From CSV upload to
continuous protection
in under an hour.

Five steps. No ongoing management. Phishforge builds profiles, generates lures, trains employees, and adapts difficulty — all automatically.

01

Profile building — HRIS or CSV

Connect BambooHR, Personio, or HiBob via OAuth in two clicks. Or upload a CSV with employee names, roles, and departments. Phishforge ingests the data and builds a structured profile for every employee. No manual configuration. Profiles update automatically when your HRIS changes.

Supported integrations: BambooHR, Personio, HiBob

CSV fallback for any HRIS not listed

Profiles update automatically on HRIS sync

Role and department drive lure type inference

02

AI lure generation per profile

For each employee profile, Phishforge's AI infers the tools they're likely to use based on their role and department. It then generates a personalised lure library — not templates, not selections from a bank. Every lure is written by the model. A developer's lures reference GitHub, AWS, and Jira. A finance manager's reference Sage, Xero, and DocuSign.

Role → tool inference, no manual mapping

Every lure generated fresh, never templated

Lure difficulty calibrated to employee history

Lure types: credential harvest, urgency, authority, social

03

Continuous campaign cadence

Set a cadence — weekly, fortnightly, monthly — and Phishforge handles everything. Campaigns run on a rolling schedule indefinitely. There's no campaign end date, no renewal, no manual trigger. The platform randomises send times within each window to avoid predictable patterns.

Configurable cadence: weekly to monthly

Randomised send times within each window

No campaign end date — runs until you pause

Slack and Teams alerts for high-risk events

04

Post-click training moment

When an employee clicks a lure, they're immediately shown a training page — contextual to the specific lure type they fell for. Not a generic security awareness module. A developer who clicked a fake GitHub alert gets training specifically about OAuth phishing and token theft. It's shown once, immediately, at the moment of maximum attention.

Training triggered immediately on click

Content specific to the lure type (not generic)

One-screen format — no multi-module courses

Completion tracked and included in risk score

05

Adaptive difficulty and risk scoring

Over time, Phishforge builds a human risk profile per employee. Repeat clickers receive harder, more sophisticated lures on a faster cadence. Fast reporters receive increasingly subtle lures to maintain vigilance. The platform surfaces your highest-risk individuals and departments automatically — no manual analysis required.

Per-employee risk score, updated after every interaction

Difficulty increases automatically for repeat clickers

High-risk individuals flagged in real-time dashboard

Department-level risk trends over time

See Phishforge running against
your own employee profiles.

14-day free trial. Connect your HRIS or upload a CSV. First lures go out within the hour.