Tenant sending profiles
Keep sender identities and encrypted gateway credentials isolated to the customer workspace.
Run tenant-controlled email exercises with safe content, measurable participant journeys, authenticated delivery callbacks, debriefs and SIEM-ready events.
A click alone does not explain whether the employee recognized the scenario, continued toward an unsafe decision, reported it, replied, encountered a security scanner or learned from the debrief. Deceptiment records a broader event timeline while separating known automated email-security activity from human behavior.
Campaign owners can work with reusable templates and audiences, safe HTML composition, personalization variables, plain-text fallback, A/B variants and review-required recurring drafts. Tenant-owned sender configurations remain isolated and use encrypted credentials.
Public landing and debrief experiences are intentionally credential-free. They can measure intent and continuation without receiving passwords, codes, payment data or other sensitive information.
Keep sender identities and encrypted gateway credentials isolated to the customer workspace.
Review sender configuration and SPF, DKIM and DMARC readiness before production delivery.
Use sanitized HTML, live preview, personalization variables, plain-text fallback and inert artifacts.
Require customer authorization, safety approval, a successful test and a safe landing experience before launch.
Correlate provider events to the exact participant through opaque tokens and authenticated callbacks.
Connect each participant journey to debriefing, campaign results, operational events and reporting.
Real social-engineering attempts often move between channels. An email may introduce an urgent issue, provide a meeting invitation or establish a request that later continues through WhatsApp or Microsoft Teams voice. Deceptiment’s platform evidence model allows security teams to view email alongside its governed voice-assessment channels.
That does not mean every campaign must be multi-channel. A focused email assessment remains useful when the control objective is reporting, safe-link handling, supplier verification or response to an apparent executive request.
No. Credential and sensitive-data collection are prohibited; the safe experience measures intent without accepting those values.
Known email-security scanner activity is excluded from participant analytics while remaining available for troubleshooting.
The documented workflow includes A/B content variants, participant journey metrics and variant comparisons.
Email events enter the central operational stream, which supports export, HTTP forwarding and a configured pull API.
Review campaign design, safe interaction controls, reporting and integration.
Book a platform demonstration →