Train your people without handing over your people.
PhishNova’s AI runs on a local model inside your own environment, so employee names, roles and risk scores never reach a third-party cloud. Simulations across email, SMS, voice and WhatsApp — coaching the second they click.
Local AI by default · self-hostable · DPDP & ISO 27001 evidence trail
We’re early, and we’d rather show you the product than a wall of logos. Book a demo and we’ll run passive OSINT on your own domain — you’ll see exactly what we’d find before you decide anything.
The problem
Your team doesn’t click because they’re careless.
They click because last quarter’s template doesn’t look like this quarter’s attack. Static, once-a-year phishing tests train people for threats that have already moved on — and they leave you guessing where the real exposure is.
The PhishNova way
Simulate what’s happening now. Coach the moment it lands. Measure what changed.
- Templates drawn from live threat intel, not a stale library.
- A different lure for each employee — at a different minute.
- One risk score, folded from internal signals and passive OSINT.
Platform
Everything you need to run security awareness like ops.
Six capabilities that turn a once-a-year checkbox into a live, adaptive program.
Multi-channel simulations
Email, SMS, voice, and WhatsApp lures from one console, running on autopilot. AI tailors each to role, department, and tone — no manual HTML.
4 CHANNELS · AUTOPILOTThreat Mirror
Reads live threat intel and scam news every six hours, then drafts simulations from real, current attacks — queued for one-click approval.
REFRESH · 6HAdaptive difficulty
Every employee earns a behavioral score. Risky users get harder spear-phishing; the rest get more coaching. The program tunes itself.
+2 / −4 SCORINGForensic Moment coaching
The instant someone clicks, they see the red flags they missed — drawn from the exact lure. A teachable moment, not a gotcha.
ON THE CLICKOrganization Risk Profile
Internal signals and passive OSINT fold into one risk score with a ranked, do-this-next action list. Stop guessing where to spend time.
ONE SCOREAI Security Companion
Knows your live campaigns, employees, and risk. Ask it anything; act on what it says.
ASK ANYTHINGHow it works
Live in a day. Reducing risk by the quarter.
Connect & map
Sync your directory and run passive OSINT. PhishNova maps your external attack surface and flags email-auth gaps — no scanning of your infrastructure.
Simulate & coach
Launch multi-channel simulations on autopilot. The moment someone clicks, coaching fires with the exact red flags they missed.
Measure & reduce
Watch culture score and coverage gaps move. Work the ranked action list — escalate the risky, coach the rest, prove the trend.
The console
One operations room for your whole program.
Campaigns, threat intel, domain health, and training — instrumented and scoped by org, department, and manager. What follows is the real interface, not a mock.

The canonical catalogue of attacks your org faces — templates and training link back here.
Real product screenshot — demo workspace, not a customer account
Pricing
Priced per seat. Scaled to your program.
Starter
For teams standing up their first program.
billed annually · up to 250 seats
- Email & SMS simulations
- AI template generator
- PhishNova Academy
- Monthly reports
Team
Everything you need to run a real, adaptive program.
billed annually · up to 2,500 seats
Everything in Starter, plus
- All 4 channels — adds voice & WhatsApp
- Autopilot programs & Threat Mirror
- Adaptive difficulty & Forensic coaching
- Department & manager analytics
Enterprise
Multi-tenant, governed, and integrated.
Custom volume pricing · unlimited seats
Everything in Team, plus
- SSO / SAML & multi-tenant orgs
- OSINT & Organization Risk Profile
- AI Security Companion & API
- Full audit log & approval queue
Need the full breakdown? Compare every plan →
“An awareness program should be judged the way you judge any other control: does the risk go down, and can you prove it?”
That is the whole product thesis. We’re a young company and we don’t have a customer case study to hand you yet — so instead, come test the claim on your own attack surface and hold us to it.
FAQ
Questions, answered.
Traditional tools ship a static template library and run a once-a-year test. PhishNova reads live threat intelligence every six hours and drafts simulations from the real attacks happening now, across email, SMS, voice, and WhatsApp — then coaches employees the instant they click. It is a continuous, adaptive program, not an annual checkbox.
No. PhishNova uses passive OSINT to map your external attack surface and flags email-authentication gaps (SPF/DKIM/DMARC). There is no agent to install and no scanning of your internal infrastructure.
Most teams are live in a day: connect your directory, run the passive recon, review the first Threat Mirror drafts, and launch. You reduce risk over the following quarters as the program adapts to each employee.
A seat is one employee enrolled in your program. Pricing scales by tier — Starter and Team are billed per seat with monthly or annual options (annual saves 17%), and Enterprise is custom volume pricing with unlimited seats.
Yes. Starter and Team can request a 14-day trial with no credit card — we provision your workspace within one business day. Enterprise buyers typically start with a 30-minute demo and a passive OSINT snapshot of their own attack surface.
PhishNova is built multi-tenant and org-scoped, and supports GDPR and India’s DPDP Act. A Data Processing Addendum is available, and Enterprise adds SSO/SAML, full audit logging, and an approval queue for governance. We do not yet hold a third-party certification such as SOC 2 — see our Security page for exactly where we stand and what we can share with your review team today.
See PhishNova on your own attack surface.
Book a 30-minute demo. We’ll run passive OSINT on your domain and show you where you’re exposed — before you commit to anything.
No agent to install · Passive recon only · GDPR & DPDP aligned
