Phishing training on autopilot, that proves it ran.
Fallax delivers simulations inside your own Microsoft 365 or Google Workspace tenant, trains your people at the moment they click, and turns every test into audit-ready evidence.
- No DNS, no allowlisting
- First 10 seats free
- GDPR compliant, EU-hosted
As seen on
- Product Hunt
- Hacker News
- G2
Everything a phishing programme needs, nothing else
Five things have to work for a programme to survive a real company. The rest is a course library you'll never open.
- AmeliaMarcoJonas
Runs itself.
One schedule per person, tuned by their last result. 0
Sending domains. DNS records. Spam folders.
Delivery that can't miss.
- +11 moreSign in to OneDrivem.ricci@acme.io••••••••Next
Lures your people believe.
Borrowed from the apps your tenant reports in use. Security Awareness
Nice catch, Marco
That message was a phishing simulation from the security team at Acme, and you reported it instead of clicking it.
+140 points6 reports in a rowSee your standingEveryone who reports hears back.
A thank-you the moment they report, with the points and the streak they just earned.- ISO 27001
- SOC 2
- NIS2
- DORA
- PCI DSS
- HIPAA
- GDPR
awareness-evidence.csv1,326 people, timestampedVantaDrataSecureframeSprintoOne export. Every auditor.
Lure library
It shouldn't look like a test. It should look like Tuesday.
Every lure arrives built: the email, the page it opens, and the translations.
- Every lure has a matching sign-in clone
- Fork any of them, or paste your own HTML
- Ranked by the apps your tenant really uses
See how Fallax picks which brand to forge
Brand names and logos are their owners' trademarks, shown only to identify what these simulations imitate. Not affiliated with or endorsed by any of them.
How it works
From inbox to audit evidence
It lands, somebody falls for it, the lesson is served at the click, and the record files itself. Nobody starts any of it.
Action required: set up multi-factor authentication
What you set up, once
An afternoon, and then the loop above runs on its own.
Connect your workspace
One admin consent. No DNS, nothing to allowlist.
Let it read which apps you use
Optional and read-only. Your people's real apps go first.
Switch the programme on
It picks who, what and when, and keeps picking.
Audit day
“Show me that everyone was trained, and when.”
Every ISO 27001, SOC 2 and NIS2 audit asks it. Answering it usually costs somebody a week of screenshots.
- Delivered09:14
- Opened09:22
- Clicked09:23
- Trained09:23
Or never export it
It files itself into the compliance platform you already run.
Model Context Protocol
Bring your own assistant
Paste one URL into Claude or ChatGPT. The awareness section of the report drafts itself, from campaigns that actually ran.
Draft the awareness training section of our ISO 27001 report.
A.6.3 · draft
Over the last 12 months Acme Corp ran 9 phishing simulations reaching 1,248 of 1,326 staff (94%). Click rate fell from 31.2% to 9.8%. Everyone who clicked was shown awareness training at that moment, logged against their name with a timestamp.
Cited from 9 campaigns · Aug 2025 to Jul 2026
Free for your first 10 people
Then €1.00 a seat, falling as you grow. Every account gets the whole product.
- Billed annually, 20% below the monthly price.
- No seat minimum. No lock-in.
- Cancel whenever you like.
Under 100 people and facing a first SOC 2 or ISO 27001? Fallax for Startups makes it 50 free seats for 12 months.
What security teams ask first
The questions that come up in every security review, answered without the hedging.
Is it safe to run this against our own staff?
That is the only thing it is built for. Fallax sends only to recipients you upload, delivered inside your own tenant, and every link points at your own landing page. Treat it like any other internal security test: get sign-off from HR or your works council before the first campaign, and tell people afterwards that the programme exists.
Who has to run this month to month?
Nobody, which is the point. Switch the continuous programme on and every person gets their own schedule, with the cadence and difficulty set by how they handled the last one: frequent clickers are tested more often on easier lures, consistent reporters get the hardest ones less often. Each send lands at a random minute inside that person's working hours, and hard guardrails bound it: a monthly cap, a minimum gap between sends, and a pause that drops everything queued the moment you hit it.
Do you store the credentials people submit?
No. When someone submits a simulated login form, Fallax records that a submission occurred and the field names only, never the values typed into them. There is no code path that persists a submitted password, so there is nothing for us, or an attacker, to leak.
Will this damage our email reputation?
It can't. Fallax never sends simulations over the public email system, so there is no sending domain and no SPF/DKIM/DMARC to configure. Each simulation is injected straight into the target's mailbox through your own Microsoft 365 or Google Workspace tenant, so nothing ever touches the deliverability of the domain your real business mail depends on.
Which compliance frameworks does this produce evidence for?
Security awareness training is a control in nearly all of them, and they want the same artefact: a dated, per-person record that training happened. One Fallax export answers ISO 27001 A.6.3, SOC 2 CC1.4 and CC2.2, NIS2 Article 21(2)(g), DORA Article 13(6), PCI DSS 12.6.3.1, HIPAA §164.308(a)(5), GDPR Article 32 and NIST CSF PR.AT-01. Connect Vanta, Drata, Secureframe or Sprinto and Fallax files the same evidence for you, with a blocked or undelivered message never reported as completed training.
Is Fallax itself GDPR compliant?
Yes, and the paperwork is published rather than promised. Customer data is stored in the European Union, all 4 sub-processors are EU-hosted and named in Annex III of our data processing agreement, and the DPA is incorporated into the terms, so there is nothing to negotiate before you start. Submitted credential values are never written to storage, there is no advertising or ad-tech tracking anywhere, and the one optional cookie, product analytics, stays switched off until you accept it. Read the privacy notice and DPA in full from the footer.
Does it work with our identity provider?
Sign-in is Google Workspace and Microsoft Entra ID out of the box, so there is no extra password for your admins to manage and access follows your directory. Production deployments are SSO-only; the email and password form exists only for local development.
Find out who clicks. Before it counts.
Connect your workspace and switch the programme on this afternoon. The first 10 seats are free.
Every workspace includes
- Unlimited campaigns
- The continuous adaptive programme
- Unlimited admins and members
- Microsoft 365 & Google Workspace delivery
- Every template and landing page
- Training at the moment of the click
- Full evidence export, CSV and PDF
- Continuous sync to Vanta, Drata, Secureframe and Sprinto
- Slack and Teams notifications
- Google and Microsoft Entra SSO
- Complete event history
Evidence maps to 8 frameworks, including ISO 27001, SOC 2, NIS2, DORA, PCI DSS, HIPAA, GDPR.



































