Trust centre
Trust and security
Phished runs phishing simulations and security awareness training for organisations that trust us with employee data. This page sets out how we protect that data, which standards we are audited against, where AI is involved, and how to reach our security team.
Overview
At Phished, we're deeply committed to maintaining robust and comprehensive security measures. We believe that keeping our systems, and by extension your data, secure is of paramount importance. We don't just comply with the industry standard for data protection, we strive to exceed it.
This Security Page provides an overview of our stringent internal security program. It gives you an insight into our dedication to consistently uphold the highest levels of data security. On this page, you can request access to our audit reports and security policies for a detailed review.
If you have any questions about our security program, please review our Security Overview which is available below.
Company details
- Legal entity
- Phished BV
- Registered office
- Bondgenotenlaan 138, 3000 Leuven, Belgium
- Company registration number
- 0735.908.019
- Privacy contact
- [email protected]
Controls
How Phished secures its own organisation, its staff and the devices they work on.
Corporate Security
Control
Security awareness
Everyone at Phished follows continuous security awareness training and phishing simulations — the same programme the platform runs for our customers.
Incident Response
A documented process defines how a security incident is reported, triaged, escalated and closed, and who decides at each step.
Role-based access control
Access to internal systems is granted by role, on a need-to-know basis, and reviewed as part of the information security management system.
Recovery time objective
Service is restored within 4 hours of a major disruption.
Recovery point objective
A recovery loses at most 10 minutes of data.
Policies
Control
Information Security Policy
The approved policy that every other policy and control on this page follows. It is reviewed periodically and after any significant change.
Access Control Policy
How accounts are requested, approved, reviewed and revoked, and what is required before anyone is given access to production.
Asset Management Policy
How company assets and the data on them are recorded, classified, handled and handed back when someone leaves.
Endpoint Security
Control
Disk Encryption
Company devices encrypt their storage, so a lost or stolen laptop is not a disclosure of what was on it.
Endpoint Detection & Response
Detection and response software runs on company devices, watching for threats and containing them without waiting for someone to notice.
Mobile Device Management
Company devices are enrolled in device management, which enforces the security baseline — encryption, screen lock, updates — and can wipe a device remotely.
Security
Control
Industry-grade encryption (in transit and at rest)
Your data is encrypted in transit and at rest.
Audit logging
Administrator actions in the platform are recorded, and the log is yours to read.
SSO (SAMLv2) compatible
Your people sign in through your own identity provider over SAML 2.0.
Audit events stream to your SIEM (Splunk, Datadog or an HTTPS webhook)
Audit events can be streamed to Splunk, Datadog or an HTTPS endpoint of your own, so the platform's activity lands in the tooling you already watch.
Infrastructure
Control
Google Cloud Platform
The platform runs on Google Cloud Platform.
Validated disaster recovery plan
The disaster recovery plan is documented and tested rather than assumed.
Enterprise-grade Web Application Firewall (WAF)
A web application firewall filters traffic before it reaches the platform.
Data residency: the European Union (Belgium) or the United States, fixed per organisation
Your organisation's data stays in the region set for it — the European Union (Belgium) or the United States — rather than moving with load.
Live service status and incident history
Live service status and the history of past incidents, published as they happen.
Access control
Control
Role-based access control
What an administrator can see and do is set by their role, not by who set the account up.
Multi-factor authentication
Administrators can be required to confirm a sign-in with a second factor.
Password security
Password requirements apply to every account, and passwords are never stored in a readable form.
SCIM provisioning and deprovisioning from Microsoft Entra ID
Accounts are created, updated and removed automatically from Microsoft Entra ID, so a leaver loses access without anyone remembering to remove them.
Legal
Control
Cyber insurance
Phished carries cyber insurance covering security incidents, including the cost of responding to one.
Data Processing Agreement
The agreement that governs our processing of the personal data you put into the platform: what we may do with it, on whose instructions, and what happens to it at the end of the contract.
Privacy policy
What personal data Phished collects, why we process it, and how long we keep it.
Cookie policy
Which cookies our websites set, what each one is for, and how to refuse them.
Sub-processors
Everyone who processes personal data on our behalf, taken from Annex 2 of the data processing agreement.
| Sub-processor | Primary data centre | What it does | Data protection contact |
|---|---|---|---|
| Google Cloud EMEA Ltd | EEA (Belgium), with failover | Cloud infrastructure for the platform as a whole. Primary processing is in Belgium. Regional failover can move processing to another Google Cloud region inside the EEA. | Visit |
| Cloudflare, Inc. | Global anycast network | Edge protection for the platform: DDoS mitigation, web application firewall and content delivery. Cloudflare operates a global anycast network. Traffic is inspected at the Cloudflare location closest to the user. Any processing outside the EEA is covered by Cloudflare's certification under the EU-U.S. Data Privacy Framework and, as a fallback, the EU Standard Contractual Clauses (Module Three) as incorporated in the Cloudflare Data Processing Addendum. | Visit |
| Microsoft Ireland Operations Ltd | EEA (France) | The processing of emails that get sent to Phished.io (our own domains) and for ZIM customers, who use the Microsoft 365 integration to defend their mailboxes. | Visit |
| Mailgun (Mailjet SAS) | EEA (Germany) | Delivering simulations, report replies and Academy mail. | Visit |
| Zendesk Inc. | EEA (Ireland) | Handling customer support requests. | Visit |
| Intercom R&D Unlimited Company | EEA (Ireland) | The AI support chat inside the platform, which only administrators can open. | Visit |
| Urlscan GmbH | EEA (Germany) | Analysing URLs found in reported mail. Optional, and can be switched off. | Visit |
Every sub-processor that stores your data keeps its primary data centre inside the European Economic Area.
