Phishing simulation
Test people the way attackers actually test them
Most programmes send one email template to everybody once a quarter. SafeLoop generates a lure per person from role, department, tenure and prior behaviour, then delivers it over the channel that person is genuinely reachable on — including the staff who have no corporate mailbox.
- 4
- delivery channels
- 5
- difficulty tiers
- 0
- credentials stored
Coverage
Four channels in one campaign builder
Pick an audience and an objective. SafeLoop chooses the channel per person based on reachability and role exposure, so a depot driver gets an SMS and a finance controller gets a phone call — from the same campaign, scored on the same scale.
- Spear-phishing and business email compromise
- Smishing over SMS with regional short-code delivery
- Vishing with synthesised voice and a call script
- Quishing with QR codes sized for printed lures
Targeting
Difficulty that moves with the person
Tier one is an obvious mass-market scam. Tier five is a thread hijack referencing a real internal project name. People climb as they improve and drop back when they struggle, which keeps the programme teaching instead of just recording failures.
- Lures generated per person, not per campaign
- Role, department, tenure and prior-failure inputs
- Cool-down windows so nobody is tested twice in a week
How it works
The parts that decide whether a simulation is worth sending
Deliverability, safety and evidence — the three places programmes usually fall down.
Verified before it sends
Every campaign runs an inbox-placement test against a seed group first. If a rule is missing, you find out before 12,000 people don't receive it.
- Dedicated simulation mail infrastructure
- Per-tenant sending domains
Credentials are never captured
A submit is recorded as an event with a timestamp. The characters typed are discarded at the collector before anything is written to storage.
- Enforced in code, not policy
- Verified in third-party testing
Time-to-click, to the second
Median time to click is 21 seconds. Knowing which of your people are inside that window is more useful than knowing your average.
- Per-person click and submit latency
- Reported-in-under-a-minute cohort
Directory-driven, never a CSV
Audiences follow your IdP. Dynamic rules on any attribute mean a new joiner is in scope the day their account is created.
- SCIM with a 15-minute sync
- Department, site and manager scoping
A failure becomes a lesson
Anyone who clicks, submits or misses a report is enrolled in the matching module within seconds — no administrator in the loop.
- Matched to the failure type
- Completion written to the audit log
Campaigns over the API
Create audiences, launch campaigns and stream every event into your SIEM. The console is one client of the same API.
- REST + signed webhooks
- Idempotent event delivery
Specification
Channel detail
| Channel | Delivery | What it tests |
|---|---|---|
| Dedicated MTA, per-tenant domains, allow-list wizard | Spear-phishing, BEC, thread hijack, attachment lures | |
| SMS | Regional short code or long code, 40+ countries | Smishing, delivery-notification and payroll scams |
| Voice | Outbound call with synthesised speech and a branching script | Vishing, callback fraud, IT-helpdesk impersonation |
| QR | Printable and on-screen codes with per-person tokens | Quishing from posters, invoices and parking notices |
Every channel produces the same funnel and feeds the same Behavioral Risk Score, so results are comparable across a mixed workforce.
Questions
Asked on every first call
The ones that decide whether a first call turns into a second one.
3 questions
Will simulated phishing emails reach the inbox?
Yes. SafeLoop generates the exact allow-list configuration for Microsoft 365 Advanced Delivery, Google Workspace and your secure email gateway, then runs an inbox-placement test to a seed group before the campaign goes live. Simulations send from dedicated infrastructure rather than a shared transactional provider, whose terms forbid simulated phishing.
Do you store the passwords people type into a simulation?
Never. The submit is recorded as an event — who, which campaign, how long after delivery — and the person is coached immediately. The characters themselves are discarded at the collector before any write occurs.
How often should simulations run?
Monthly per person is the pattern that holds results. Quarterly campaigns produce a short-lived improvement that reverts within two quarters; weekly testing produces fatigue and complaints. SafeLoop paces per person with cool-down windows rather than sending to everyone on the same day.
Keep reading
Related
See a live campaign against your own test group
Twenty minutes, your people, real delivery. You keep the funnel and the provisional score.