Frequently Asked Questions
Find answers to common questions about AutoPhish and how it works.
Got Questions? We Have Answers!
What is AutoPhish?
AutoPhish is a cybersecurity SaaS platform designed to help organizations strengthen their security posture. We use AI-powered, automated phishing simulations and provide targeted security awareness training to educate employees.
How does the phishing simulation work?
Administrators can configure and schedule phishing campaigns. Our platform sends realistic, AI-generated simulation emails to selected employees. We track interactions (like clicks or data entry attempts on simulated pages) to measure awareness and identify areas for training.
Do you store passwords entered during simulations?
Absolutely not. AutoPhish **does not** store, log, or transmit any passwords or sensitive data entered by users on simulated login pages. Our focus is solely on tracking the interaction itself for training purposes.
Is AutoPhish GDPR compliant?
Yes, we are committed to data privacy. We act as a data processor for employee data used in simulations, following GDPR guidelines. Data processing primarily occurs within the EU. Please see our Privacy Policy for full details.
How do I register an account?
You can sign up on our registration page by providing your email and creating a strong password. You will also need to agree to our Terms of Service and Privacy Policy before completing the registration.
Are there different subscription plans?
Yes. Each plan includes a monthly pool of credits and a limit on verified domains. Credits are spent as you send: 1 credit per simulated email and 2 credits per SMS segment. Please check our Pricing page for details on each plan.
Why do I need to verify my domain?
Domain verification is a crucial security step. It proves you own the domain you intend to send simulation emails from, preventing misuse of our platform and ensuring simulations are authorized.
Can campaigns be customized?
Yes, administrators can customize various aspects of phishing campaigns, including selecting email templates, target groups, and scheduling frequency to fit their organization's needs.
What kind of reporting is available?
AutoPhish provides a dedicated reports section where you can view summary statistics (like open rates, click rates, login attempt rates) over selected date ranges. You can also see details of individual campaign executions and identify users who might need additional training based on their interactions.
How does AutoPhish know about my company's products and services?
Our AI automatically fetches context about your company, such as products and services, from your website. This is done to speed up the initial setup phase and to help our AI create more realistic and targeted phishing campaigns. This information is used solely for the purpose of generating phishing simulations and is not shared with any third parties.
What is the 'Risk Score' shown in reports?
The Risk Score is a calculated metric designed to help prioritize users for follow-up training. It assigns weights to different interactions: login attempts are weighted highest, followed by link clicks, and then email opens. A higher score indicates a user has interacted in riskier ways across one or more simulations.
Do you support multiple companies or resellers?
Yes. AutoPhish now includes Multi-Company support with owner-based billing and role-based access per company. It's ideal for groups and IT service providers. Our Reseller Mode lets MSPs and system houses manage multiple client organizations with strict data separation. Learn more on the Multi-Company page.
Didn't find your answer?
Our comprehensive help center has detailed guides, tutorials, and additional resources to help you get the most out of AutoPhish.
Visit Help Center