Features

Everything GottaPhish does

From the simulation your employees receive to the risk score your board reads — and everything in between that makes the numbers trustworthy.

Measure the risk that is actually there

A click rate is not a risk. GottaPhish turns behaviour into a number a board can act on — and refuses to invent one when the data isn’t there.

Role criticality30%Phishing behaviour60%Training completed30%Risk score0–100lowmediumhighcriticalUnknown → no score
Each dimension counts for what is missing, and only the known ones are weighed.

Composite risk score

Role criticality, phishing behaviour and training completion weighted into one 0–100 score per employee, read as exposure rather than as a grade.

Criticality inferred from the role

Job title and department are classified critical / high / medium / low automatically, and reclassified as people move.

Reporting rate, not just click rate

The phishing report mailbox is watched through the Microsoft Graph and Gmail APIs, so you can measure who raised the alarm.

Statistics robots don’t skew

Mail link scanners get a block page instead of the lure, and machine opens are told apart from human ones. Your funnel counts people.

Simulate the way an attacker would

Generative AI writes the scenario, picks the impersonated service and speaks each employee’s language — across every channel an attacker uses.

Scenarios generated end to end

Subject, envelope sender, HTML body and pretext are produced together per recipient, tailored to their role, language and history.

A catalogue of environments

Ready-made impersonations of the services your people actually use, landing pages included — extended with your own internal tools.

Email, SMS and AI voice calls

Smishing through a telephony provider or an on-premise SMS gateway, and vishing through AI voice agents that hold a conversation.

Translated on the fly

Landing pages are pre-translated per recipient, and attachments go through document translation that preserves Office and PDF formatting.

Reach the inbox, and leave it clean

The first objection is always the same: it will be blocked, or it will land in spam. GottaPhish provisions the whole delivery chain itself.

Sending domainDNS + DKIMExchange allowlistPre-flightInboxLink scannerBlock pageRecall
Provisioned automatically; scanners are diverted, and a campaign can be pulled back.

DNS and DKIM provisioned for you

Sending domains, their records and their signing keys are created and rotated automatically — no ticket to your network team.

Exchange allowlisting, automated

Safe-sender and transport configuration is applied to your tenant through the Microsoft Graph, so the simulation reaches the mailbox it tests.

Pre-flight before every campaign

Licences, sending domains and recipient domains are verified before a single message goes out; an undeliverable campaign never leaves.

Recall from the mailboxes

A badly timed campaign can be pulled back from Microsoft 365 and Google Workspace, and the report says what was recalled before it was read.

Turn a click into training

Everyone who takes the bait gets taught, and the completion of that training feeds straight back into their score.

Built-in e-learning

A full learning platform per tenant, with courses assigned to the people who need them rather than to everyone.

Training score

Course completion is pushed back per employee and shown next to the phishing score — counted in the risk only when the platform is connected.

An employee portal

Optional per customer: employees see their own results and their own training, without an administrator having to send anything.

One platform, your whole org chart

A group is not one company, and a manager is not an administrator. GottaPhish maps onto the structure you already have.

No data across branchesGroupSubsidiary ASubsidiary BOwn admin, branding,SSOManagerTheir team
Licences flow down the tree; visibility never crosses it sideways.

Managers see their own team

A manager signs in and gets their team’s dashboard, restricted at the database level. The reporting line comes from your directory.

Subsidiaries and delegation

Entities nest as deep as your group does. Administer everything centrally, or hand a subsidiary its own admin — data never crosses branches.

Licences that cascade

Licences flow down the tree and a released one stays with the entity that held it, with an Excel export of the distribution.

White-label, all the way down

Your own domain, branded login page and SSO realm per entity — the same mechanism resellers and MSPs run their own clients on.

Plug it in, and prove it

Everything a security team is asked for in an audit, and everything IT asks for before rolling it out.

SSO and SCIM provisioning

Users are pushed in from Entra ID, Okta or OneLogin over SCIM 2.0 — with department and reporting line — and sign in through your IdP.

Microsoft 365 and Google Workspace

Connected through the providers’ own APIs, with a live test that tells you whether the credential really works before you rely on it.

Dashboards, scoped per tenant

Embedded analytics with row-level security, so every account, entity and manager sees exactly their own perimeter and nothing else.

REST API and webhooks

A documented OpenAPI surface and outbound webhooks, so campaigns and results flow into your SIEM, your ITSM or your own reporting.

RBAC and an exportable audit log

Granular roles, and a per-tenant audit trail you can export as CSV for ISO 27001 or an internal review.

Hosted in France and the EU

GDPR-compliant infrastructure certified ISO/IEC 27001 and ISO 9001, maintained in-house — your data exportable at any time.

See it on your own environment

A 30-minute demo on your own domains, your own org chart, your own languages.