100 seats × $2.50 per seat / month. The annual column is $2.00 per seat / month on a twelve-month commitment, billed monthly. Figures are VAT-exclusive; the secondary line applies VAT at 16%. Indicative only — not a quotation.
Start measuring and improving phishing resilience.
- Phishing simulations & campaign analytics
- Department Level Reporting
- Training courses & quizzes
- Outlook / Gmail report button
- Email support
Add the intelligence layer that makes awareness targeted.
- Everything in Essentials
- Threat intelligence & technology watches
- Breach & leak monitoring for your domains
- Analyst Threat Inbox
- Priority support
Instant setup · pay by card or M-Pesa
Up to 25 seats online
For regulated organizations with security review requirements.
- Everything in Professional
- SAML SSO & enforced MFA policy
- Audit log exports & API access
- Dedicated onboarding & success
- Vulnerability Assessment and Penetration Testing
No surprises
What the rate already includes
One published figure per seat. The things a comparison usually finds hidden behind a tier are in all of them.
- The simulation engine
- Courses, quizzes and completion tracking
- The Outlook and Gmail Report add-in
- Per-department resilience reporting
- Billed monthly in advance
- An annual commitment buys the rate, not a different invoice
- One honest seats × rate line on the document
- Card or M-Pesa for self-serve
- Per-tenant SAML SSO and enforced MFA
- Audit log export and org-scoped API keys
- A security review we expect to pass
- Dedicated onboarding
Before you ask
What your security review will want
You are choosing a custodian for how your people respond to attack. The documents that govern that are linked here rather than buried, and they say what is true today.
Seraph Cyber is a Kenyan company and the platform is operated from Nairobi. Some sub-processors sit outside Kenya; they are named in the Privacy Notice, and transfers rely on the safeguards in section 49 of the Data Protection Act.
Privacy Notice and sub-processorsA Data Processing Addendum is published in full, not held back for negotiation. It covers instructions, confidentiality, breach notice, sub-processors, audit and deletion — and we answer a security questionnaire once a year at no charge.
Read the DPAYour data is exportable throughout, including while an account is suspended for non-payment. Erasing a staff member anonymises their records after a 30-day grace period; invoices and the tax records attached to them are kept because the law requires it.
Trust & security in fullThe other lane
Some organisations should start with an assessment instead
A per-seat subscription is the right shape when you know you want a running programme. If the question is still where are we exposed, an assessment answers that first and usually decides the programme afterwards.