Phish your team
before someone else does.
A security-awareness training platform built on realistic email, text & phone-call simulations that show you exactly who takes the bait, and turn your team from your weakest link into your last line of defense.
Launch a campaign in minutes · Email · SMS · Voice · No security team required
Everyone who slipped up got a friendly "this was just a test" note. No real passwords stored, and now you know who to help.
How it works
Three steps. No security team required.
Most security-awareness platforms are built for enterprise security departments. phis3d is built for the person who just needs to know whether their team would click or pick up the phone, and prove they're getting better.
Import your team
Drop in a CSV of names, emails, and phone numbers, or sync a group. Verify your domain once so we know they're yours to test.
Launch a campaign
Pick a realistic template, choose email, SMS, voice call, or all three, and schedule it. phis3d sends each person a uniquely tracked lure automatically.
See who clicked
Watch opens, clicks, and credential submissions land in real time. Everyone who falls for it gets a friendly 'this was a test' reveal.
Why now
Your people are the attack surface.
Firewalls and EDR keep getting better, so attackers go around them, straight to your employees' inboxes and phones. The only way to find out who'd click is to safely click first.
Most breaches
start with a human clicking a link, not a software exploit.
Text & voice attacks surge
Smishing and AI-voice vishing slip past the email filters most tools stop at.
Insurers & auditors
increasingly require documented security-awareness testing.
Email · SMS · Voice
Most tools stop at email. Attackers don't.
Real attacks come by text and phone too: fake delivery notices, MFA prompts, and an "IT support" call asking you to reset your password. phis3d runs the same realistic simulations across email, SMS, and voice, so you test how your team actually gets targeted.
- ✓Realistic email lures with per-recipient tracking links
- ✓SMS / smishing campaigns sent to mobile (where filters don't help)
- ✓Voice / vishing calls with scripted lures that test who complies
- ✓Track delivered → opened → clicked → credentials → who talked
- ✓A clear 'this was a training test' reveal, never a real password stored
📧 IT Help Desk
Your password expires today, re-verify to keep access
lure · email · click tracked
💬 +1 (415) 555-0142
[FedEx] Your package is held. Confirm address: hxxp://…
lure · sms · click tracked
📞 Incoming call · "IT Support"
"We flagged your account, read me the code we just texted…"
lure · voice · response tracked
Awareness training that people actually remember
A video everyone clicks through once a year doesn't change behavior. Getting safely caught, and seeing the reveal, does.
Compliance
Half your compliance checklist already says "train your people."
Nearly every major security framework requires ongoing security-awareness training, and several now name phishing and social engineering explicitly. Running documented phishing simulations is one of the clearest ways to prove that control to an auditor or insurer.
PCI DSS v4.0
Card payment handlersSecurity awareness at hire + annually. v4.0 explicitly adds phishing & social engineering (req. 12.6.3.1).
HIPAA Security Rule
Healthcare & associatesA security awareness & training program for the entire workforce (§164.308(a)(5)).
SOC 2
SaaS & service orgsAuditors expect documented, recurring security-awareness training (CC1.4 / CC2.2).
ISO/IEC 27001:2022
Certified organizationsInformation-security awareness, education & training for all staff (Annex A 6.3).
GLBA · FTC Safeguards
Financial institutionsSecurity-awareness training for all personnel handling customer data (16 CFR 314).
NYDFS 23 NYCRR 500
NY financial servicesAnnual cybersecurity training that must cover social engineering & phishing (§500.14).
CMMC 2.0 / NIST 800-171
DoD contractorsSecurity-awareness training, including recognizing & reporting threats (AT controls).
Cyber insurance
Most policyholdersCarriers increasingly require awareness training + phishing simulations for coverage.
Awareness training is broader than phishing, and phis3d isn't legal or compliance advice, but simulations with click-through tracking and reporting give you the documented, repeatable evidence these frameworks ask for. Confirm the specifics that apply to your organization.
Pricing
Simple per-employee pricing.
Pay for the people you test. The more employees, the lower the rate. Founding customers get 50% off their first year.
$200/mo founding 50% off
$300/mo founding 50% off
Volume pricing: the more employees, the lower the per-employee rate. Founding-customer discount applies to your first year.
Starter
Email phishing simulations for a small team.
- 1-9 employees$10/ea
- 10-49 employees$8/ea
- 50-99 employees$6/ea
per employee / month
- ✓Realistic email phishing simulations
- ✓Open, click & credential tracking
- ✓“This was a test” reveal pages
- ✓Click-rate reporting by person & team
- ✓Domain verification & consent controls
Pro
Email, SMS + voice, automated, audit-ready.
- 1-9 employees$15/ea
- 10-49 employees$12/ea
- 50-99 employees$9/ea
per employee / month
- ✓Everything in Starter
- ✓SMS / smishing simulations
- ✓Voice / vishing call simulations
- ✓Automated recurring campaigns
- ✓Repeat-clicker tracking
- ✓Compliance-ready reports (auditor / insurer export)
Business / MSP
For 100+ employees and resellers.
Custom
- ✓Everything in Pro
- ✓100+ employees
- ✓White-label & multi-org (for MSPs)
- ✓SSO & API access
- ✓Priority support
Every plan includes reveal pages, domain verification, and consent controls. Cancel anytime.
Find out who'd click before an attacker does.
Drop your work email and we'll get you set up with your first phishing test, including a free baseline for your team.