A security awareness program should not become a security risk. This page sets out how we protect your organization's data, who helps us run the service, and where we stand on compliance. If a question is not answered here, ask us and we will answer it.
Each of these is how the product works now, not a plan.
Simulations, training and the Report phishing button need no access to anyone's mailbox. We read your directory to know who to train, and nothing more.
Mailbox access is opt-in. You grant it only to place simulations straight into inboxes or to remove a confirmed phishing email, and we use it only for that.
Every console account must use two-factor sign-in. There is no way to skip it.
Single sign-on with Microsoft or Google is available, and your organization can require it. Passwords are at least 12 characters.
A console session signs out after 30 minutes without activity and 12 hours after sign-in, however active. Signing out in one tab signs out the others.
All traffic uses TLS. The database is encrypted at rest with AES-256, including its replicas and backups.
Backups run continuously, so the database can be restored to a point in time.
Owner, admin and viewer roles control who can change what. Important actions, such as consent, campaign launches, training assignments and deletions, are written to an audit log the application never changes or deletes, even when an organization is removed.
API keys are limited to the permissions you choose, shown once, and can be revoked at any time.
Each organization's data is kept apart in the database and in the application. Our sales and support staff have no access to customer organization data.
When someone types into a simulated sign-in page, we never store what they typed. We record only that it happened, so they can be offered training.
Our AI features run on Anthropic's commercial service, which does not train its models on customer content. We do not either.
AI verdicts on reported emails are advisory. A person on your team makes the call.
Card payments go straight to Stripe. Your card number never reaches our servers.
These are the companies that process customer data on our behalf. All of them are in the United States.
| Company | What it does for us | Location |
|---|---|---|
| Render | Hosts the application and the database that holds customer data. | US (Oregon) |
| Vultr | Hosts the mail server we run to send simulation emails. | US (Atlanta, Georgia) |
| Resend | Sends account emails, such as invitations, notifications and scheduled reports. It does not send simulations. | US |
| Anthropic | Runs the AI features: the console assistant, drafting templates, and assessing reported emails. | US |
| Stripe | Takes card payments and manages subscriptions. It holds billing details, never your people's data. | US |
Your own Microsoft 365 or Google Workspace is your system, not our subprocessor. We act in it only with the permissions you grant. We will give notice before adding or changing a subprocessor.
We are a young company. We would rather tell you exactly what we have than imply more.
Ask and we will send any of these. Several are also part of the agreement you sign with us.