Security & trust
Built for security teams — held to their standard.
PhishNova is designed multi-tenant, org-scoped, and least-data by default, with GDPR and India DPDP support built in from the first line of code.
Passive recon only
PhishNova maps your external attack surface with passive OSINT. There is no agent to install and no scanning of your internal infrastructure.
Encryption in transit & at rest
All traffic is served over TLS. Data at rest is encrypted, and secrets are managed outside application code.
Access control & SSO
Role-based access is scoped by organization, department, and manager. Enterprise adds SSO/SAML and a full audit log.
Multi-tenant isolation
Every tenant’s data is org-scoped at the data layer, so one customer can never see another’s employees, campaigns, or results.
Approval queue & audit
Every simulation send is gated by a human approval queue, and side-effecting actions are written to an audit log.
Least-data by design
We collect what a program needs to run and nothing more, and we support data-subject requests under GDPR and DPDP.
See it in the product
Not a diagram — the real interface.
Screenshots below are from a live demo workspace, not mockups.

Passive recon, not a scan
DMARC, SPF, DKIM, BIMI, and MX are checked from the outside — no agent, no internal scanning.

One score, ranked actions
Internal signals plus passive OSINT roll up into a single grade and a prioritized action list.

Every action, logged
Side-effecting actions write to an audit trail mapped to ISO 27001:2022 controls and DPDP Act §8.
Real product screenshots — demo workspace, not a customer account
Certifications
We hold no third-party security certification yet. PhishNova was founded in 2026, and a SOC 2 Type II observation window takes a minimum of three months after controls are in place — so any vendor of our age claiming one should be asked for the report. We would rather tell you where we are than imply otherwise.
What we can share today: our security practices above, a signed Data Processing Addendum, and a security questionnaire response on request. Email security@phishnova.com and we will send both. When our audit completes we will publish the report here and date it.
Responsible disclosure
We welcome reports from security researchers. If you believe you’ve found a vulnerability, please email security@phishnova.com with details and steps to reproduce. We’ll acknowledge your report, keep you updated, and credit you if you’d like once the issue is resolved. Please give us reasonable time to remediate before any public disclosure.
Data processing
Our Data Processing Addendum describes how we process personal data on your behalf, sub-processors, and international transfer safeguards. For privacy questions, contact privacy@phishnova.com.