Audience
Security, IT and compliance teams at companies on Google Workspace or Microsoft 365 that need a phishing simulation programme and audit evidence for ISO 27001, SOC 2, NIS2, DORA, PCI DSS or HIPAA. From ten-person startups to enterprises, with named coverage for healthcare, financial services, fintech, insurance, law firms, SaaS, agencies and schools. MSPs run a workspace per client on one bill.
About Fallax
Fallax runs internal phishing simulations inside your own Google Workspace or Microsoft 365 tenant, trains people the moment they click, and turns the result into audit evidence.
Simulations are injected straight into mailboxes through your tenant, so there is no sending domain and nothing to allowlist: no SPF, DKIM or DMARC setup, no effect on email reputation. Anyone who clicks gets a short training page. Scheduling is per person and automatic, adjusted by how each one handled the last simulation, capped and paced by rules you set.
One export covers ISO 27001, SOC 2, NIS2, DORA, PCI DSS, HIPAA, GDPR Article 32 and NIST CSF, and syncs to Vanta, Drata, Secureframe and Sprinto.
Also included: phishing reports credited automatically from Outlook or a Gmail add-on, app discovery that aims lures at the tools staff really use, department standings, a REST API and an MCP server.
EU-hosted and GDPR compliant. Submitted credentials are never stored. First 10 seats free, permanently