SIMULATE-BY-DEFAULT • nothing sends live until a channel is explicitly armed
● Security Awareness Training

Turn your people into
your strongest layer.

Phishkit by Tribastion runs awareness newsletters, poster campaigns, deepfake-awareness modules, gamified training, and safe simulated phishing, vishing and smishing — delivered only to your own enrolled, consented staff, and measured with a human-risk score that goes down over time.

Every simulation ends in a teachable moment, and when someone types into a fake login page the platform records only that it happened and discards what they typed. No real credential is ever captured — that is a hard, non-configurable rule.

3simulation vectors
⌘Ksearch everything
24/7Slack & webhook alerts
Phishkit — Tribastion Demo Corp · Q3 simulation
Phishkit
Dashboard
Audiences
Simulations
Training
Insights
LowOrg human-risk band
86%Reported the phish
9%Clicked
2%Submitted (sim)
1,240Recipients
Campaign complete
1,240 recipients86% reported it as phishing
No credential stored
Submission logged onlyWhat they typed was discarded
● How it works

Consent first, simulate by default, teach on every interaction

A safe, closed loop: nobody is contacted without consent, nothing sends live without two independent gates passing, and every click becomes a moment to learn.

1

Enrol & consent

Import staff as recipients and group them into audiences. Consent is an append-only ledger; a hard unsubscribe is honoured everywhere, forever.

2

Design & approve

Build a lure and a teachable-moment page. Designing and launching are different permissions — a live send needs a separate approval and an armed channel.

3

Deliver & track

Simulate with zero blast radius, or send live once armed. Opens, clicks and reports are tracked per recipient — a submitted password is never stored.

4

Teach & measure

Every interaction lands on a teachable moment. Behaviour and training completion feed a human-risk score that trends down over time.

● One awareness programme

Every channel to reach your people, in one console

Awareness content, simulated social engineering and real training — all built on the same consented audience and measured by the same risk score.

Recipients & audiences

Enrolled staff, grouped into departments and cohorts — the target of every campaign.

Consent & suppression

Opt-in gates every send; a hard unsubscribe is honoured across every module, always.

Newsletters

Topic-based awareness newsletters, scheduled or one-off, with open and click tracking.

Posters & flyers

A print-ready awareness artwork library with email-embed and display-board acknowledgement.

Phishing / vishing / smishing

Safe simulated social engineering across email, SMS and voice — teachable-moment on every click.

Deepfake awareness

Lessons and "spot the deepfake" exercises on AI-voice and video fraud.

Training & gamification

Courses, quizzes and certificates with points, badges, streaks and a leaderboard.

Human risk score

A per-person, per-department and per-org number, driven by real behaviour and training.

● Built to actually use

A console your whole team opens every day

Hover or tap a card. The Tribastion platform foundation — auth, roles, audit, notifications, search and an open API — is live from day one.

Instant notifications

hover / tap

Instant notifications

Campaign launches, click-rate spikes and reported phish land in-app immediately — and push to Slack or a webhook if you've connected one.

Global search

hover / tap

Global search

Ctrl+K from anywhere searches recipients, audiences, scenarios, campaigns and courses at once — filtered to what your role can actually see.

Guided help

hover / tap

Guided help

An in-app walkthrough of the whole lifecycle plus a live role guide, read straight from the same RBAC catalog that enforces permissions — never out of sync.

Open API

hover / tap

Open API

Scoped X-API-Key credentials for a central governance or monitoring platform to pull metrics and results — permissions narrowed, never widened.

● The metric that matters

A human-risk score you can trust, because it's never hand-typed

  • Driven by real behaviourClicking or submitting to a simulation raises risk; reporting the phish lowers it. Training completion lowers it further. Every input is a real event, never an estimate.
  • Rolls up person → department → orgSee exactly where to focus training, with recency weighting so recent behaviour counts more than a stale result from a year ago.
  • We never store what people typeA simulated submission records only that it occurred. The credential is discarded before the first write — it never reaches the database, the logs, or the audit trail.
Finance — quarterly phishing simLow
Operations — smishing exerciseGuarded
New joiners — onboarding cohortElevated
Org training completion92% this quarter
● Built for a shared platform

Safe by design, for the people you're protecting

The same guardrails that gate a live send also gate who can see and do what — enforced at the query level, not just the UI.

No credential capture

A simulated submission is logged as an event only — what a person types is discarded, never stored.

Fail-closed sending

Nothing goes live unless the platform, the channel and the campaign are each explicitly enabled.

Segregation of duties

Designing a campaign and launching it live are deliberately different hands.

Tenant isolation

Every query is scoped to your organisation automatically — enforced by the framework.

Tamper-evident audit

A hash-chained log of every consequential action, verifiable end to end.

Ready to see it running on real data?

Sign in to the demo tenant and open a campaign, an audience, or the human-risk dashboard yourself.

Sign in to your console