About SafeLoop
People are the perimeter. We defend it
Two in three breaches involve a person, and most organisations answer that with one course a year. SafeLoop exists to make human risk measurable, adaptive and genuinely respectful of the people being measured.
Why we exist
The industry measured attendance and called it awareness
Every founder here had the same experience from a different chair: reporting a training-completion percentage to somebody who wanted to know whether anyone was actually safer.
The thesis
If you can't grade it, you can't reduce it
Human risk behaves like any other risk: it responds to measurement, targeting and feedback. What it does not respond to is an annual course, a poster campaign or a stern all-staff email. So we built the loop first and the content second.
- Measure resilience, not attendance
- Target the people who fail, not everybody
- Never use fear as a teaching tool
- 1. Simulate Multi-channel lure
- 2. Detect Click, submit, report
- 3. Train Auto-enrol on fail
- 4. Measure Score + benchmark
The evidence
We publish the shape, not just the headline
Most vendors publish a curve that goes down. Fewer publish where it stops going down, or what happens to the cohort the curve leaves behind. Our benchmark reports both, including the ninety-day plateau that makes programmes look finished when they are not.
- 4.6 million simulations across 1,200 organisations
- One report year cited, never spliced across years
- Third-party figures attributed inline
History
How we got here
- 2023
The measurement problem
Founded by a security awareness lead and two platform engineers who were tired of reporting training completion to a board that wanted to know whether anyone was safer.
- 2024
The score
First release of the Behavioral Risk Score: ten factors, one A–F grade, computed at person, team and org level and benchmarked against industry peers.
- 2025
Beyond email
Smishing, vishing and quishing shipped with a dedicated sending infrastructure, because deliverability turned out to be the hard part nobody advertised.
- 2026
1,200 organisations
Multi-tenant white-label for MSPs, EU and UK data residency, and the Outlook and Gmail add-in that puts reporting one click from the inbox.
What we believe
Four principles we build on
Not values on a wall — each one has cost us a feature we wanted to ship.
Measure, don't guess
Everything ties back to one score with visible working. We refused to ship a risk number we could not decompose into named factors, which delayed the first release by a quarter.
Train the right people
Blanket annual training wastes the time of the 90% who did nothing wrong and fails to reach the 10% who did. Auto-enrolment on failure is the default and cannot be turned into a mass assignment.
Show the working
Every percentage on this site resolves to the events behind it. A score somebody cannot drill into is a score they will eventually stop believing, and rightly.
Earn the access we ask for
We ask for your directory and your mail flow. In return: two independent isolation layers, credentials never stored, and an audit log we cannot quietly edit.
What we won't build
Four features we have turned down
Being specific about this is more useful than a values statement, and it is the part security and HR reviewers ask about.
No public shaming
No leaderboard of failures, no feature that publishes an individual's results to their colleagues, no export designed to name people in a group chat. We have declined this request more than once and lost at least one deal over it.
No credential capture
A simulated login page records the event and discards the characters at the collector. Storing them would make the product more 'realistic' and would create a liability nobody asked us for.
No distress lures
Redundancy notices, pay changes, medical results and bereavement pretexts are all excluded from the library and blocked in the authoring tool. They work, and the damage outlasts the lesson.
No silent data reuse
Customer event data is not used to train models for other customers. Benchmarks are aggregated and k-anonymised before any comparison leaves a tenant.
How we build
The engineering decisions behind the product
Relevant because they are the reason certain guarantees on this site are possible at all.
| Decision | Why | What it buys you |
|---|---|---|
| Tenant scope below the query builder | Passing an org id as an argument is a bug waiting to happen | A forgotten filter cannot leak another customer's data |
| Postgres row-level security as a second layer | Application correctness should not be the only control | A bug in the app does not become a breach |
| Dedicated simulation mail infrastructure | Shared providers prohibit simulated phishing in their terms | Campaigns that cannot be suspended mid-programme |
| Credentials discarded at the collector | Nothing downstream can leak what was never written | A guarantee that survives a penetration test |
| Append-only audit log | Evidence a vendor can edit is not evidence | An artefact your auditor accepts |
| Region selected per tenant | Residency is a procurement blocker, not a feature | EU, UK or US processing including backups |
The trust centre documents these controls in the form a security questionnaire expects.
How we work
Remote-first, written-down, small teams
Useful to know whether you are buying from us, partnering with us or writing to us.
UK, EU and US
Registered in London, EU processing in Dublin, and a team spread across three regions with four hours of daily overlap.
Decisions in documents
Architecture and product decisions are written down with the reasoning attached. It is why the pages on this site can be specific.
We are in the programme
Everyone here receives simulations, including tier-five ones. Engineers fail them occasionally, which is the point.
See what the loop does to a phish-prone rate
Twenty minutes, a live campaign against a test group you nominate, and the grade it produces — yours whether or not you buy anything.