AI
Where Phished uses AI, what each feature processes, and what stays under human control.
Several parts of Phished use generative AI to draft content: simulations, training material, translations, and the replies your administrators send to people who report a suspicious email. AI drafts, people decide. Nothing an AI feature produces reaches your people without an administrator's approval.
Where AI is used
| Feature | What it produces | What it processes | What triggers it |
|---|---|---|---|
| Simulation generation | Builds a profile of your organisation and drafts phishing pretexts from it. | Your organisation name and publicly available information about it. | An administrator creating a simulation. |
| Training content generation | Drafts levels, sessions, articles, questions and images. | The brief an administrator writes, or the policy document they upload. | An administrator generating content. |
| Translation | Translates content your administrators author into the languages your people read. | The content your administrators authored. | An administrator requesting a translation. |
| Reported email analysis | Summarises what is suspicious about a reported email and drafts the reply to the reporter. | The subject, body and headers of the reported email, which can contain personal data. | An administrator opening or answering a report. |
| Template copy | Drafts copy for report buttons, activation emails and protection guidance. | The template an administrator is editing, and your organisation name. | An administrator asking for a draft. |
Data handling
Model training
Human oversight
Governance
Platform security
Model providers and subprocessors
Customer controls
Change management
Questions this section does not answer
If your questionnaire asks something this section does not answer, write to [email protected]. We answer AI questions in the same way we answer the rest: in writing, and specific to what the platform actually does.
Disclosure
If you think you may have discovered a vulnerability, please send us a note
Send what you found to [email protected]. We acknowledge every report and will tell you what we did with it.
Responsible Disclosure Policy
At Phished we take the security and privacy of our users and customers seriously. We believe that collaboration with the security research community is crucial in identifying and addressing potential vulnerabilities in our systems and applications. We encourage responsible disclosure of any security issue discovered, and appreciate the assistance of security researchers in maintaining a secure environment for everyone.
If you have discovered a potential security vulnerability in an asset that belongs to Phished, we kindly ask that you adhere to the following guidelines.
- Responsible disclosure
- Make every effort to avoid any actions that could negatively impact our systems, users or customers. Only conduct testing within the boundaries of your own account, and do not access, modify or view data that does not belong to you.
- Report privately
- Submit your findings to our security team as soon as possible, at [email protected]. We recommend using encryption when communicating sensitive information.
- Provide detailed information
- Include all relevant details to help us understand and reproduce the issue: steps to replicate the problem, proof-of-concept code, and any other supporting material.
- Confidentiality
- We respect the privacy and security of security researchers. We will not share any personal information without explicit permission unless required by law. We also ask that you do not disclose any details about the vulnerability until it has been resolved and we have given you permission to do so.
- Response time
- Our security team will make every effort to acknowledge receipt of your report promptly, and will work diligently to investigate and address the issue. We aim to provide regular updates on the progress of resolving the vulnerability, and will work with you to verify and validate the fix.
- Public disclosure
- We appreciate researchers' patience while we investigate and resolve any reported vulnerability, and we ask that you refrain from disclosing it to the public.
- Legal conduct
- We encourage responsible and ethical behaviour in accordance with the law. If you discover a vulnerability, please refrain from taking advantage of it for any reason, including unauthorised access, data exfiltration or disruption of service. Engaging in such activities is strictly prohibited and may result in legal action.
- Recognition
- We recognise and appreciate the valuable contribution of security researchers who help us improve our security posture. Depending on the severity and impact of the reported vulnerability, we may offer public recognition in our hall of fame to express our gratitude. We reserve the right to determine eligibility for, and the nature of, any recognition or reward.
By submitting a security vulnerability report to Phished, you agree to abide by the guidelines set out in this policy.
What to include in a report
- What is the proof of concept? Document it with screenshots or a screen recording, or note every step in as much detail as possible.
- In what way can the vulnerability be exploited by malicious parties, and what does that require? Be specific rather than generic.
- What is the impact?
- Which account did you test with?
- What is the exact endpoint you tested against?
- What is your concrete proposal to address the vulnerability?
Out of scope
- Clickjacking on pages with no sensitive or authenticated actions.
- Software version disclosure and banner identification issues.
- Missing email best practices: invalid, incomplete or missing SPF, DKIM or DMARC records.
- Missing best practices in SSL/TLS configuration.
- Open redirects, unless an additional security impact can be demonstrated.
- Cross-site request forgery on unauthenticated forms, or forms with no sensitive actions.
- Anything related to HTTP security headers: Strict-Transport-Security, X-Frame-Options, X-XSS-Protection, X-Content-Type-Options, Content-Security-Policy.
- Older versions of any software reported without a proof of concept or working exploit.
We value your commitment to keeping our systems and users safe. Thank you for your cooperation in helping us maintain a secure environment for everyone.
Phished BV — [email protected] · Version 1.2
Compliance
Select a standard to read what it covers and to download or request the evidence.
Evidence and questionnaires
Our completed Cloud Controls Matrix questionnaire, published in the CSA STAR registry. It answers most of a vendor questionnaire on its own.
Released under NDA. The request form takes a minute and we come back to you directly.
Certifications and audits
Examined by a third party, who issued a certificate or a report with a date on it.
Regulations and frameworks
Regulations we are required to follow and frameworks we measure ourselves against. None of these is certified by anybody, so none of them carries a certification mark here.