Skip to content

About SafeLoop

People are the perimeter. We defend it

Two in three breaches involve a person, and most organisations answer that with one course a year. SafeLoop exists to make human risk measurable, adaptive and genuinely respectful of the people being measured.

SimulateDetectTrainMeasureONE LOOPBRSNo step waits for an administrator
0+
organisations run their programme on SafeLoop
As of Q2 2026
0.0M
simulations delivered across four channels
Lifetime to date
0
data residency regions — EU, UK and US
Selected per tenant
68%
of breaches involve a person, which is the whole reason we exist
Verizon DBIR 2024

Why we exist

The industry measured attendance and called it awareness

Every founder here had the same experience from a different chair: reporting a training-completion percentage to somebody who wanted to know whether anyone was actually safer.

The thesis

If you can't grade it, you can't reduce it

Human risk behaves like any other risk: it responds to measurement, targeting and feedback. What it does not respond to is an annual course, a poster campaign or a stern all-staff email. So we built the loop first and the content second.

  • Measure resilience, not attendance
  • Target the people who fail, not everybody
  • Never use fear as a teaching tool
BehavioralRisk ScoreSimulate — Multi-channel lure1SimulateDetect — Click, submit, report2DetectTrain — Auto-enrol on fail3TrainMeasure — Score + benchmark4Measure
  1. 1. Simulate Multi-channel lure
  2. 2. Detect Click, submit, report
  3. 3. Train Auto-enrol on fail
  4. 4. Measure Score + benchmark

The evidence

We publish the shape, not just the headline

Most vendors publish a curve that goes down. Fewer publish where it stops going down, or what happens to the cohort the curve leaves behind. Our benchmark reports both, including the ninety-day plateau that makes programmes look finished when they are not.

  • 4.6 million simulations across 1,200 organisations
  • One report year cited, never spliced across years
  • Third-party figures attributed inline
0%10%20%30%40%Baseline: 33.2% phish-prone33.2%Baseline90 days: 20.1% phish-prone20.1%90 days12 months: 4.2% phish-prone4.2%12 months−87%
Phish-prone rate over 12 months of continuous simulation and training. Source: KnowBe4 2026 Phishing by Industry benchmark (33.2% → 20.1% → 4.2%).

History

How we got here

  1. 2023

    The measurement problem

    Founded by a security awareness lead and two platform engineers who were tired of reporting training completion to a board that wanted to know whether anyone was safer.

  2. 2024

    The score

    First release of the Behavioral Risk Score: ten factors, one A–F grade, computed at person, team and org level and benchmarked against industry peers.

  3. 2025

    Beyond email

    Smishing, vishing and quishing shipped with a dedicated sending infrastructure, because deliverability turned out to be the hard part nobody advertised.

  4. 2026

    1,200 organisations

    Multi-tenant white-label for MSPs, EU and UK data residency, and the Outlook and Gmail add-in that puts reporting one click from the inbox.

What we believe

Four principles we build on

Not values on a wall — each one has cost us a feature we wanted to ship.

Measure, don't guess

Everything ties back to one score with visible working. We refused to ship a risk number we could not decompose into named factors, which delayed the first release by a quarter.

Train the right people

Blanket annual training wastes the time of the 90% who did nothing wrong and fails to reach the 10% who did. Auto-enrolment on failure is the default and cannot be turned into a mass assignment.

Show the working

Every percentage on this site resolves to the events behind it. A score somebody cannot drill into is a score they will eventually stop believing, and rightly.

Earn the access we ask for

We ask for your directory and your mail flow. In return: two independent isolation layers, credentials never stored, and an audit log we cannot quietly edit.

What we won't build

Four features we have turned down

Being specific about this is more useful than a values statement, and it is the part security and HR reviewers ask about.

No public shaming

No leaderboard of failures, no feature that publishes an individual's results to their colleagues, no export designed to name people in a group chat. We have declined this request more than once and lost at least one deal over it.

No credential capture

A simulated login page records the event and discards the characters at the collector. Storing them would make the product more 'realistic' and would create a liability nobody asked us for.

No distress lures

Redundancy notices, pay changes, medical results and bereavement pretexts are all excluded from the library and blocked in the authoring tool. They work, and the damage outlasts the lesson.

No silent data reuse

Customer event data is not used to train models for other customers. Benchmarks are aggregated and k-anonymised before any comparison leaves a tenant.

How we build

The engineering decisions behind the product

Relevant because they are the reason certain guarantees on this site are possible at all.

DecisionWhyWhat it buys you
Tenant scope below the query builderPassing an org id as an argument is a bug waiting to happenA forgotten filter cannot leak another customer's data
Postgres row-level security as a second layerApplication correctness should not be the only controlA bug in the app does not become a breach
Dedicated simulation mail infrastructureShared providers prohibit simulated phishing in their termsCampaigns that cannot be suspended mid-programme
Credentials discarded at the collectorNothing downstream can leak what was never writtenA guarantee that survives a penetration test
Append-only audit logEvidence a vendor can edit is not evidenceAn artefact your auditor accepts
Region selected per tenantResidency is a procurement blocker, not a featureEU, UK or US processing including backups

The trust centre documents these controls in the form a security questionnaire expects.

How we work

Remote-first, written-down, small teams

Useful to know whether you are buying from us, partnering with us or writing to us.

UK, EU and US

Registered in London, EU processing in Dublin, and a team spread across three regions with four hours of daily overlap.

Decisions in documents

Architecture and product decisions are written down with the reasoning attached. It is why the pages on this site can be specific.

We are in the programme

Everyone here receives simulations, including tier-five ones. Engineers fail them occasionally, which is the point.

See what the loop does to a phish-prone rate

Twenty minutes, a live campaign against a test group you nominate, and the grade it produces — yours whether or not you buy anything.

See your human risk in 20 minutes

Book a demo and we’ll run a sample campaign against a test group.