Skip to content
New · Voice & QR simulations plus the mail add-in

Your people, your strongest defense

SafeLoop runs AI-adaptive phishing simulations across email, SMS, voice and QR, trains whoever fails within seconds, and rolls the whole programme into one A–F Behavioral Risk Score.

Verified inbox placement SSO, SCIM & SAML SOC 2 Type II & ISO 27001

Live baseline campaign on day one — no agents to deploy, no CSV to upload.

EmailSMSVoiceQRB84 / 100BRS

Trusted by security teams at 1,200+ organizations

0%
of breaches involve the human element
Verizon DBIR 2024
0%
drop in phish-prone rate over 12 months of continuous training
KnowBe4 2026 benchmark · 33.2% → 4.2%
<0s
median time for a person to click and then submit credentials
Verizon DBIR 2024 · 21s + 28s
A–F
Behavioral Risk Score for every person, team and org
Benchmarked against your industry

Behavioral Risk Score

One grade, and the arithmetic behind it

Ten named factors across susceptibility, resilience and exposure, resolved into a single A–F grade per person, team, department and organisation — benchmarked against your industry.

B84/100
Org grade · up from D two quarters ago
Phish-prone
4.2%
Report rate
61%
Percentile
88th
A90–100Resilient
B80–89Solid
C70–79Uneven
D60–69Exposed
F≤59Critical
01

Susceptibility

What people fall for

32/40
  • Susceptibility rate10
  • Credential-submit rate8
  • Repeat-clicker rate8
  • Time-to-click6
02

Resilience

What they do about it

22/30
  • Report rate9
  • Real-threat response7
  • Training completion6
03

Exposure

Surface their role carries

17/30
  • Multi-channel exposure7
  • Department risk5
  • Tenure / onboarding risk5
Ten factors, each weighted out of ten. Count the cells — the grade is arithmetic you can check, not a length you have to trust.

It grades resilience, not risk

Higher always means better. Competitor scales run higher-is-riskier, which reads backwards the moment a letter is attached to it.

Bands absorb noise

A percentage invites an argument about a two-point move that means nothing. A band moves when behaviour moves.

Every grade drills to an event

A department's C resolves to the people, campaigns and timestamps behind it. Nothing about the number is a black box.

One platform

Simulate, train and measure — on one loop

Four surfaces that feed each other. A failed simulation becomes a lesson, a finished lesson becomes a score, and the score decides who gets targeted next.

Step 1 of 4

Every channel an attacker will actually try

Attackers stopped limiting themselves to email years ago. SafeLoop runs the same playbook they do — spear-phishing, smishing, deepfake vishing and QR quishing — with lures generated per person from role, department and past behaviour.

  • AI-written lures, difficulty tiered 1–5
  • Pre-send inbox placement test before every campaign
  • Credential pages never capture what is typed
EmailSpear-phishing, BEC
SMSSmishing
VoiceVishing, deepfake
QRQuishing

How it works

Live in a day. Improving in a week.

No agents to deploy and no lists to wrangle. Connect your directory and SafeLoop runs the loop.

1

Connect & baseline

Provision from Entra, Okta or Google over SSO and SCIM, generate your allow-list rules, then run one honest baseline campaign.

Day one

2

Simulate & train

SafeLoop picks the channel, lure and difficulty per person, and enrols anyone who fails into a three-minute lesson.

Continuous

3

Measure & report

Watch the grade climb, compare against your industry percentile, and export the board pack with commentary written.

First report in 30 days

Customers

Security teams prove it moved

From one-in-three clicking to near-zero. Every number came out of the platform.

