Your people, your strongest defense
SafeLoop runs AI-adaptive phishing simulations across email, SMS, voice and QR, trains whoever fails within seconds, and rolls the whole programme into one A–F Behavioral Risk Score.
Live baseline campaign on day one — no agents to deploy, no CSV to upload.
Trusted by security teams at 1,200+ organizations
- Northwind Health
- Contoso Retail
- Globex Financial
- Initech
- Umbrella Logistics
- Soylent Foods
The platform
Six products, one loop
Simulation produces evidence, evidence triggers training, training changes behaviour, and behaviour re-targets the next simulation.
Behavioral Risk Score
One grade, and the arithmetic behind it
Ten named factors across susceptibility, resilience and exposure, resolved into a single A–F grade per person, team, department and organisation — benchmarked against your industry.
- Phish-prone
- 4.2%
- Report rate
- 61%
- Percentile
- 88th
Susceptibility
What people fall for
32/40- Susceptibility rate10
- Credential-submit rate8
- Repeat-clicker rate8
- Time-to-click6
Resilience
What they do about it
22/30- Report rate9
- Real-threat response7
- Training completion6
Exposure
Surface their role carries
17/30- Multi-channel exposure7
- Department risk5
- Tenure / onboarding risk5
It grades resilience, not risk
Higher always means better. Competitor scales run higher-is-riskier, which reads backwards the moment a letter is attached to it.
Bands absorb noise
A percentage invites an argument about a two-point move that means nothing. A band moves when behaviour moves.
Every grade drills to an event
A department's C resolves to the people, campaigns and timestamps behind it. Nothing about the number is a black box.
One platform
Simulate, train and measure — on one loop
Four surfaces that feed each other. A failed simulation becomes a lesson, a finished lesson becomes a score, and the score decides who gets targeted next.
Step 1 of 4
Every channel an attacker will actually try
Attackers stopped limiting themselves to email years ago. SafeLoop runs the same playbook they do — spear-phishing, smishing, deepfake vishing and QR quishing — with lures generated per person from role, department and past behaviour.
- AI-written lures, difficulty tiered 1–5
- Pre-send inbox placement test before every campaign
- Credential pages never capture what is typed
How it works
Live in a day. Improving in a week.
No agents to deploy and no lists to wrangle. Connect your directory and SafeLoop runs the loop.
Connect & baseline
Provision from Entra, Okta or Google over SSO and SCIM, generate your allow-list rules, then run one honest baseline campaign.
Simulate & train
SafeLoop picks the channel, lure and difficulty per person, and enrols anyone who fails into a three-minute lesson.
Measure & report
Watch the grade climb, compare against your industry percentile, and export the board pack with commentary written.
Customers
Security teams prove it moved
From one-in-three clicking to near-zero. Every number came out of the platform.
In their words
What security teams say after two quarters
We cut our phish-prone rate from 31% to under 5% in two quarters. For the first time the board could see human risk move, and move in the right direction.
The voice simulations were the moment it landed. Our finance team had never been tested on a phone call before, and the first result was uncomfortable — which is exactly the point.
I stopped maintaining spreadsheets of who needed training. Someone clicks, they get the lesson, the score updates. My job went back to being security work.
Identity & provisioning
Connects to the directory you already trust
SSO in minutes, SCIM provisioning that keeps itself current, and an offboarding that takes effect in the same sync your IdP runs. No endpoint agent, and no CSV anybody has to remember to upload.
- Microsoft EntraSAML · OIDC · SCIM
- OktaSAML · OIDC · SCIM
- Google WorkspaceSSO · directory sync
- LDAPOn-prem AD sync
- SCIMSCIM 2.0 provisioning
- Microsoft 365Delivery · allow-list
What we read
- Name and work email
- Mobile number (only if SMS or voice is in scope)
- Department, manager, location
What we write back
- Nothing to your directory
- Group membership is never modified
- No mail-flow rule that copies traffic
What we never see
- Mailbox contents
- Credentials typed into a simulation
- Anything a person has not chosen to report
Trust & compliance
Audited ourselves, mapped for you
Two different things, kept apart: the certifications SafeLoop holds, and the control references your training evidence is tagged with.
SafeLoop is audited against
Your training evidence is mapped to
- NIST CSF 2.0PR.AT
- HIPAA§164.308(a)(5)
- PCI DSS v4.012.6.3
- GDPRArt. 39
- ISO 27001A.6.3
- SOC 2CC2.2
Questions
Asked on every first call
Four questions that come up before anything else. Twenty more, grouped, on the contact page.
4 questions
What is human risk management?
Managing the likelihood that a person's action causes a security incident, as a measured and reducible risk rather than an annual awareness campaign. The distinguishing feature is a behavioural metric that changes over time — in SafeLoop, an A–F Behavioral Risk Score built from ten named factors.
How is this different from annual security awareness training?
Annual training measures attendance. SafeLoop tests people continuously across four channels, enrols whoever fails into a matched three-minute lesson within seconds, and reports a graded trend benchmarked against comparable organisations.
Will simulated phishing emails actually reach the inbox?
Yes. SafeLoop generates the exact allow-list configuration for Microsoft 365 Advanced Delivery, Google Workspace and your secure email gateway, then runs an inbox-placement test to a seed group before every campaign goes live.
How quickly can we go live?
A baseline campaign typically runs on day one. SCIM provisions people without a CSV, the allow-list wizard produces the exact rules for your mail platform, and there is no endpoint agent to deploy.