Three differences. Craft — our lures are designed by working pen-testers using current adversary tactics, not pulled from a shared template library. Vectors — we cover email, SMS, voice (including AI-deepfake on request), QR, and MFA fatigue as standard. Most SaaS competitors are email-first and treat the other vectors as add-ons or roadmap items. Reporting — our reports are reviewed by our audit team before they ship and are formatted to satisfy ISO 27001, SOC 2, NIS2 and DORA evidence requirements without rework. Where SaaS platforms win is on price-per-seat at scale; we are typically the right choice when realism and audit-grade evidence matter more than per-seat pricing optimisation.
Annual programmes priced per employee per year, with discounts at common breakpoints (250+, 1,000+, 5,000+ employees). Pricing scales with vector mix and cadence — an email-only quarterly programme is cheaper than a multi-vector monthly programme. Pilot campaigns (a single baseline plus debrief) are available as a one-off engagement for organisations that want to see results before committing to an annual programme. Contact us at hello@auditone.io for an indicative range.
Baseline click rate is measured on day one. Meaningful reduction shows up after 60–90 days of programme — typically a 30–50% drop from baseline. Mature click rates (under 5%) require sustained monthly cadence over 9–12 months and escalating sophistication, because employees adapt to the lures they have seen. The programme is not a one-off project; it is a control that compounds with sustained operation.
A well-run programme actively reduces helpdesk load over time, because employees become better at recognising and reporting real phishing. Initial campaigns do generate "I got a suspicious email" reports — which is the desired behaviour, not noise. We provide your helpdesk with a triage playbook so reported simulation emails are auto-acknowledged. Customers typically see reported-phishing tickets become useful threat intelligence by month three.
In most jurisdictions, including the EU under GDPR, internal phishing simulations are lawful as part of a legitimate-interest security programme — provided the programme is documented, proportionate, and employee data is processed in line with normal HR data handling. We provide a DPIA template and works-council briefing pack with every engagement. In some jurisdictions (notably Germany) the works council must be consulted before the programme starts; we walk you through that process if relevant.
Yes — and this is where the gap between AuditOne and most platforms is widest. We can generate LLM-crafted spear-phishing with native-language quality, AI-generated voice calls (vishing) that clone a target executive's voice from public audio, and multi-modal sequences that combine an email with a follow-up phone call. These are exactly the tactics being deployed against real organisations in 2026. AI-vishing in particular requires explicit scope authorisation and works-council sign-off; we manage that consent flow as part of scoping.
Yes. Our sending infrastructure is allowlisted as part of setup so simulations bypass Microsoft Defender, Proofpoint, Mimecast, or Google Workspace's built-in filtering — otherwise the test would measure your gateway's accuracy, not your employees' behaviour. We can also configure the opposite: send simulations through your gateway specifically to test whether your security stack catches them. Both modes are useful for different reasons.
Yes. The most common starting point is a single baseline campaign — one email-vector simulation across all employees, no prior training, full reporting, no annual commitment. You see your real click rate, your real reporting rate, and your real worst-case exposure. Most customers convert to an annual programme after seeing their baseline; some discover their existing programme is already working and decide they don't need us. Either outcome is fine.