Privacy-first AI
Your employees’ risk data never leaves your walls.
Every AI-powered awareness platform asks you to send it the most sensitive people-data you hold — who is most susceptible, what they clicked, what department they sit in. PhishNova’s AI runs on a local model inside your own infrastructure, so you do not have to.
Local model by default · switchable to cloud · self-hostable via Docker
How it works
Four things that are true because of where the model runs.
Not a policy promise — an architecture. Each of these is a property of how the platform is built, which is why it holds whether or not you trust us.
The model runs where you put it
PhishNova’s AI provider defaults to a local model served by Ollama inside your own environment. Generating a lure, drafting a coaching page, answering a question about your own risk data — none of it requires an outbound call to a model vendor.
Nothing sensitive has to leave
The data an awareness platform holds is exactly the data you would least like to hand over: who is most susceptible, what they clicked, which department they sit in, and the internal context that makes a spear-phishing simulation realistic. Run local and none of it is transmitted anywhere.
Switchable, not locked
Local or cloud is a setting, not an architecture decision you make once and live with. Point the platform at Ollama, Claude, OpenAI, Groq, or your own endpoint — and change your mind later when a contract clause, an audit finding, or a new jurisdiction changes the requirement.
Self-host the whole platform
Enterprise deployments run the entire stack inside your infrastructure via Docker — application, database and model. For a buyer whose answer to “where does this data live?” has to be “here”, that is the difference between a deployable product and a non-starter.
The comparison
What a cloud-only platform cannot answer.
| The question a reviewer asks | Cloud-only platform | PhishNova |
|---|---|---|
| Where does the AI model run? | The vendor’s cloud, or their model provider’s | Your infrastructure, on a local model — or a cloud provider if you choose |
| Who sees employee risk scores? | You, the vendor, and their model provider | You |
| Can the whole platform be self-hosted? | Rarely, and usually at a bespoke price | Yes, via Docker, on the Enterprise tier |
| Can you change posture later? | Migrate vendors | Change a setting |
| Is AI output auto-published? | Varies — often yes | No. Every send passes a human approval queue |
Comparing architectures, not vendors. Any platform that self-hosts its model can answer these the same way — most do not.
Straight answers
The questions a security reviewer actually asks.
Does running a local model mean a worse product?
Not for this workload. Open, locally-deployable models handle scoped generation — writing a lure from a threat, drafting coaching for a specific red flag — well. Frontier cloud models can still have an edge on the longest and most complex generation tasks, which is exactly why the provider is switchable rather than fixed. The tradeoff is infrastructure, not quality.
What actually leaves our environment if we run local?
For AI generation, nothing. The model is served inside your environment and the prompt never crosses your boundary. Passive OSINT and Scam Radar read public sources from the internet, which is outbound-only and carries no employee data. If you self-host on the Enterprise tier, the application and database sit inside your infrastructure too.
How does this help with DPDP Act 2023?
Two ways. Data minimisation and residency get simpler when employee data never transits a third-party processor — there is one fewer processor to name, contract and diligence. And the audit log maps side-effecting actions to DPDP §8 and ISO 27001:2022 controls, so the evidence a reviewer asks for is already assembled. It supports your compliance; it is not a certification and we do not present it as one.
Do you hold SOC 2 or ISO 27001 certification?
No. PhishNova was founded in 2026 and a SOC 2 Type II observation window takes a minimum of three months after controls are in place, so any vendor our age claiming one should be asked for the report. We would rather tell you where we are. What we can share today: our security practices, a signed DPA, and a completed security questionnaire on request.
What should we ask other AI security vendors?
Where does data sent to the model physically go, and under whose control? Is self-hosted deployment available or is cloud the only option? Can you switch between local and cloud without switching platforms? Is AI output reviewed by a human before it reaches an employee? And what happens to data sent to the model provider — retained, trained on, or discarded? "We use AI" tells you very little; "here is exactly where your data goes when we do" tells you what you are agreeing to.
See it running on your own domain.
Book a 30-minute demo and we’ll run passive OSINT and email-authentication checks on your real domain first — you’ll see exactly what an attacker would find before you decide anything.
No agent to install · passive recon only · signed DPA available