Skip to content

Security

Security FAQ

Short answers for security reviews. Full pack: Security & privacy package.

Do you capture passwords in phishing simulations?
No. Simulations do not collect employee credentials.
Can we dry-run before live send?
Yes. Live send is off by default and should be enabled only after dry-run and approval.
Where is data stored?
Production is designed for Canada-oriented residency. See Privacy Policy and Subprocessors.
Are you SOC 2 or ISO certified?
Not yet. We publish readiness trackers and do not claim certificates we do not hold.
Who is controller of employee data?
You are. PhishGuard is the processor/service provider for simulation data under your pilot DPA.
How fast do you notify of a breach?
Without undue delay; pilot DPA targets ≤ 72 hours after confirmation for customer personal information.
How do subprocessors change?
Material additions are reviewed, emailed to active customers with a default 10 business day objection window, and listed on /subprocessors.
What happens to data at the end of a pilot?
Delete or return from primary systems within 30 days of end/request, subject to legal retention — see deletion runbook and DPA.