Skip to main content
Cyber Health Score
Get started

Authorised email-based simulations

AI-Powered Social Engineering Evaluator (ASPE)

Authorised email-based phishing simulations that help teams recognise and respond to suspicious email. ASPE is a controlled awareness capability, not penetration testing, and it does not guarantee improved security outcomes.

Capability

Realistic enough to teach. Controlled enough to trust.

Campaign design keeps permission, pacing, participant education and in-workspace reporting visible as separate responsibilities.
01

Authorised email simulations

Plan controlled, authorised email-based phishing simulations scoped to recipients your organisation is permitted to include.

02

Context-aware email scenarios

Provide organisation context such as industry, tools, and culture so campaign email variations can reflect realistic internal communication styles.

03

Paced campaign delivery

Set launch windows, deadlines, and per-recipient email limits so delivery can be paced within a daily email capacity.

04

Engagement reporting and education

Review delivery and click engagement in your workspace, and send participants to a safe education page that explains missed warning signs.

Campaign path

Prepare, bound and authorise before delivery.

The launch sequence makes authorisation an explicit decision, not an implied consequence of uploading recipients.
  1. 01

    Prepare your recipients

    Upload a CSV containing name, email, role, and department for authorised recipients. You can optionally upload a custom senders CSV to support realistic vendor-style email scenarios.

  2. 02

    Set intensity and timeline

    Define how many emails each recipient may receive and set launch and deadline dates. Campaign planning helps keep delivery within a paced daily email capacity.

  3. 03

    Configure email scenarios

    Provide organisation context such as industry, software stacks, and internal culture so the campaign can generate context-aware email variations.

  4. 04

    Authorise and launch

    Review the Acceptable Use Policy, confirm authorisation, and launch the campaign. You can monitor de-duplicated engagement metrics from your workspace dashboard.

Build an authorised awareness campaign.

Start in a tenant-scoped workspace and confirm permission before launch.