Skip to content
Fallax

Phishing training on autopilot, that proves it ran.

Fallax delivers simulations inside your own Microsoft 365 or Google Workspace tenant, trains your people at the moment they click, and turns every test into audit-ready evidence.

  • No DNS, no allowlisting
  • First 10 seats free
  • GDPR compliant, EU-hosted

As seen on

  • Reddit
  • Product Hunt
  • Hacker News
  • G2

Everything a phishing programme needs, nothing else

Five things have to work for a programme to survive a real company. The rest is a course library you'll never open.

  • Runs itself.

    One schedule per person, tuned by their last result.
  • 0

    Sending domains. DNS records. Spam folders.

    Delivery that can't miss.

  • Lures your people believe.

    Borrowed from the apps your tenant reports in use.
  • Everyone who reports hears back.

    A thank-you the moment they report, with the points and the streak they just earned.
    • ISO 27001
    • SOC 2
    • NIS2
    • DORA
    • PCI DSS
    • HIPAA
    • GDPR
    awareness-evidence.csv
    1,326 people, timestamped
    VantaDrataSecureframeSprinto

    One export. Every auditor.

Lure library

It shouldn't look like a test. It should look like Tuesday.

Every lure arrives built: the email, the page it opens, and the translations.

Microsoftmicrosoft.comMicrosoft account unusual sign-in activity
Googlegoogle.comMarco Rossi shared a document with you
DocuSigndocusign.netPlease DocuSign: Invoice INV-48210
ADPadp.comAction required: verify your direct deposit
Workdaymyworkday.comOpen Enrollment is now available in Workday
Oktaokta.comAction required: set up multi-factor authentication
Dropboxdropbox.comAmelia Vermeulen shared "Q3 Forecast & Headcount.xlsx" with you
Slackslack.comYou've been added to the Acme Slack
Zoomzoom.usCloud recording: Quarterly Business Review is available
Salesforcesalesforce.comAction required: your Salesforce password expires today
LinkedInlinkedin.comMarco Rossi would like to connect on LinkedIn
GitHubgithub.com[GitHub] A new sign-in to your account
Adobeadobesign.comPlease review and sign: Master Services Agreement 2026
Atlassianatlassian.netMarco Rossi mentioned you on 'Q3 Planning'
Boxbox.comJonas Peeters shared "Q3 Planning.xlsx" with you on Box
QuickBooksintuit.comInvoice 48210 from Meridian Goods is due today
ServiceNowservice-now.comApproval requested: REQ0048210 (VPN access)
Mimecastmimecast.com[Mimecast] You have 3 held messages
1Password1password.comA vault item was shared with you
Auth0auth0.comSecurity alert: a new administrator was added to your Auth0 tenant
OneLoginonelogin.comRe-authentication required for your OneLogin portal
JumpCloudjumpcloud.comYour JumpCloud password expires soon
Notionnotion.soMarco Rossi mentioned you in Q3 Planning
Proofpointproofpoint.com[Proofpoint] End User Digest: 3 messages in quarantine
Duo Securityduosecurity.comEnrol your new device in Duo
Ping Identitypingidentity.comApproval required: new application access in PingOne
LastPasslastpass.comNew device signed in to your LastPass vault
Bitwardenbitwarden.comNew device logged in to your Bitwarden account
Dashlanedashlane.comConfirm your new device to access your vault
Cloudflarecloudflare.comYour Cloudflare Access login code
Yubicoyubico.comRegister your YubiKey to keep account access
Ripplingrippling.comA new app is ready for you in Rippling
Zohozoho.comYour Zoho Mail storage is almost full
Barracudabarracuda.com[Barracuda] You have 3 messages in quarantine
Amazonamazon.comAmazon: we noticed unusual sign-in activity
Microsoft Azureazure.microsoft.comAction needed: your Azure subscription payment failed
  • Every lure has a matching sign-in clone
  • Fork any of them, or paste your own HTML
  • Ranked by the apps your tenant really uses

See how Fallax picks which brand to forge

Brand names and logos are their owners' trademarks, shown only to identify what these simulations imitate. Not affiliated with or endorsed by any of them.

How it works

From inbox to audit evidence

It lands, somebody falls for it, the lesson is served at the click, and the record files itself. Nobody starts any of it.

What you set up, once

An afternoon, and then the loop above runs on its own.

  1. Connect your workspace

    One admin consent. No DNS, nothing to allowlist.

  2. Let it read which apps you use

    Optional and read-only. Your people's real apps go first.

