Pricing
Priced per seat. Scaled to your program.
Start free, grow into a real adaptive program, and add governance when you need it. Annual billing saves 17%. Prices in USD; INR invoicing available for Indian entities — ask us.
Starter
For teams standing up their first program.
billed annually · up to 250 seats
- Email & SMS simulations
- AI template generator
- PhishNova Academy
- Monthly reports
Team
Everything you need to run a real, adaptive program.
billed annually · up to 2,500 seats
Everything in Starter, plus
- All 4 channels — adds voice & WhatsApp
- Autopilot programs & Threat Mirror
- Adaptive difficulty & Forensic coaching
- Department & manager analytics
Enterprise
Multi-tenant, governed, and integrated.
Custom volume pricing · unlimited seats
Everything in Team, plus
- SSO / SAML & multi-tenant orgs
- OSINT & Organization Risk Profile
- AI Security Companion & API
- Full audit log & approval queue
Compare plans
Every capability, side by side.
| Capability | Starter | Team | Enterprise |
|---|---|---|---|
| Simulations | |||
| Email simulations | |||
| SMS (smishing) simulations | |||
| Voice (vishing) simulations | |||
| WhatsApp simulations | |||
| AI template generator | |||
| Threat Mirror (6-hour refresh) | |||
| Autopilot programs | |||
| Coaching & training | |||
| PhishNova Academy | |||
| Forensic Moment coaching | |||
| Adaptive difficulty | |||
| Analytics & risk | |||
| Monthly reports | |||
| Department & manager analytics | |||
| Organization Risk Profile + OSINT | |||
| AI Security Companion | |||
| Governance & platform | |||
| Role-based access | Basic | Dept + manager | Full RBAC |
| SSO / SAML | |||
| Multi-tenant orgs | |||
| API access | |||
| Full audit log & approval queue | Approval queue | ||
| Support | Priority | Dedicated CSM | |
Need something bespoke? Talk to sales about Enterprise →
FAQ
Pricing & program questions.
Traditional tools ship a static template library and run a once-a-year test. PhishNova reads live threat intelligence every six hours and drafts simulations from the real attacks happening now, across email, SMS, voice, and WhatsApp — then coaches employees the instant they click. It is a continuous, adaptive program, not an annual checkbox.
No. PhishNova uses passive OSINT to map your external attack surface and flags email-authentication gaps (SPF/DKIM/DMARC). There is no agent to install and no scanning of your internal infrastructure.
Most teams are live in a day: connect your directory, run the passive recon, review the first Threat Mirror drafts, and launch. You reduce risk over the following quarters as the program adapts to each employee.
A seat is one employee enrolled in your program. Pricing scales by tier — Starter and Team are billed per seat with monthly or annual options (annual saves 17%), and Enterprise is custom volume pricing with unlimited seats.
Yes. Starter and Team can request a 14-day trial with no credit card — we provision your workspace within one business day. Enterprise buyers typically start with a 30-minute demo and a passive OSINT snapshot of their own attack surface.
PhishNova is built multi-tenant and org-scoped, and supports GDPR and India’s DPDP Act. A Data Processing Addendum is available, and Enterprise adds SSO/SAML, full audit logging, and an approval queue for governance. We do not yet hold a third-party certification such as SOC 2 — see our Security page for exactly where we stand and what we can share with your review team today.
Yes. Threat Mirror includes regional coverage — for example, India-specific scam patterns via the India Scam Radar — so simulations reflect the lures your employees actually receive.
No. Forensic Moment coaching is framed as a teachable moment: the click carries the employee straight into coaching that shows the specific red flags in the exact lure they fell for — not a scoreboard, and not an email to their manager.