Run realistic phishing simulations using a library of up-to-date attack templates — CEO fraud, invoice scams, IT helpdesk, credential harvesting, and smishing. Campaigns are personalised per employee using their name, department, and role.
When an employee clicks a phishing link, they're immediately redirected to a targeted training module explaining what they missed and why. Training adapts to each employee's specific failure pattern — not generic compliance videos.
Every employee gets a Human Risk Score based on simulation performance, training completion, and reporting behaviour. CISOs get a clear view of the riskiest employees, departments, and locations at a glance.
Access training modules covering phishing, password hygiene, social engineering, ransomware, data handling, and insider threats. Content is available in English, Hindi, Tamil, Telugu, and other regional languages.
One-click phishing report button for Outlook, Gmail, and mobile. Employees who correctly report simulations earn points and recognition — creating a positive security culture rather than a blame culture.
Generate security awareness compliance reports for ISO 27001, DPDP Act, RBI IT Framework, and SEBI CSCRF — with click rates, training completion rates, and improvement trends over time.
Sync employees from Active Directory, Google Workspace, or Okta in minutes. Gordon automatically groups employees by department, role, and location for targeted campaign design.
Select from 50+ phishing templates or create custom ones. Gordon schedules campaigns automatically, randomises send times to avoid detection, and tracks every click, credential submission, and report.
Employees who fail receive an immediate, personalised training module. Gordon tracks completion, sends reminders, and escalates to managers if training is not completed within the SLA.
Monitor click rates, training completion, and risk scores over time. Generate compliance reports for your board, auditors, and regulators — showing measurable improvement in human risk posture.
A private bank with 3,200 employees needed to demonstrate security awareness training for RBI's IT Framework. Their existing annual training had 34% click rates on simulations.
After 90 days of Gordon's adaptive simulations, click rates dropped to 6%. RBI inspection passed with zero findings on awareness training. Board received monthly risk score dashboards.
An IT services firm had suffered two Business Email Compromise (BEC) incidents in 12 months, losing ₹48 lakhs. Their finance team was the highest-risk group.
Gordon ran targeted CEO-fraud simulations for the finance team. After 6 weeks, the team's risk score improved from 28 to 81. Zero BEC incidents in the 18 months since deployment.
A hospital chain needed to train 1,800 staff on data protection under India's DPDP Act — including doctors, nurses, and administrative staff with varying levels of tech literacy.
Gordon delivered role-specific training in Hindi and English, with 5-minute modules designed for non-technical staff. 94% completion rate in 30 days. Full DPDP training documentation generated automatically.
Choose the plan that fits your team. Upgrade or cancel anytime.
For growing companies up to 100 employees. Core security, GRC, and insurance in one platform.
Start Free TrialFor companies with 100–500 employees. Expanded limits across all modules.
Start Free TrialFor large enterprises 500+ employees. Unlimited scale, dedicated support, and custom SLAs.
Talk to Sales| Features | Free | Startup $1,787/mo |
Mid-Market $3,382/mo |
Enterprise $6,607/mo |
|---|---|---|---|---|
| ▶Attack Surface Monitoring12 scans/year | ||||
| Monitored Assets (Domains, IPs, Mobile Apps) | — | 1 asset | 3 assets | 10 assets |
