FAQ
Questions we're asked most
How does this impact employee privacy?+
Simulations measure aggregate behavior, not individual performance reviews. We never publish per-employee click data, and reports default to non-punitive coaching. You can configure roles so HR sees only summary statistics.
Can we customize the simulation content?+
Yes. Templates are tailored per industry and region — local banks, postal services, tax authorities, common SaaS vendors — and you can request fully custom scenarios for high-risk roles like finance or executives.
Is the platform available in local languages?+
We deliver simulations and training in Swedish, Estonian, Danish, and English at launch. Additional Nordic, Baltic, and EU languages are added on request — usually within a few weeks.
Where is data stored?+
Exclusively in EU/EEA data centers. No data leaves the EU. We use EU-based subprocessors only, and we publish our subprocessor list in the DPA.
How does this help with NIS2 compliance?+
NIS2 requires that essential and important entities provide cybersecurity training and demonstrate ongoing risk management. Our reports are formatted as audit evidence — campaign records, training completion, and risk trends over time — that you can attach directly to NIS2 documentation.
What does setup look like?+
We handle setup for you. Tell us your industry, team size, and who should receive the first simulated phish, and we'll have your first campaign running within a few business days. No software to install.
What does it cost?+
Pricing is per seat per month, with a flat setup fee. We share current pricing during the demo call so we can match it to your team size and use case.
Do you offer a Data Processing Agreement (DPA)?+
Yes. A standard EU-aligned DPA is available before signing and is mandatory for customers in regulated industries. Custom clauses are negotiable for enterprise contracts.