Northwind Health

Healthcare · 12,000 people

31% → 4%phish-prone rate in two quarters
A regional health system with a mobile, shift-based workforce. Baseline put one in three staff at risk. Adaptive multi-channel campaigns plus same-shift microlearning closed the gap, and the HIPAA evidence pack now exports in a click.
Globex Financial

Financial services · 4,200 people

6.4×increase in phishing report rate
Wire-fraud lures and synthesised-voice vishing aimed at treasury and the exec team. Within a quarter, staff stopped ignoring suspicious mail and started reporting it in seconds — turning the workforce into a live detection layer for the SOC.
Initech

Technology · 1,800 people

D → ABehavioral Risk Score, every department
SCIM-provisioned from Okta in an afternoon. Auto-enrolment did the work no awareness lead had time for: every department moved up at least one grade across three quarters, each step reported to the board.

In their words

What security teams say after two quarters

We cut our phish-prone rate from 31% to under 5% in two quarters. For the first time the board could see human risk move, and move in the right direction.
Northwind HealthHead of Security AwarenessNorthwind Health · 12,000 people
The voice simulations were the moment it landed. Our finance team had never been tested on a phone call before, and the first result was uncomfortable — which is exactly the point.
Globex FinancialCISOGlobex Financial · 4,200 people
I stopped maintaining spreadsheets of who needed training. Someone clicks, they get the lesson, the score updates. My job went back to being security work.
InitechSecurity Awareness LeadInitech · 1,800 people

Identity & provisioning

Connects to the directory you already trust

SSO in minutes, SCIM provisioning that keeps itself current, and an offboarding that takes effect in the same sync your IdP runs. No endpoint agent, and no CSV anybody has to remember to upload.

  • Microsoft EntraSAML · OIDC · SCIM
  • OktaSAML · OIDC · SCIM
  • Google WorkspaceSSO · directory sync
  • LDAPOn-prem AD sync
  • SCIMSCIM 2.0 provisioning
  • Microsoft 365Delivery · allow-list

What we read

  • Name and work email
  • Mobile number (only if SMS or voice is in scope)
  • Department, manager, location

What we write back

  • Nothing to your directory
  • Group membership is never modified
  • No mail-flow rule that copies traffic

What we never see

  • Mailbox contents
  • Credentials typed into a simulation
  • Anything a person has not chosen to report
~20 minSSO and SCIM connected on a sandbox tenant
15 minDirectory sync interval
ImmediateDeprovision on SCIM delete or disable
ZeroAgents installed on laptops or phones

Trust & compliance

Audited ourselves, mapped for you

Two different things, kept apart: the certifications SafeLoop holds, and the control references your training evidence is tagged with.

SafeLoop is audited against

SOC 2Type II
ISO 27001Certified
ISO 27701Privacy
Cyber EssentialsPlus

Your training evidence is mapped to

  • NIST CSF 2.0PR.AT
  • HIPAA§164.308(a)(5)
  • PCI DSS v4.012.6.3
  • GDPRArt. 39
  • ISO 27001A.6.3
  • SOC 2CC2.2

Questions

Asked on every first call

Four questions that come up before anything else. Twenty more, grouped, on the contact page.

4 questions

What is human risk management?

Managing the likelihood that a person's action causes a security incident, as a measured and reducible risk rather than an annual awareness campaign. The distinguishing feature is a behavioural metric that changes over time — in SafeLoop, an A–F Behavioral Risk Score built from ten named factors.

How is this different from annual security awareness training?

Annual training measures attendance. SafeLoop tests people continuously across four channels, enrols whoever fails into a matched three-minute lesson within seconds, and reports a graded trend benchmarked against comparable organisations.

Will simulated phishing emails actually reach the inbox?

Yes. SafeLoop generates the exact allow-list configuration for Microsoft 365 Advanced Delivery, Google Workspace and your secure email gateway, then runs an inbox-placement test to a seed group before every campaign goes live.

How quickly can we go live?

A baseline campaign typically runs on day one. SCIM provisions people without a CSV, the allow-list wizard produces the exact rules for your mail platform, and there is no endpoint agent to deploy.

See your human risk in 20 minutes

Book a demo and we’ll run a sample campaign against a test group.