Fallax
Fallax runs internal phishing simulations inside your own Google Workspace or Microsoft 365 tenant, trains people the moment they click, and turns the result into audit evidence.
Simulations are injected straight into mailboxes through your tenant, so there is no sending domain and nothing to allowlist: no SPF, DKIM or DMARC setup, no effect on email reputation. Anyone who clicks gets a short training page. Scheduling is per person and automatic, adjusted by how each one handled the last simulation, capped and paced by rules you set.
One export covers ISO 27001, SOC 2, NIS2, DORA, PCI DSS, HIPAA, GDPR Article 32 and NIST CSF, and syncs to Vanta, Drata, Secureframe and Sprinto.
Also included: phishing reports credited automatically from Outlook or a Gmail add-on, app discovery that aims lures at the tools staff really use, department standings, a REST API and an MCP server.
EU-hosted and GDPR compliant. Submitted credentials are never stored. First 10 seats free, permanently
Learn more
INFIMA
Smart organizations and MSPs (like you!) provide End User Security Awareness Training to their clients.
Easy, right?!
Except there's a problem: competing platforms load your team with tasks.
So we provide our Partners with a fully automated platform - sync new clients (Office 365 and Google Workspaces) and you're all set!
End the tasks.
Satisfy regulators and insurance requirements.
Make your program a success with automation that performs.
Partnership Counts:
Simple, straightforward pricing and Partnership cut your risks.
Get rid of the sticky, minimum seat contracts. Only pay for what you need.
Simple Onboarding:
Onboard new clients in minutes. (Yep - we know it's hard to believe.)
Learn more
HailBytes
HailBytes SAT is a self-hosted phishing simulation and Security Awareness Training platform for IT and security teams that want continuous user testing without per-seat licensing or sending employee data to a third-party SaaS. Continuous testing with targeted micro-training measurably reduces successful phishing attacks over time.
Key capabilities include unlimited campaigns, AI-assisted phishing templates, post-click training modules and quizzes, credential-capture landing pages, and user segmentation by department, risk tier, or cohort. Enterprise features include RBAC, MFA/TOTP, SSO/OIDC, SAML, SIEM export, and any SMTP provider supported.
Deploys from AWS or Azure Marketplace in under 30 minutes on a hardened image you control. Pricing starts at $0.24/vCPU/hour (roughly $4,200/year), typically 70 to 80% less than commercial alternatives. Includes a 30-day free trial. Your account, your data, no vendor lock-in.
Learn more
SafeInstinct
SafeInstinct is cybersecurity awareness training that turns security and privacy requirements into practical habits your team can use the same day. Instead of generic once-a-year courses, short 15-30 minute modules cover the threats employees actually face: phishing, business email compromise and payment fraud, data handling and classification, access and least privilege, and GDPR + CCPA readiness. New modules are added at no extra cost.
The Adaptive Risk-Based plan personalizes training automatically: a lightweight agent reports the apps each employee uses, and AI tailors their training path to that real risk profile, adapting as new signals appear. Admins can also generate custom trainings from a prompt to match internal policies.
An admin dashboard tracks assignments, due dates, completion and scores, with owner, admin and employee roles. Pricing is per user, billed annually, with all training modules included and per-user rates dropping as seats grow.
Learn more