Trust Center

Security and trust, by design.

Sensebait handles sensitive moments by definition — a phishing simulation platform has to be trustworthy before it's anything else. Here's how we protect your organization and your data.

Safe Simulations

A simulation should reduce risk, never create it

Simulated credential pages never capture or store a real password. Ever.

A Sensebait simulation reduces your risk — it never creates a new exposure of its own. What we record is the behavior that matters for scoring: whether a lure was opened, clicked, reported, or ignored.

Simulation capture log
Safe
Email opened Recorded
Link clicked Recorded
Reported to security Recorded
Password entered Never stored

Data Protection

How your data is handled

Encryption

Customer data is encrypted in transit and at rest.

Access control

Role-based access control for admins, managers, and viewers — so people see only what their role requires.

Audit trails

Per-user audit trails of every simulation and training action, retained as evidence for your program.

Compliance Support

Evidence for your compliance program

Sensebait provides evidence to support your compliance with ISO 27001, NIST, DORA, PCI-DSS, and sectoral mandates — training records, simulation results, per-user audit trails, and trended human risk scores your auditors can work from.

This describes how Sensebait helps your program meet your obligations. It is stated separately from any certifications Sensebait itself holds, so there is no ambiguity between the two.

Responsible Disclosure

Found a vulnerability?

We want to hear from you. Report it to our security team and we'll acknowledge your disclosure.

security@sensebait.com

Questions from your security review?

Talk to a security architect. We'll walk your team through how Sensebait handles data, access, and simulation safety.