Fallax icon
Fallax icon

Fallax

Phishing simulation and security awareness training that delivers through your own Microsoft 365 or Google Workspace tenant and exports audit evidence for ISO 27001, SOC 2 and NIS2.

Fallax screenshot 1

Cost / License

  • Freemium (Subscription)
  • Proprietary

Platforms

  • Online
  • Software as a Service (SaaS)
1like
0comments
0articles

Features

Fallax News & Activities

Highlights All activities

Recent activities

Fallax information

  • Developed by

    BE flagFallax
  • Licensing

    Proprietary and Freemium product.
  • Pricing

    Subscription that costs up to $1000 per month + free version with limited functionality.
  • Alternatives

    3 alternatives listed
  • Supported Languages

    • English

AlternativeTo Category

Security & Privacy
Fallax was added to AlternativeTo by IgnaceMaes on and this page was last updated .
No comments or reviews, maybe you want to be first?

What is Fallax?

Fallax is a phishing simulation and security awareness platform for authorised internal security testing. It connects to your Microsoft 365 or Google Workspace tenant with one admin consent, syncs your people straight from the directory, and delivers simulated phishing emails by injecting them into staff mailboxes through your own tenant. There is no sending domain to configure, no SPF/DKIM/DMARC setup, and no risk to the deliverability of the domain your real business mail depends on.

Once connected, a continuous programme gives every person their own schedule of simulations, sent at a random minute inside their own working hours so colleagues cannot warn each other. Cadence and difficulty adapt to how each person handled the last one: frequent clickers are tested more often on easier lures, consistent reporters get the hardest ones less often. A monthly cap, a minimum gap between sends and a pause that drops the whole queue keep it bounded. One-off campaigns still exist for tests you want to run by hand.

Opens, clicks, credential submissions and reports are tracked per person. Submitted credential values are never stored, only that a submission occurred. Anyone who falls for a simulation lands on an awareness page showing them what to look for next time, and a report mailbox credits staff who forward suspicious mail without anyone ticking a box.

Every simulation lands in a per-recipient audit trail that exports as CSV or PDF evidence for ISO 27001 A.6.3, SOC 2 CC1.4 and CC2.2, NIS2 Article 21(2)(g), DORA Article 13(6), PCI DSS 12.6.3.1, HIPAA 164.308(a)(5), GDPR Article 32 and NIST CSF PR.AT-01, or syncs itself into Vanta and Drata.

Other features:

  • App discovery: asks your tenant which applications it federates and who signs in to them, then ranks the lure gallery so the phishing template borrows a brand your staff really use
  • Template and landing page gallery with merge tags, inbox-row and rendered previews, and per-template click rates
  • People and audiences: manual add, CSV import with column mapping, directory sync, bulk actions
  • Domain ownership verification (SSO, DNS TXT record, or mailbox connector) that fences in which addresses a campaign may target and which senders it may present
  • Multi-tenant workspaces with Google and Microsoft Entra SSO
  • Read-only MCP server so Claude, ChatGPT or any MCP client can query a workspace's reporting
  • Reporting: resilience trend, engagement funnel, risk by department, per-template effectiveness

Official Links