Trust Center
Security and trust, by design.
Sensebait handles sensitive moments by definition — a phishing simulation platform has to be trustworthy before it's anything else. Here's how we protect your organization and your data.
Safe Simulations
A simulation should reduce risk, never create it
Simulated credential pages never capture or store a real password. Ever.
A Sensebait simulation reduces your risk — it never creates a new exposure of its own. What we record is the behavior that matters for scoring: whether a lure was opened, clicked, reported, or ignored.
Data Protection
How your data is handled
Encryption
Customer data is encrypted in transit and at rest.
Access control
Role-based access control for admins, managers, and viewers — so people see only what their role requires.
Audit trails
Per-user audit trails of every simulation and training action, retained as evidence for your program.
Compliance Support
Evidence for your compliance program
Sensebait provides evidence to support your compliance with ISO 27001, NIST, DORA, PCI-DSS, and sectoral mandates — training records, simulation results, per-user audit trails, and trended human risk scores your auditors can work from.
This describes how Sensebait helps your program meet your obligations. It is stated separately from any certifications Sensebait itself holds, so there is no ambiguity between the two.
Responsible Disclosure
Found a vulnerability?
We want to hear from you. Report it to our security team and we'll acknowledge your disclosure.
Questions from your security review?
Talk to a security architect. We'll walk your team through how Sensebait handles data, access, and simulation safety.