Security
Security FAQ
Short answers for security reviews. Full pack: Security & privacy package.
- Do you capture passwords in phishing simulations?
- No. Simulations do not collect employee credentials.
- Can we dry-run before live send?
- Yes. Live send is off by default and should be enabled only after dry-run and approval.
- Where is data stored?
- Production is designed for Canada-oriented residency. See Privacy Policy and Subprocessors.
- Are you SOC 2 or ISO certified?
- Not yet. We publish readiness trackers and do not claim certificates we do not hold.
- Who is controller of employee data?
- You are. PhishGuard is the processor/service provider for simulation data under your pilot DPA.
- How fast do you notify of a breach?
- Without undue delay; pilot DPA targets ≤ 72 hours after confirmation for customer personal information.
- How do subprocessors change?
- Material additions are reviewed, emailed to active customers with a default 10 business day objection window, and listed on /subprocessors.
- What happens to data at the end of a pilot?
- Delete or return from primary systems within 30 days of end/request, subject to legal retention — see deletion runbook and DPA.