Early access: 20% off your first 12 months

Phishing simulation and security awareness training that runs itself

Turn the HUMAN VECTOR into your strongest defense.

Connect your directory and your phishing sims run themselves: a baseline for everyone, AI-drafted templates tuned to each person, training the moment someone slips, and a warning to your team when a real attack starts to spread.

30 days for your whole company. You start in Preview Mode, so nothing reaches your people until you say go. Nothing to allowlist with Inbox: Direct Injection. Cancel in two clicks.

AI DrivenScheduled
Next simulationTuesday 9:12 AM, randomized across the morning
128 people
DifficultyAdaptive per person; repeat clickers get harder templates
Auto
RemediationAssigned on the click, reminders until done
On
Reported emailAI verdict in seconds; alerts when an attack spreads
Watching
Baseline phish-prone rate
33%
Roughly a third of employees click a phishing email before any training. That is the vector we close.
The problem

Most breaches start with a PERSON, not a firewall.

People are the attack surface. Add the awareness layer that shores up the right vector, the human vector, and your weakest link becomes something you can measure and improve: simulations that surface the risk, training that closes it, and posture you can prove to leadership or a client.

AI Driven

A program that runs itself, and gets sharper every month

Start with a baseline to everyone. From there the AI Driven program takes over: it drafts realistic templates, matches each person's difficulty to how they actually perform, rotates so nothing gets memorized, and assigns the right training the moment someone slips. When your people report a real phish, it can turn that email into a safe training facsimile, so next month's simulation looks like what attackers are really sending. Set it once and it keeps the pressure on for you.

It also keeps watch on what your people report.

  • Every reported email gets a verdict in seconds: Safe, Unsafe or Unsure, with the reason.
  • The queue sorts itself so the risky ones are on top.
  • Our AI spots an attack spreading through your company and alerts your team.
  • It labels. Your team decides. AI can make mistakes, so a person confirms each assessment before acting, and it never touches a mailbox on its own.
Reported bySubjectAI
amy@acme.testUpdate your direct deposit before FridayUnsafe
cal@acme.testQuick favorUnsure
ben@acme.testCompleted: Vendor agreementSafe
Security alert
Attack spreading

Our AI flagged this email as an attack spreading through your company. It reached 12 of 40 mailboxes.

SubjectUpdate your direct deposit before Friday
Frompayroll@acme-hr-portal.com
AI assessmentUnsafe
Reach12 of 40 mailboxes
Review the Threat

The alert your team gets, with the reach counted across your mailboxes once you grant access. The AI assessment is a starting point: a person on your team confirms it.

Prove it

One number your board, your insurer and your client all understand.

The posture score blends three things that matter: who avoids the attack, who finishes training, and who reports. It moves month by month, and everything behind it is a click away.

Security posture · 6 months Risk: low
84
blended awareness score, trending up
REPORT

Board PDF

The client report as one page: score, trend, key rates, program facts and signed policies. Download it, or let the monthly email carry it.

EVIDENCE

Insurance evidence pack

Simulations run, people covered, training completed and policies signed, in the shape an underwriter asks for.

POLICIES

Read, signed, versioned

Publish a policy, every person signs by name, and a changed text asks everyone again. Reminders go out on their own.

BENCHMARK

Against the 33% baseline

Every rate sits next to the industry number, so a 9% phish-prone rate reads as what it is.

API

Your program, from your own tools

Everything you do in the console you can do from code. Create a key, give it only the permissions it needs, and connect your PSA, your reporting, your scripts, or an AI assistant.

  • Scoped API keys. Create them in the console, each limited to what it may read or change, and revoke any key in one click.
  • People, campaigns and results. Sync the directory, launch and schedule simulations, and pull opens, clicks, submissions and reports.
  • Webhooks. Get an event the moment someone clicks, reports or finishes training.
  • Built for MSPs. Create and manage client organizations across your whole book from one key.
  • A full OpenAPI specification. Load it into your API tools, or point an AI assistant at it.

Part of the Pro plan.

The mission

Four pillars...without compromise

01 / STABLE

It just works

On schedule, every time. Every email tracked in real time. No silent failures. A real person when you need one. Reliable, by design.

02 / EFFECTIVE

Training that sticks

A click instantly brings up interactive training, with knowledge checks and a certificate of completion.

03 / AUTOMATED

Set it and forget it

Simulations, reminders, and remediation run on their own, all year. New employees enrolled the moment they appear in the directory.

04 / VIGILANT

Attacks seen early

AI drafts the templates, tunes the difficulty to each person, reads what your people report, and alerts your team when an attack is spreading. It labels; your people decide.

How it works

Stand up a program in a few short minutes.

01 — Connect

Directory and tools

Link your Microsoft 365 or Google directory (or a client's). Turn on Inbox: Direct Injection and simulations land straight in the mailbox, with nothing to add to your allowlist or spam filter. Minutes, not a project.

02 — Simulate

Realistic, AI Driven

Topic-matched phishing simulations run on a schedule you set once, rotating so nobody memorizes them.

03 — Train

The people who click

A click launches interactive remediation for that person automatically, with reminders until it's done.

04 — Report

Report it. Remove it.

A report button right in the inbox sends suspicious mail straight to you. Our AI reads each one and labels it Safe, Unsafe or Unsure with the reason, so your queue sorts itself. Confirm a real phish and pull it from every mailbox in one click.

For MSPs

Every client, one console, your brand.

Onboard clients in bulk, launch once across all of them, bill a line per client, and run the whole program under your own name.

ONBOARD

Clients in bulk

Paste a list or upload a CSV.

LAUNCH

One send, many clients

Each gets its own results.

BRAND

White label on Pro

Your name, never ours.

BILL

A line per client

Seats each client uses.

Get started

Be early. Be ahead.

If awareness has been the tool you can't quite trust, let's fix that together. Try it free for 30 days across your whole company, in Preview Mode until you say go, and sign up during early access for 20% off your first 12 months. Or talk to us about volume or contract pricing.