Skip to main content
Cybersecurity Awareness Month: New videos, games, and ready-to-use resources

Frequently Asked Questions

Straight answers about Adaptive Security, from what the platform does to how to switch from your current vendor.

59 questions

Security Awareness Training

Security awareness training educates employees on how to recognize and respond to cyber threats — including phishing emails, deepfake video scams, social engineering, and AI-powered attacks. Effective programs combine interactive training modules, real-world simulations, and automated reinforcement to build lasting behavior change across your organization.

Learn more

Most security frameworks recommend at least monthly training touchpoints, with continuous reinforcement throughout the year. Adaptive delivers training automatically based on each employee's risk score and behavioral signals — so employees get exactly the training they need, when they need it, without manual scheduling.

Learn more

Yes. Adaptive is purpose-built for the AI era, with training modules covering deepfake video scams, AI-generated phishing emails, voice cloning (vishing), SMS phishing (smishing), and other modern attack vectors that legacy platforms were never designed to address. Employees can even experience realistic AI deepfake simulations of executives in a safe training environment.

Learn more

Absolutely. Adaptive automatically assigns role-based training modules matched to each employee's job function and risk profile. You can also use the AI Content Studio to generate fully custom training on any topic, company policy, or real-world scenario — then brand every frame, visual, and interaction to match your organization.

Learn more

Phishing Simulations

Connect via API in minutes — no rip-and-replace required. Adaptive integrates with your existing identity, email, and ticketing systems out of the box.

Learn more

Email, SMS, voice (vishing), and multi-channel attack chains — all generated by AI from real OSINT data on your employees.

Learn more

Yes — every element of every simulation is customizable. No locked libraries, no template walls.

Learn more

Per-employee risk scores update in real-time based on simulation outcomes, training completion, reported phish, and other behavioral signals.

Learn more

Adaptive automatically triggers targeted training and follow-ups — no manual workflows or weekly admin chores.

Learn more

Email Security

Adaptive connects to your email environment via API and analyzes every inbound message using layered AI detection — behavioral signals, intent analysis, and LLM reasoning. Threats are quarantined before employees ever see them, and every detected attack feeds back into training and risk scoring.

Learn more

No — Adaptive layers on top of your existing email provider via API. There are no MX record changes, no rip-and-replace, and no migration required. You keep the email platform you already have and Adaptive adds an AI detection layer on top.

Learn more

No. Adaptive integrates via API, not as an inline mail gateway. That means setup takes minutes and there's zero disruption to your mail flow during deployment.

Learn more

Native filters are rule-based and match known patterns. They miss AI-generated attacks because those attacks are novel by design. Adaptive uses behavioral signals and LLM reasoning to catch threats with no known signature — the kind purpose-built for bypassing traditional filters.

Learn more

Adaptive automatically quarantines the email across every affected inbox in your organization. The employee and security team are notified, and the detection signal feeds into the employee's risk score and can trigger targeted training. Every remediation action is fully reversible.

Learn more

Phish Triage

Phish triage is the process of reviewing, classifying, and remediating employee-reported phishing emails. Adaptive's Phish Triage integrates with your reporting method of choice and provides a centralized workspace to review, categorize, and take action on suspicious messages.

Learn more

When an employee reports an email, it is immediately moved to their trash as a default protective action, before the AI even runs. Adaptive's AI engine then analyzes the email's metadata, headers, links, and attachments, and returns a verdict (safe, spam, or malicious) along with a confidence score and explanation of exactly why that decision was made. Security teams configure their own confidence thresholds (between 70 and 100%) to control what gets auto-remediated versus routed to manual review. Teams can also set up allow-lists by email address, domain, or List-ID so known-safe senders are never flagged. When an allow-listed email gets reported, employees receive instant feedback that it's safe.

Learn more

The Phish Alert Button works natively in Gmail, Outlook, and on mobile. For employees on non-standard clients like Superhuman, ProtonMail, Yahoo Mail, or third-party setups, Adaptive also supports reporting via an email forwarding alias, so every employee in your org can report suspicious emails regardless of what email client they use. When a report comes in through any method, Adaptive immediately ingests it for AI analysis and sends immediate feedback on the verdict.

Learn more

Phish Remix lets you turn any employee-reported email into a live phishing simulation. This allows your team to train on actual attacks hitting your inbox, not just templates. When a real threat comes in, you can convert it into a simulation and send it org-wide in seconds.

Learn more

Yes. Every remediation action in Adaptive is fully reversible. If an email is incorrectly classified or you need to undo a cleanup action, you can reverse it instantly. All actions are logged with complete audit trails, so your team maintains visibility and control over everything that happens in the system.

Learn more

No. Adaptive follows a zero data retention policy with its AI providers: reported emails are processed in-memory and discarded immediately after analysis. They are never stored, logged, or used to train AI models. Phish Triage's AI is pre-trained on industry-standard phishing datasets, not on your organization's private email data. The product is also built to GDPR, SOC 2, and HIPAA standards, with all email data encrypted in transit and at rest.

