No consultant. No specialist. No enterprise rollout.

The security-awareness program for teams without a security team.

Run the social-engineering simulations, coach people the moment they slip, and get the audit-ready evidence you'd otherwise hire a consultant for. You set it up yourself, it's live this week, and it costs less than a consultant charges for a day.

mail.acme-corp.com / inbox
PrimarySocialPromotions
ITIT Support
Action required: password expiring in 1 hour — Reset to keep account access…
just now
MMarketing
Q3 campaign results — Numbers are in, hit 118% of pipeline target…
1h
HHR Department
Updated PTO policy — Please review attached changes for FY26…
1h
JMJohn Miller
Re: Project timeline — Looks good. Let's sync tomorrow at 9…
2h
FFinance
Monthly expense report — Attached for your review and approval…
3h
SSlack
You have 3 unread messages — #general, #design and 1 more…
3h
ZZoom
Your meeting recording is ready — Weekly sync · 42 min…
4h
CCalendar
Reminder: 1:1 with Priya at 3:00 PM — Google Meet link attached…
5h
AAWS Billing
Your July invoice is available — Total due $1,284.60…
6h
IT
IT Support <support@acme-corp.io>
to sarah.chen@acme-corp.com · just now
Action required: password expiring in 1 hour

Hi Sarah,

Our security audit detected your password is set to expire in 59 minutes. To avoid losing access to email and Slack, please reset it immediately using the secure portal below.

→ Reset password now

If you don't reset before expiry, your account will be locked and IT will need to manually restore access.

— Acme IT · Do not reply · Ticket #SEC-29481

https://acme-corp-secure.co/login
Sign in to renew your password
Email
Password

Reported in 9 seconds.

Sarah spotted the sender mismatch, hit Report, and the campaign was quarantined for the whole org.

9s
Time to report
412
Teammates protected
$0
Breach cost
!
21 SECONDS · NO INTERVENTION

Credentials captured.

+00:00sEmail opened by S. Chen · Sales
+00:08sClick on “Reset password” link
+00:14sLookalike domain loaded · acme-corp-secure.co
+00:21sCredentials submitted · attacker has account access
+00:23sLogin from 104.21.x.x · Tallinn · token issued
+00:42sMFA bypassed via session-replay · 14 systems accessible
Time to compromise
21s
Systems exposed
14
Avg. breach cost
$4.88M
01 · Inbox
01 · DiscoverQ3 phishing simulation
240Sent
236Received
187Opened
63Clicked
29Submitted
DifficultyHard
TemplatePassword expiry · IT Helpdesk
Credential submit rate · by dept
Sales
34%
Finance
26%
Support
15%
Eng
6%
Repeat offenders · by dept
Finance
22%
Sales
18%
Support
9%
Eng
3%
02 · TrainCoached the instant they slip
The exact email that fooled them, annotated
IT
IT Supporthelpdesk@acme-c0rp.com
Look-alike domain
Action required: your password expires today
Hi Sarah, our security check found your password expires in the next 2 hours. Re-verify now to keep access to email and Slack — un-verified accounts are locked automatically.Fake urgency
Reset password now →Spoofed link
— Acme IT Helpdesk · Ticket #SEC-2914 · do not reply
63Coached instantly
34sAvg. read time
0Scheduled courses
Repeat-click rate after coaching 8%, down from 26% on first touch.
03 · ProtectRisk falls on a live dashboard
4%Click rate27 pts
3Repeat offendersfrom 11
4.2%Phish-prone29 pts
100%Coverageenrolled
Click rate · last 6 campaigns
C1C2C3C4C5C6
Board-ready summaryExport as PDF
04 · ImproveEvery loop makes them harder to fool
Safe-habit rate · after 6 campaigns
4.2%phish-prone now
34%where you started
30 ptsacross 6 campaigns
Re-targets 12 repeat offenders
Rotates in 8 fresh templates
Tracks progress across 4 departments
Next campaign auto-scheduled, targeting the riskiest teams: Sales & Finance.

Discover, train, and measure.

Set it up once. Every campaign sharpens the last until safe habits stick. Tap a step to see it.

