Skip to content

The platform

One platform for human risk

Simulate every channel attackers use, train the people who fail within seconds, and measure the whole programme with a single behavioural grade. No agents, no annual checkbox.

4
attack channels
10
score factors
1 day
to first campaign
SimulateDetectTrainMeasureONE LOOPBRSNo step waits for an administrator

One platform

Simulate, train and measure — on one loop

Four surfaces that feed each other. A failed simulation becomes a lesson, a finished lesson becomes a score, and the score decides who gets targeted next.

Step 1 of 4

Every channel an attacker will actually try

Attackers stopped limiting themselves to email years ago. SafeLoop runs the same playbook they do — spear-phishing, smishing, deepfake vishing and QR quishing — with lures generated per person from role, department and past behaviour.

  • AI-written lures, difficulty tiered 1–5
  • Pre-send inbox placement test before every campaign
  • Credential pages never capture what is typed
EmailSpear-phishing, BEC
SMSSmishing
VoiceVishing, deepfake
QRQuishing

Why it compounds

The loop is the product

Nothing in the cycle waits for an administrator to notice, which is why the second quarter is better than the first.

Mechanism

Four surfaces that feed each other

A failed simulation enrols a lesson. A completed lesson lowers targeting difficulty. A reported real threat raises the grade. Each signal changes what happens next without anyone scheduling it.

  • Failure to enrolment in seconds, not next cycle
  • Difficulty adapts per person, both directions
  • Reporting counted as resilience, not noise
BehavioralRisk ScoreSimulate — Multi-channel lure1SimulateDetect — Click, submit, report2DetectTrain — Auto-enrol on fail3TrainMeasure — Score + benchmark4Measure
  1. 1. Simulate Multi-channel lure
  2. 2. Detect Click, submit, report
  3. 3. Train Auto-enrol on fail
  4. 4. Measure Score + benchmark

The difference

Built to change behavior, not tick a box

Three ways organisations approach human risk, and what each one can actually tell you at the end of a quarter.

CapabilitySafeLoopGeneric phishing toolAnnual checkbox training
Continuous, adaptive simulationsDifficulty tiers per person, not one campaign for everyoneIncludedPartialNot included
Email, SMS, voice and QRSmishing, vishing and quishing, not email aloneIncludedNot includedNot included
Verified inbox placement before sendDedicated sending infrastructure plus a seed-group placement testIncludedNot includedNot included
Auto-enrolment the moment someone failsIncludedPartialNot included
Per-person behavioural scoreTen factors, A–F, from person to orgIncludedNot includedNot included
Industry benchmarkingIncludedPartialNot included
Never stores submitted credentialsIncludedPartial
Board report with written commentaryIncludedNot includedNot included
SCIM deprovisioning in the same syncIncludedPartialNot included
Evidence pack for HIPAA / PCI / ISOCertificates plus an immutable audit logIncludedNot includedPartial

Partial means the capability exists in some form but is manual, email-only, or priced as a separate module.

Integrations

Plugs into the stack you already run

Provision from your directory, deliver through your gateway, and pipe every event anywhere. No agents, no rip-and-replace, no CSV imports.

Microsoft 365Delivery + allow-list
Microsoft EntraSSO + provisioning
Google WorkspaceDelivery + allow-list
OktaSAML / OIDC / SCIM
SlackNudges + report
TeamsNudges + report
SCIMAuto (de)provisioning
LDAPOn-prem directory
MimecastSEG bypass rules
ProofpointSEG bypass rules
WebhooksEvery event, real time
REST APICampaigns + reporting

Directory sync runs every 15 minutes. Deprovisioning is immediate — when someone leaves your IdP, they leave SafeLoop in the same sync.

Trust & compliance

Audited ourselves, mapped for you

Two different things, kept apart: the certifications SafeLoop holds, and the control references your training evidence is tagged with.

SafeLoop is audited against

SOC 2Type II
ISO 27001Certified
ISO 27701Privacy
Cyber EssentialsPlus

Your training evidence is mapped to

  • NIST CSF 2.0PR.AT
  • HIPAA§164.308(a)(5)
  • PCI DSS v4.012.6.3
  • GDPRArt. 39
  • ISO 27001A.6.3
  • SOC 2CC2.2

See the platform on your own data

Book a demo and a specialist runs a live campaign against a test group, then walks through the grade it produces.

Twenty minutes. No installation and no procurement paperwork to get started.

See your human risk in 20 minutes

Book a demo and we’ll run a sample campaign against a test group.