What we never do
No real password capture. Dry-run before live send. Tenant isolation. Admin audit trail.
You are evaluating a tool that will touch employee mailboxes and behaviour data. Here is what to expect — plain language for security and privacy stakeholders.
No real password capture. Dry-run before live send. Tenant isolation. Admin audit trail.
Canada-oriented residency design. Subprocessors published. Architecture shared for reviews.
You remain controller/custodian. We are processor under contract — purpose-limited, with breach notice and deletion.
SOC 2 / ISO readiness trackers — never certificates we do not hold. Full security package on request.
If you are a public body, you remain the custodian under provincial privacy law. PhishGuard acts as your service provider: purpose-limited use, safeguards, breach notice, and deletion at end of relationship. Commercial customers: PIPEDA-aligned practices. Québec: Law 25 addressed in onboarding.
Full detail: Privacy Policy · Subprocessors
We track readiness against Chiaro (SOC 2 control library), ISO 27001:2022, and ISO 27701. We never claim a report or certificate we do not hold.
The public demo uses sample data — no Google Workspace connection. A paid pilot connects your tenant under agreement, with seat count and success criteria you choose. See Terms · Pilot offer.