
Phishing simulation and awareness training with audit-ready evidence exports

Phishing simulation and awareness training with audit-ready evidence exports
The Entire Cybersecurity Market, One Prompt Away
Connect your AI assistant to ... tools and ... vendors. Ask anything about the cybersecurity market.
Fallax provides phishing simulation and security awareness training software aimed at small and mid-sized organizations that need to produce compliance evidence without a lengthy sales process. The platform injects simulated phishing emails directly into a customer's own Google Workspace or Microsoft 365 tenant, removing the need to configure a separate sending domain, SPF, DKIM, DMARC records or allowlisting. Simulations run on a per-person schedule that adjusts based on how each individual responded to previous tests. Employees who click a simulated phishing link are shown a short training page explaining what happened, and those who report a suspicious email receive positive feedback. The service does not store submitted credentials, only whether a submission occurred. Fallax generates an exportable, dated, per-person record of training activity intended to satisfy auditor requirements across multiple frameworks, including ISO 27001, SOC 2, NIS2, DORA, PCI DSS, HIPAA, GDPR and NIST CSF. It can also sync evidence automatically with third-party compliance platforms such as Vanta, Drata, Secureframe and Sprinto. The product is offered as a single tier that scales from 10 free seats up to organizations of 5,000 people, with published per-seat pricing rather than custom quotes. All product features, including SSO, custom sending domain and evidence export, are included in the free plan. Data is hosted in the European Union, with Stripe as the only sub-processor located outside the EU for billing purposes.