  3. Switch the programme on

    It picks who, what and when, and keeps picking.

See how the programme picks who gets what

Audit day

“Show me that everyone was trained, and when.”

Every ISO 27001, SOC 2 and NIS2 audit asks it. Answering it usually costs somebody a week of screenshots.

Okta luremarco.rossi@acme.com
  1. Delivered09:14
  2. Opened09:22
  3. Clicked09:23
  4. Trained09:23
awareness-evidence.csv
One timestamped row per action

Export it

One file answers all 8 frameworks, clause by clause.

See each clause

Or never export it

It files itself into the compliance platform you already run.

Model Context Protocol

Bring your own assistant

Paste one URL into Claude or ChatGPT. The awareness section of the report drafts itself, from campaigns that actually ran.

Works withClaudeChatGPTAny MCP client

Free for your first 10 people

Then €1.00 a seat, falling as you grow. Every account gets the whole product.

€40/month
€480 a year · €0.80 per seat
  • Billed annually, 20% below the monthly price.
  • No seat minimum. No lock-in.
  • Cancel whenever you like.

Under 100 people and facing a first SOC 2 or ISO 27001? Fallax for Startups makes it 50 free seats for 12 months.

What security teams ask first

The questions that come up in every security review, answered without the hedging.

Is it safe to run this against our own staff?

That is the only thing it is built for. Fallax sends only to recipients you upload, delivered inside your own tenant, and every link points at your own landing page. Treat it like any other internal security test: get sign-off from HR or your works council before the first campaign, and tell people afterwards that the programme exists.

Who has to run this month to month?

Nobody, which is the point. Switch the continuous programme on and every person gets their own schedule, with the cadence and difficulty set by how they handled the last one: frequent clickers are tested more often on easier lures, consistent reporters get the hardest ones less often. Each send lands at a random minute inside that person's working hours, and hard guardrails bound it: a monthly cap, a minimum gap between sends, and a pause that drops everything queued the moment you hit it.

Do you store the credentials people submit?

No. When someone submits a simulated login form, Fallax records that a submission occurred and the field names only, never the values typed into them. There is no code path that persists a submitted password, so there is nothing for us, or an attacker, to leak.

Will this damage our email reputation?

It can't. Fallax never sends simulations over the public email system, so there is no sending domain and no SPF/DKIM/DMARC to configure. Each simulation is injected straight into the target's mailbox through your own Microsoft 365 or Google Workspace tenant, so nothing ever touches the deliverability of the domain your real business mail depends on.

Which compliance frameworks does this produce evidence for?

Security awareness training is a control in nearly all of them, and they want the same artefact: a dated, per-person record that training happened. One Fallax export answers ISO 27001 A.6.3, SOC 2 CC1.4 and CC2.2, NIS2 Article 21(2)(g), DORA Article 13(6), PCI DSS 12.6.3.1, HIPAA §164.308(a)(5), GDPR Article 32 and NIST CSF PR.AT-01. Connect Vanta, Drata, Secureframe or Sprinto and Fallax files the same evidence for you, with a blocked or undelivered message never reported as completed training.

Is Fallax itself GDPR compliant?

Yes, and the paperwork is published rather than promised. Customer data is stored in the European Union, all 4 sub-processors are EU-hosted and named in Annex III of our data processing agreement, and the DPA is incorporated into the terms, so there is nothing to negotiate before you start. Submitted credential values are never written to storage, there is no advertising or ad-tech tracking anywhere, and the one optional cookie, product analytics, stays switched off until you accept it. Read the privacy notice and DPA in full from the footer.

Does it work with our identity provider?

Sign-in is Google Workspace and Microsoft Entra ID out of the box, so there is no extra password for your admins to manage and access follows your directory. Production deployments are SSO-only; the email and password form exists only for local development.

Find out who clicks. Before it counts.

Connect your workspace and switch the programme on this afternoon. The first 10 seats are free.

Every workspace includes

  • Unlimited campaigns
  • The continuous adaptive programme
  • Unlimited admins and members
  • Microsoft 365 & Google Workspace delivery
  • Every template and landing page
  • Training at the moment of the click
  • Full evidence export, CSV and PDF
  • Continuous sync to Vanta, Drata, Secureframe and Sprinto
  • Slack and Teams notifications
  • Google and Microsoft Entra SSO
  • Complete event history

Evidence maps to 8 frameworks, including ISO 27001, SOC 2, NIS2, DORA, PCI DSS, HIPAA, GDPR.