Learn more

AI Governance

Adaptive AI Governance gives security teams visibility and control over how employees use AI tools and software across the browser, including unsanctioned apps and risky behavior. It automatically enforces acceptable use policies with zero tuning, and coaches employees in real time when a violation occurs.

Learn more

Adaptive deploys a lightweight browser extension and device agent to employee devices that captures activity across your organization. The browser extension captures activity like site visits, login attempts, and prompts sent to AI tools, and works across Chrome and Edge. The device agent extends that same visibility onto the desktop, tracking every app and command line tool installed. Both run silently in the background and require no action from employees. Security teams get a full view of which AI tools are in use, by which teams, and how often.

Learn more

The browser extension and device agent are both designed to capture security-relevant signals, not surveil employees. The extension lives silently in the browser's extensions menu and the agent is a service running quietly on the device. Both have no popups and cannot be disabled by users. Activity is only captured in corporate browser profiles and company enrolled devices, not personal ones. The data sent back to Adaptive is structured metadata, not raw content like full page bodies or clipboard text.

Learn more

Yes. AI and shadow IT behavior feeds directly into each employee's Adaptive risk score, so ungoverned AI usage shows up in the same place as phishing simulation results and training completions. When risky behavior is detected, Adaptive can automatically assign targeted training. Governance events can also be forwarded to your SIEM for correlation across your broader security infrastructure.

Learn more

The extension is force-installed via your existing MDM platform. Adaptive supports Intune (Windows), Google Admin, Jamf, and Kandji. Deployment files are provided by the Adaptive team with your company identifier already built in. The extension can't be disabled by end users once deployed.

Learn more

The device agent is force-installed via your existing MDM platform. Adaptive supports Intune, plus a generic installer that works with any other Windows MDM. Installer files and the install command come from Adaptive's admin console, with your company key already built in. The agent can't be disabled by end users once deployed, and runs invisibly in the background.

Learn more

Compliance & Policy Training

Compliance training educates employees on the regulatory frameworks, internal policies, and behavioral standards your organization must meet — covering everything from data privacy (HIPAA, GDPR, CCPA) to financial controls (SOC 2, PCI-DSS, AML) to workplace conduct. Effective programs combine interactive modules, jurisdiction-specific content, and an audit trail that holds up under regulatory review.

Learn more

Adaptive includes pre-built training modules for HIPAA, GDPR, PCI-DSS, CCPA/CPRA, SOC 2, ISO 27001, AML/CFT, NYDFS, and dozens more frameworks. Each module is kept current as regulations evolve, and you can build fully custom modules for industry-specific requirements using the AI Content Studio.

Learn more

Compliance training is available localized in 39+ languages, with jurisdiction-specific tracks built in for states like California, New York, Illinois, Connecticut, and Washington, and countries including the UK, Australia, Netherlands, France, Germany, India, Canada, Brazil, and Singapore. Connect your HRIS and employees are automatically enrolled in the right training for their location on day one.

Learn more

Yes. Every Adaptive module is fully editable — adjust copy, swap visuals, and apply your brand to every frame. For policies and topics not in the standard library, the AI Content Studio generates a fully interactive compliance module from any policy document or regulation text in minutes.

Learn more

Risk Management

Human risk monitoring is the practice of continuously measuring and reducing the security risk posed by employee behavior. Adaptive tracks activity across phishing simulations, training completions, job role exposure, and more, then converts that data into a risk score for every employee, team, and location. Security teams use these scores to prioritize attention, track improvement over time, and report program performance to leadership.

Learn more

Every employee gets a score from 1 (low risk) to 100 (high risk), updated daily. The score is built from four inputs: phishing simulation performance (50%), training completion (25%), job risk based on role, tenure, and application access (25%), and a temporary adjustment for new employees without enough behavioral history yet. You can click into any employee's profile to see exactly what is driving their score and what needs to change.

Learn more

Connect your HRIS once and Adaptive automatically calculates risk scores for every team, office, and custom group. You can see which departments carry the most exposure, how scores are trending over time, and which locations present the highest concentration of risk, without any manual effort.

Learn more

Yes. Every signal Adaptive captures can automatically trigger training, simulations, and remediation actions. When an employee's score crosses a configured threshold, Adaptive can enroll them in targeted training or launch a follow-up phishing simulation. You can also set group-level remediation campaigns for teams or departments that trend high, so the program responds to actual behavior rather than a fixed schedule.

Learn more

Adaptive runs OSINT scans on your executives and high-credential users to surface their publicly available information. It then maps those findings to the specific attack scenarios a bad actor would construct from them. Each executive profile surfaces vulnerability categories like identity theft risk, credential exposure, and deepfake risk, organized by severity. The goal is to show your security team exactly what an attacker already knows about your leadership before they use it.

Learn more

Adaptive includes a library of pre-built risk report templates covering org-wide risk scores, department breakdowns, individual risk, and trend analysis over time. Reports can be customized for your audience, set on a delivery cadence, and sent directly to your CISO's inbox automatically. No logins or manual exports required.

