AI campaign generator
Describe a scenario in one line. HukProof writes the lure, the lookalike domain, and a brand-matched landing page, all modelled on today’s live attacks.
No consultant. No specialist. No enterprise rollout.
Run the social-engineering simulations, coach people the moment they slip, and get the audit-ready evidence you'd otherwise hire a consultant for. You set it up yourself, it's live this week, and it costs less than a consultant charges for a day.
Hi Sarah,
Our security audit detected your password is set to expire in 59 minutes. To avoid losing access to email and Slack, please reset it immediately using the secure portal below.
If you don't reset before expiry, your account will be locked and IT will need to manually restore access.
— Acme IT · Do not reply · Ticket #SEC-29481
Sarah spotted the sender mismatch, hit Report, and the campaign was quarantined for the whole org.
Set it up once. Every campaign sharpens the last until safe habits stick. Tap a step to see it.
Without hiring one.
Describe a scenario in one line. HukProof writes the lure, the lookalike domain, and a brand-matched landing page, all modelled on today’s live attacks.
Phishing simulations from lookalike domains: email and QR-code (quishing) today, with SMS (smishing) on the roadmap, all from one platform.
See department-level risk update in real time and find the handful of people behind most of the clicks, with repeat-offender flagging built in.
Pick your own custom sending domain for a more realistic simulation. SPF, DKIM and DMARC are handled for you.
The instant someone falls for a phishing email, they’re coached on the spot with an annotated breakdown of the exact red flags they missed. Teaching at the moment of the mistake sticks far better than a course weeks later.
One page per campaign: click, credential entry, time-to-report, and a department leaderboard, all export-ready as evidence for your own compliance reviews.
An attacker needs under a minute. You’d wait months to find out for real. A safe simulated phish tells you today: who clicks, which teams, which repeat offenders. The only thing lost is a teachable moment.
Start free. Upgrade when your team grows.
Everything you need to run your first simulations.
Up to 200 employees, then $0.50/employee/mo.
For up to 5,000 employees, multi-tenant, or regulated industries.
The practical stuff: delivery, setup, privacy, and how your people actually experience it.
Still have a question? Start free and see it on your own team. No card, no sales call.
Yes. You send from your own branded domain with SPF, DKIM and DMARC configured for you, and we detect your mail provider and walk you through a one-time allowlisting step for Microsoft 365 or Google Workspace. A built-in test lets you confirm delivery before you launch. Simulations land in the inbox the way a real attack would, not buried in a quarantine nobody checks. And if a message ever is filtered, you’ll see it in the results, so your numbers reflect reality rather than a false sense of safety.
Minutes, not weeks. Import your team from a CSV or your directory, pick a ready-made template or generate one with AI, choose a sending domain, and launch. No onboarding project or professional-services engagement required. Results come in as your people open, click and report.
They don’t reach an attacker. They reach a short, plain-language teachable moment. It shows the exact red flags they missed in the email they just fell for, while it’s still fresh in their mind. That in-context coaching is what actually changes habits, and it’s why click rates keep dropping campaign after campaign instead of plateauing.
No. There’s no public shaming and no leaderboard of names. Falling for a simulation triggers coaching, not blame, and reporting is framed around team-level risk trends rather than singling individuals out. The goal is a workforce that confidently spots real attacks, not one that resents the security team.
Every customer’s data is isolated at the database level, so one organisation can never see another’s. We collect only what’s needed to run and measure campaigns: recipients, templates and engagement events, and nothing more. Higher tiers include a signed DPA and audit logs, with a BAA planned for regulated industries.
No. It’s built for lean teams who’d rather ship than schedule a training day. Set it up once and the loop runs itself. Each campaign automatically focuses on the riskiest people and sharpens the next. Most customers run it without a dedicated security hire.
A once-a-year course is forgotten by week two. HukProof tests continuously, teaches in the exact moment someone slips, and measures whether risk is genuinely falling, the way real attackers probe your people all year long, not for one afternoon in Q1. You get a trend line you can take to the board, not a completion certificate.
See your real risk
Run a safe simulated phish and see exactly where your risk is, before an attacker does it for you.