Per-target phishing simulations generated on Bedrock and independently reviewed by a second Claude endpoint before anything is queued, with HR data treated as untrusted input and every prompt and response written to an audit log.
An MSSP offering security awareness training needed to move past static phishing templates that sophisticated employees recognized on sight. The employees who are genuinely susceptible are often susceptible to entirely different lure types than a generic template targets.
Producing contextually personalized simulations that adapt to each user's actual susceptibility pattern requires a generative model at the core. No template library can produce that. What it also requires is a safety architecture, because the system's job is to generate convincing phishing email.
Each stage below is a real component in the deployed pipeline. Stages outlined in teal are control points: the places where the architecture constrains what the model can receive or emit.
Primary campaign generation engine producing personalized phishing simulations per target role profile.
Independent safety-check call evaluating each generated email for out-of-scope content before it is queued for delivery.
Pulls job title, department, and role context per simulated target to build the generation profile.
Stores click and report rates per user per campaign, feeding back into the profile for next-cycle adaptation.
Orchestrates the generation, review, approval-gate, and queuing pipeline for each campaign run.
Records the exact prompt and Claude response for every generated campaign email before any downstream action.
Guardrails were designed in from the start, not added after the fact. Where the system touches untrusted input, a control sits between that input and the model.
No production AI system is finished. These are the live risks carried by this architecture, documented for the operating team rather than buried.
On numbers. Client identity and any identifying detail are withheld under NDA. Outcomes are stated as direction and materiality rather than as figures we are not free to publish.
Most engagements start with a short, paid R&D sprint so both sides can decide if it is a fit. If we are not the right call, we will say so early.