Learn more

Reporting

Adaptive includes pre-built report templates for org-wide risk scores, department breakdowns, individual employee risk, and trend analysis over time. Reports can be exported or delivered automatically to stakeholders.

Learn more

Yes — every report is fully customizable. Tailor the data, layout, and delivery schedule for different audiences: CISOs, HR teams, board members, or department heads.

Learn more

Risk data updates in real time as employees interact with simulations, complete training, and generate new behavioral signals. Reports reflect the most current scores at the time of generation.

Learn more

Adaptive's API lets you pull risk data into any BI platform. We also offer native integrations with common SIEM and GRC tools for automated data syncing.

Learn more

Reports export as PDF, CSV, and JSON. Automated delivery sends reports directly to inboxes on a schedule you define — no logins required for recipients.

Learn more

Access is role-based. Admins can scope report visibility by department, team, or individual — ensuring sensitive risk data is only visible to authorized stakeholders.

Learn more

Deployment

Setup is designed to take a few clicks, not weeks. Adaptive provides hands-on implementation support so your program is running quickly, and the platform integrates with tools like Microsoft and Google Workspace so you do not need to build anything from scratch.

Learn more

Yes. Adaptive automatically enrolls new employees in training as they join, so security awareness is embedded from day one without requiring manual setup from your team each time someone starts. New hires also receive a temporary risk adjustment in the platform until enough behavioral data is collected to establish their baseline.

Learn more

Pricing

Adaptive Security is priced per seat. Fill out the form above to get a custom quote based on your employee count and the products you need. Our team will follow up with a personalized proposal.

Learn more

The platform includes Security Awareness Training (phishing simulations, compliance training library, automated assignments, real-time risk scoring), Email Security (inbound threat detection, attachment scanning, impersonation protection), and AI Governance (shadow AI detection, acceptable use enforcement, data leakage prevention). Products can be purchased individually or bundled.

Learn more

Yes. Book a personalized demo to see the platform in action. Our team will walk you through the capabilities and help build a quote tailored to your organization.

Learn more

Yes. Adaptive consolidates security awareness training, phishing simulations, email security, AI governance, and human risk monitoring into a single platform. Enterprise security teams using separate tools for each of these functions can replace fragmented vendor relationships with one hub that shares data across every product.

Learn more

Integrations

Email, identity & HR

Yes. Adaptive integrates with Microsoft 365, Google Workspace, Slack, and a wide range of identity providers and HR systems. It is designed to fit into an existing stack rather than replace it, and the platform connects to your directory so employee groups stay in sync automatically.

Learn more

Security tools

Yes, Adaptive can send verdicts and relevant context to supported downstream security workflows through integrations.

Learn more

Compliance

Yes. Adaptive includes a library of pre-built HIPAA training modules covering topics like covered entities, hybrid entities, and end-user obligations. Modules are branded to your organization, short enough to fit a clinical schedule, and automatically assigned by role so a nurse and a billing clerk aren't sitting through the same content.

Learn more

Adaptive supports onboarding and recurring awareness training, phishing simulations, and completion reporting. PCI DSS v4.0.1 Requirement 12.6.3 calls for training at hire and at least annually, while 12.6.3.1 includes phishing and related social engineering. Your organization remains responsible for the full requirement, including program review and policy acknowledgment.

Learn more

Security & privacy

Adaptive Security’s Trust Center lists a SOC 2 Type II report available by access request. Review the report for the auditor’s opinion, assessment period, and systems covered. A report request link is not a substitute for reviewing the report’s scope.

Learn more

An attestation covers the systems and services named in its report, not automatically every product. Use the product index on this page to understand supported compliance activities, then request the SOC 2 report and confirm the scope for the products you plan to use.

Learn more

Support

Adaptive provides hands-on implementation support from day one, custom requests for training content and phishing simulations, real-time personalized support, and early access to new products and features. The goal is a program that is running and delivering results quickly, not a lengthy onboarding process.

Learn more

No. Adaptive is designed to run with minimal oversight. Training campaigns, phishing simulations, and reporting are all automated once configured, so the platform handles delivery and follow-up without requiring a dedicated security team. A single person can operate Adaptive at enterprise scale. Hands-on support is included from day one for setup, custom requests, and ongoing questions.

Learn more

Switching vendors

Adaptive is designed for fast deployment through a direct API connection, with no MX record changes or month-long rollout. Teams can add Adaptive to their existing Microsoft 365 or Google Workspace environment without taking on a traditional gateway migration.

Learn more

Adaptive deploys through a direct API connection in minutes, with no MX record changes or month-long gateway rollout. Teams can protect inboxes from one clean console without the deployment and ongoing administration associated with a traditional secure email gateway.

Learn more

Adaptive Security is transparently priced — get a custom quote in minutes with the form above. Unlike legacy platforms that require multi-year enterprise negotiations, Adaptive offers straightforward per-seat pricing. Contact our team to compare.

Learn more

Human and agent security for the AI era.