| Exposed subdomains & open ports | — | ✓ | ✓ | ✓ |
| SSL/TLS certificate health | — | ✓ | ✓ | ✓ |
| DNS anomalies & misconfigurations | — | ✓ | ✓ | ✓ |
| Web technology fingerprinting | — | ✓ | ✓ | ✓ |
| CVE & vulnerability scoring | — | ✓ | ✓ | ✓ |
| Continuous monitoring & alerts | — | ✓ | ✓ | ✓ |
| ▶SOC Monitoring24/7 | ||||
| Monitored Endpoints | — | Upto 100 | Upto 500 | Upto 2,000 |
| AI-powered alert triage | — | ✓ | ✓ | ✓ |
| Kill-chain reconstruction (MITRE ATT&CK) | — | ✓ | ✓ | ✓ |
| Automated response playbooks | — | ✓ | ✓ | ✓ |
| CERT-In 6-hour incident reporting | — | ✓ | ✓ | ✓ |
| Threat intelligence (IOCs, Campaigns) | — | 10 threats, 5 IOCs | 50 threats, 20 IOCs | Unlimited |
| ▶Workforce Risk & Security Awareness | ||||
| Monitored Employees | — | Upto 100 | Upto 500 | Upto 2,000 |
| Email phishing simulation | — | ✓ | ✓ | ✓ |
| Custom phishing templates | — | ✓ | ✓ | ✓ |
| Security awareness training + LMS | — | ✓ | ✓ | ✓ |
| ▶Dark Web Monitoring | ||||
| Monitored Keywords (brand, legal name, vendors) | — | 1 keyword | 1 keyword | 5 keywords |
| Tor forums, paste sites, Telegram channels | — | ✓ | ✓ | ✓ |
| Breach databases & data dumps | — | ✓ | ✓ | ✓ |
| Ransomware & APT group monitoring | — | ✓ | ✓ | ✓ |
| ▶Cloud Security & Billing Monitoring | ||||
| Cloud Instances Monitored | — | 1 instance | 2 instances | 5 instances |
| Misconfiguration detection (CIS 572 benchmark) | — | ✓ | ✓ | ✓ |
| IAM & privilege escalation checks | — | ✓ | ✓ | ✓ |
| S3 / Blob public exposure alerts | — | ✓ | ✓ | ✓ |
| Cloud billing tracking & optimisation | — | ✓ | ✓ | ✓ |
| ▶GRC & ComplianceAudit charges extra | ||||
| Compliance Frameworks | — | 2 frameworks | 4 frameworks | 5 frameworks |
| Automated control mapping | — | ✓ | ✓ | ✓ |
| AI gap assessment & remediation tasks | — | ✓ | ✓ | ✓ |
| Policy & procedure auto-generation | — | ✓ | ✓ | ✓ |
| Risk register automation | — | ✓ | ✓ | ✓ |
| AI-based internal audit & audit-ready reports | — | ✓ | ✓ | ✓ |
| Trust center | — | ✓ | ✓ | ✓ |
| ▶Third Party Risk Management (TPRM) | ||||
| Vendors Monitored | — | 100 vendors | 250 vendors | 1,000 vendors |
| AI security questionnaire dispatch & scoring | — | ✓ | ✓ | ✓ |
| Continuous external surface scan | — | ✓ | ✓ | ✓ |
| Breach & dark web alerts for vendor | — | ✓ | ✓ | ✓ |
| Risk rating (A–F) with trend | — | ✓ | ✓ | ✓ |
| ▶Gordon AI | ||||
| AI Credits / Tokens | — | 500 credits | 1,000 credits | 1,000 credits |
| Auto-generated risk narratives | — | ✓ | ✓ | ✓ |
| One-click remediation playbooks | — | ✓ | ✓ | ✓ |
| Executive summary generation | — | ✓ | ✓ | ✓ |
| AI-assisted questionnaire filling (CRQ) | — | ✓ | ✓ | ✓ |
| Threat intelligence summaries | — | ✓ | ✓ | ✓ |
| ▶Brand Intelligence & Takedowns | ||||
| Brand Assets Monitored | — | 1 asset, 20 keywords | 3 assets, 60 keywords | 5 assets, 100 keywords |
| Fake domain / phishing page / typosquat monitoring | — | ✓ | ✓ | ✓ |
| Reverse imaging / logo detection | — | ✓ | ✓ | ✓ |
| Social media & counterfeit listing monitoring | — | ✓ | ✓ | ✓ |
| Takedowns (Rogue app, DMCA, Phishing pages) | — | 25 takedowns | 100 takedowns | 125 takedowns |
| ▶Consent Manager (DPDPA) | ||||
| Unique Consents (website / mobile app users) | — | 25K consents | 100K consents | 500K consents |
| Granular consent collection & withdrawal | — | ✓ | ✓ | ✓ |
| 15+ platform integrations | — | ✓ | ✓ | ✓ |
| 22 Indian language translation (DPDPA Art. 18) | — | ✓ | ✓ | ✓ |
| Cookie scanner, data deletion & grievance requests | — | ✓ | ✓ | ✓ |
| Google Consent Mode V2 support | — | ✓ | ✓ | ✓ |
All plans include a 15-day free trial — no credit card required.
91% of breaches start with a human. Make sure yours are trained, tested, and ready. Start a free phishing simulation today.