Skip to content
PHISHNOVA
AI runs on a local model, inside your infrastructure

Train your people without handing over your people.

PhishNova’s AI runs on a local model inside your own environment, so employee names, roles and risk scores never reach a third-party cloud. Simulations across email, SMS, voice and WhatsApp — coaching the second they click.

Local AI by default · self-hostable · DPDP & ISO 27001 evidence trail

We’re early, and we’d rather show you the product than a wall of logos. Book a demo and we’ll run passive OSINT on your own domain — you’ll see exactly what we’d find before you decide anything.

The problem

Your team doesn’t click because they’re careless.

They click because last quarter’s template doesn’t look like this quarter’s attack. Static, once-a-year phishing tests train people for threats that have already moved on — and they leave you guessing where the real exposure is.

The PhishNova way

Simulate what’s happening now. Coach the moment it lands. Measure what changed.

  • Templates drawn from live threat intel, not a stale library.
  • A different lure for each employee — at a different minute.
  • One risk score, folded from internal signals and passive OSINT.

How it works

Live in a day. Reducing risk by the quarter.

01

Connect & map

Sync your directory and run passive OSINT. PhishNova maps your external attack surface and flags email-auth gaps — no scanning of your infrastructure.

02

Simulate & coach

Launch multi-channel simulations on autopilot. The moment someone clicks, coaching fires with the exact red flags they missed.

03

Measure & reduce

Watch culture score and coverage gaps move. Work the ranked action list — escalate the risky, coach the rest, prove the trend.

The console

One operations room for your whole program.

Campaigns, threat intel, domain health, and training — instrumented and scoped by org, department, and manager. What follows is the real interface, not a mock.

app.phishnova.com/threat-library
Threat Library catalogue showing corporate and consumer attack vectors by channel and severity

The canonical catalogue of attacks your org faces — templates and training link back here.

Real product screenshot — demo workspace, not a customer account

4
Channels simulated
email · sms · voice · whatsapp
6h
Threat library refresh
real attacks, mirrored
On click
Coaching delivered
no digest, no delay
1
Score to work from
internal signals + osint

Pricing

Priced per seat. Scaled to your program.

MonthlyAnnual · save 17%

Starter

For teams standing up their first program.

$5/ seat / mo

billed annually · up to 250 seats

  • Email & SMS simulations
  • AI template generator
  • PhishNova Academy
  • Monthly reports
Most popular

Team

Everything you need to run a real, adaptive program.

$8/ seat / mo

billed annually · up to 2,500 seats

Everything in Starter, plus

  • All 4 channels — adds voice & WhatsApp
  • Autopilot programs & Threat Mirror
  • Adaptive difficulty & Forensic coaching
  • Department & manager analytics

Enterprise

Multi-tenant, governed, and integrated.

Custom

Custom volume pricing · unlimited seats

Everything in Team, plus

  • SSO / SAML & multi-tenant orgs
  • OSINT & Organization Risk Profile
  • AI Security Companion & API
  • Full audit log & approval queue

Need the full breakdown? Compare every plan →

“An awareness program should be judged the way you judge any other control: does the risk go down, and can you prove it?”

That is the whole product thesis. We’re a young company and we don’t have a customer case study to hand you yet — so instead, come test the claim on your own attack surface and hold us to it.

FAQ

Questions, answered.

Traditional tools ship a static template library and run a once-a-year test. PhishNova reads live threat intelligence every six hours and drafts simulations from the real attacks happening now, across email, SMS, voice, and WhatsApp — then coaches employees the instant they click. It is a continuous, adaptive program, not an annual checkbox.

No. PhishNova uses passive OSINT to map your external attack surface and flags email-authentication gaps (SPF/DKIM/DMARC). There is no agent to install and no scanning of your internal infrastructure.

Most teams are live in a day: connect your directory, run the passive recon, review the first Threat Mirror drafts, and launch. You reduce risk over the following quarters as the program adapts to each employee.

A seat is one employee enrolled in your program. Pricing scales by tier — Starter and Team are billed per seat with monthly or annual options (annual saves 17%), and Enterprise is custom volume pricing with unlimited seats.

Yes. Starter and Team can request a 14-day trial with no credit card — we provision your workspace within one business day. Enterprise buyers typically start with a 30-minute demo and a passive OSINT snapshot of their own attack surface.

PhishNova is built multi-tenant and org-scoped, and supports GDPR and India’s DPDP Act. A Data Processing Addendum is available, and Enterprise adds SSO/SAML, full audit logging, and an approval queue for governance. We do not yet hold a third-party certification such as SOC 2 — see our Security page for exactly where we stand and what we can share with your review team today.

See PhishNova on your own attack surface.

Book a 30-minute demo. We’ll run passive OSINT on your domain and show you where you’re exposed — before you commit to anything.

No agent to install · Passive recon only · GDPR & DPDP aligned