Free · vendor-neutral · about 5 minutes
See your program the way an attacker sees your company.
Type a domain. We read what's public, show you what it hands an attacker, then ask 10 questions about what actually happens inside your program. No login, no install.
What the audit checks
The PsySec (psychological security) Program Audit measures a security awareness program, never the People in it.
Pass one reads what is already public about your company, the same way an attacker would before writing a first email. Pass two asks ten questions about what happens inside the Program. The reveal scores eight areas out of 100 (belief and culture, training design, Simulation as reinforcement, reporting and recognition, manager involvement, measurement, compliance fit, and AI and deepfake readiness), maps your answers to the frameworks you confirm, and lists your top three moves for the next 30, 60 and 90 days, then exports to a PDF.
- Email spoofing. Whether your email authentication records (SPF, DKIM and DMARC, the public DNS entries that tell other mail servers who may send as you) let a stranger send mail as you.
- Lookalike domains. Which domains that resemble yours already exist and can send mail.
- Authority and trust map. Which roles, approvers and login pages your public site hands to someone writing a pretext (the cover story behind a scam). Roles only, never names.
- Reporting door. Whether an outsider has a clear place to tell you someone is impersonating you: a security.txt file (a standard contact file security researchers look for) or a report address.
- Ten questions about the Program. What a Person gets back after reporting, what happens after a click, whether training comes before Simulations, and who is excused.
Each public finding maps onto the six pressure tactics of social engineering: urgency, scarcity, trust, helpfulness, authority and social proof. The scan is passive, the results are vendor-neutral, and no names are collected. Read how the scan works and what it never does.
Frequently asked questions
- Does the scan touch my systems?
- No. It reads public web pages, public DNS records, and public certificate logs. It never logs in, scans ports, or sends email.
- Does it name employees?
- Never. Roles only, and the results describe the program, not people.
- Is it free?
- Yes. The audit and the on-screen results are free with no login. We ask for an email to send the PDF.
- Is it legal advice?
- No. The compliance table cites each requirement and shows the date we last verified it, but check with your auditor.
- Does it work if we don't use Hook?
- Yes. The recommendations name practices, not vendors.