Skip to content
PHISHNOVA

Security & trust

Built for security teams — held to their standard.

PhishNova is designed multi-tenant, org-scoped, and least-data by default, with GDPR and India DPDP support built in from the first line of code.

Local AI optionIndia DPDP alignedGDPR alignedPassive recon only

Passive recon only

PhishNova maps your external attack surface with passive OSINT. There is no agent to install and no scanning of your internal infrastructure.

Encryption in transit & at rest

All traffic is served over TLS. Data at rest is encrypted, and secrets are managed outside application code.

Access control & SSO

Role-based access is scoped by organization, department, and manager. Enterprise adds SSO/SAML and a full audit log.

Multi-tenant isolation

Every tenant’s data is org-scoped at the data layer, so one customer can never see another’s employees, campaigns, or results.

Approval queue & audit

Every simulation send is gated by a human approval queue, and side-effecting actions are written to an audit log.

Least-data by design

We collect what a program needs to run and nothing more, and we support data-subject requests under GDPR and DPDP.

See it in the product

Not a diagram — the real interface.

Screenshots below are from a live demo workspace, not mockups.

app.phishnova.com/security-posture
Technical drill-down of DMARC, SPF, DKIM, BIMI and MX findings with recommended simulations

Passive recon, not a scan

DMARC, SPF, DKIM, BIMI, and MX are checked from the outside — no agent, no internal scanning.

app.phishnova.com/security-posture
Security Culture Score screen showing a risk grade and ranked, highest-impact actions

One score, ranked actions

Internal signals plus passive OSINT roll up into a single grade and a prioritized action list.

app.phishnova.com/audit-log
Audit and Event Log summary showing ISO 27001:2022 and DPDP Act 2023 coverage badges

Every action, logged

Side-effecting actions write to an audit trail mapped to ISO 27001:2022 controls and DPDP Act §8.

Real product screenshots — demo workspace, not a customer account

Certifications

We hold no third-party security certification yet. PhishNova was founded in 2026, and a SOC 2 Type II observation window takes a minimum of three months after controls are in place — so any vendor of our age claiming one should be asked for the report. We would rather tell you where we are than imply otherwise.

What we can share today: our security practices above, a signed Data Processing Addendum, and a security questionnaire response on request. Email security@phishnova.com and we will send both. When our audit completes we will publish the report here and date it.

Responsible disclosure

We welcome reports from security researchers. If you believe you’ve found a vulnerability, please email security@phishnova.com with details and steps to reproduce. We’ll acknowledge your report, keep you updated, and credit you if you’d like once the issue is resolved. Please give us reasonable time to remediate before any public disclosure.

Data processing

Our Data Processing Addendum describes how we process personal data on your behalf, sub-processors, and international transfer safeguards. For privacy questions, contact privacy@phishnova.com.