
Yes. Every engagement is consented and scoped with your security team in advance. You set the targets, timing, and rules, and you can stop a run at any time.
Simulation tools send templates. The agent does autonomous OSINT and writes a personalized lure per target, the way a real attacker would, so the result reflects your actual exposure rather than recognition of a known template.
OSINT is drawn from public sources and handed back to you as part of the report. Engagement events such as clicks, replies, and credential-submit attempts are logged for your team, but real credentials are never captured or stored. Nothing is used to harm employees; it is used to find and close gaps.
Only the targets you provide and approve: a domain, teams, roles, or named employees.
No. The agent never captures or stores real credentials. It records only that a submit happened on the lure page, which shows who would have been compromised so your team can drive training and controls. Passwords and secrets are never collected.
Request a sample report to see the deliverable, then book a scoping call with your security team.