Everything a security consultant would build you.

Without hiring one.

Find your risky clicks before an attacker does.

An attacker needs under a minute. You’d wait months to find out for real. A safe simulated phish tells you today: who clicks, which teams, which repeat offenders. The only thing lost is a teachable moment.

Run a free simulationFree for up to 100 employees · no card
How exposed is your team right now?
People in your organisation100
Months of continuous training12 mo
33
would click a phishing email today, before any training
4
still at risk after 12 months of training
29 fewer people walking your attackers straight in. Phish-prone rate now 4.2%.
$150kestimated annual cost of phishing at this size and training level, down from $150k untrained. Ponemon / Proofpoint, 2021 ↗
Modelled on the global phish-prone rate: 33.2% untrained → 20.1% at 3 months → 4.2% at 12 months of testing. KnowBe4, 2026 ↗

Cheaper than one security consultant call.

Start free. Upgrade when your team grows.

Free
$0/mo

Everything you need to run your first simulations.

  • Up to 100 employees
  • 2 campaigns
  • Ready-made + custom templates
  • Basic risk dashboard
Start free
Pro
$29/mo

Up to 200 employees, then $0.50/employee/mo.

  • Up to 1,000 employees
  • Unlimited campaigns
  • Custom domains
  • AI campaign generator
  • Email + QR simulations
Scale
Talk to us

For up to 5,000 employees, multi-tenant, or regulated industries.

  • Everything in Pro
  • SAML SSO + SCIM (planned)
  • Custom sending domain pool
  • Dedicated success manager
  • Audit log + DPA + BAA (planned)

Questions teams ask first.

The practical stuff: delivery, setup, privacy, and how your people actually experience it.

Still have a question? Start free and see it on your own team. No card, no sales call.

Will simulated phishing actually reach the inbox?

Yes. You send from your own branded domain with SPF, DKIM and DMARC configured for you, and we detect your mail provider and walk you through a one-time allowlisting step for Microsoft 365 or Google Workspace. A built-in test lets you confirm delivery before you launch. Simulations land in the inbox the way a real attack would, not buried in a quarantine nobody checks. And if a message ever is filtered, you’ll see it in the results, so your numbers reflect reality rather than a false sense of safety.

How fast can we launch our first campaign?

Minutes, not weeks. Import your team from a CSV or your directory, pick a ready-made template or generate one with AI, choose a sending domain, and launch. No onboarding project or professional-services engagement required. Results come in as your people open, click and report.

What happens the moment someone clicks?

They don’t reach an attacker. They reach a short, plain-language teachable moment. It shows the exact red flags they missed in the email they just fell for, while it’s still fresh in their mind. That in-context coaching is what actually changes habits, and it’s why click rates keep dropping campaign after campaign instead of plateauing.

Won’t this embarrass or punish our people?

No. There’s no public shaming and no leaderboard of names. Falling for a simulation triggers coaching, not blame, and reporting is framed around team-level risk trends rather than singling individuals out. The goal is a workforce that confidently spots real attacks, not one that resents the security team.

How is our data handled and kept private?

Every customer’s data is isolated at the database level, so one organisation can never see another’s. We collect only what’s needed to run and measure campaigns: recipients, templates and engagement events, and nothing more. Higher tiers include a signed DPA and audit logs, with a BAA planned for regulated industries.

Do we need a security team to run it?

No. It’s built for lean teams who’d rather ship than schedule a training day. Set it up once and the loop runs itself. Each campaign automatically focuses on the riskiest people and sharpens the next. Most customers run it without a dedicated security hire.

How is this different from annual security training?

A once-a-year course is forgotten by week two. HukProof tests continuously, teaches in the exact moment someone slips, and measures whether risk is genuinely falling, the way real attackers probe your people all year long, not for one afternoon in Q1. You get a trend line you can take to the board, not a completion certificate.

See your real risk

Find out who would have clicked.

Run a safe simulated phish and see exactly where your risk is, before an attacker does it for you.

  • Free for up to 100 people
  • No credit card
  • First results in minutes