The phishing simulation platform for EU teams

Your people are the attack surface. Test them weekly.

AutoPhish generates the campaigns, sends them from dedicated simulation domains, and trains whoever falls for them — automatically, every month, without a project plan.

  • Servers in Germany
  • GDPR by default
  • Setup in 10 min
app.autophish.io — product tour

Trusted by security-conscious teams

edeja software
Post Business Solutions
RansomLeak Security Training
Allegro Vivo
Brevius
Perfect-EDV IT Services

Join teams using AutoPhish to build a human firewall against phishing.

How it works

Your first phishing simulation, live in 10 minutes

Three steps. No consultants, no onboarding project, no template library to curate.

1

Connect your domain

Add the domains you own so AutoPhish can verify them and keep checking SPF, DKIM and DMARC. Simulations go out from dedicated AutoPhish sending domains, so no DNS change is needed to start.

2

Configure the campaign

Pick target groups and a schedule. AI writes the pretexts for your industry, language and season — invoice fraud, HR notices, MFA resets.

3

Analyse and train

Clicks are recorded in reporting. A credential submission triggers the teachable moment and, when you enable it for the campaign, a short module on the tactic that worked. Reporting shows risk per team, per user, over time.

The platform

Everything a phishing simulation programme needs

Simulation, training and email-authentication monitoring in one place — so the programme keeps running when you get busy.

Realistic AI simulations

Pretexts generated to mimic current attacks in your industry, not a static library everyone has already seen.

Automated campaigns

Set a cadence once. Simulations go out on schedule, staggered per user, with no monthly admin from you.

Targeted training

Training follows the simulation someone actually fell for, not one annual video for all 300 people. Assign the built-in course, redirect to your own training URL, or switch it off per campaign.

Domain security monitoring

Continuous SPF, DKIM and DMARC checks with alerts when records change or look-alike domains appear.

Multi-company for MSPs

One login, many client tenants. Separate domains, campaigns and reports per company, switchable from the top bar.

Reporting for audits

Per-campaign and per-user evidence of training delivery, exportable when an auditor asks for it.

Compare

AutoPhish vs. legacy awareness suites

Most awareness platforms were built for large enterprises with a dedicated programme owner. AutoPhish is built for the team that has other work to do.

Time to first campaign

AutoPhish: About 10 minutes, self-serve

Legacy suites: Onboarding call, then days of setup

Simulation content

AutoPhish: AI-generated per industry and language

Legacy suites: Shared template library staff have seen

Training assignment

AutoPhish: Automatic on submission, based on the simulation that worked

Legacy suites: Manual course assignment or annual module

Email authentication

AutoPhish: Dedicated sending domains; your own SPF/DKIM/DMARC monitored

Legacy suites: Your problem, handled outside the tool

Data residency

AutoPhish: EU only — servers in Germany

Legacy suites: Often US-hosted with transfer clauses

Multi-client management

AutoPhish: Built in for MSPs, one login

Legacy suites: Separate contract or instance per client

Commitment to start

AutoPhish: 7-day Pro trial, no credit card to sign up

Legacy suites: Annual contract and per-seat minimums

Buyer's guide

What a phishing simulation platform does — and what to look for

AutoPhish is a phishing simulation platform: it sends realistic, AI-generated phishing emails to your own employees, measures who clicks, and automatically trains the people who fall for them. A phishing simulation platform sends controlled, realistic phishing emails to your own staff, records who opens, clicks or submits credentials, and turns that result into training. Done once a year it produces a compliance screenshot. Done continuously it produces a measurable drop in click rate — which is the only number that matters when a real campaign arrives.

The differences between platforms come down to four things: how believable the emails are, how fast you can get a campaign out, what happens in the seconds after a click, and where your employee data lives.

Simulation realism

Shared template libraries age badly — staff recognise the same fake parcel notice across employers. Generated pretexts, localised and tied to your industry and calendar, keep the test honest.

Deliverability and domain setup

If simulation mail is filtered, your results are noise. AutoPhish sends from dedicated simulation domains, so nothing depends on your own DNS — and it monitors your real SPF, DKIM and DMARC records separately.

The teachable moment

Training lands when the mistake is fresh. A landing page that names the red flags the user missed, plus a short module on that tactic, beats a quarterly course nobody finishes.

Data residency and works councils

Simulation results are employee performance data. EU hosting, a signed DPA and the option to anonymise individual results are what get a programme past legal and the works council.

Automation over campaigns

A platform that needs a human to launch each round becomes a platform nobody uses by month four. Set the cadence once and let the system schedule, send and follow up.

Evidence for ISO 27001 and NIS2

Auditors ask who was trained, on what, and when. Exportable per-user records turn awareness training from an assertion into evidence.

Compliance & hosting

Built in the EU, hosted in the EU

AutoPhish is an Austrian-founded company with servers in Germany. All data is processed inside the EU, DPAs are signed on request, and the privacy policy is written in plain language by design.

EU-hosted

Servers in Germany, no transatlantic transfer.

GDPR by default

DPA on request, anonymisation options for results.

Audit evidence

Exportable records for ISO 27001 and NIS2 reviews.

Built by engineers

Security practitioners, not a rebranded LMS.

Common questions

Everything security buyers ask before signing up.

See AutoPhish on your own domain

A 30-minute walkthrough: we set up a live simulation against a test group and show you the reporting an auditor would accept.