Acceptable Use Policy
Last updated September 20, 2026
This Acceptable Use Policy ("AUP") sets the operational rules for every organization that uses phish.co's phishing, smishing, and vishing assessment service (the "Service"). It is part of, and incorporated into, our Master Services & Authorized-Use Agreement and Terms of Service; where a term is defined there, it has the same meaning here. If those documents and this AUP conflict on acceptable use, the stricter provision applies. This AUP is written for the customer organization; if you received an assessment and want the plain-language explanation, see Responsible Use instead.
What you may do
- Run simulated phishing (email), and — where enabled and attested — smishing (SMS) and vishing (voice) assessments against your organization's own current employees and contractors.
- Target only domains your organization has verified it controls through the Service.
- Use generic or fictitious senders, brands, and scenarios that resemble the kinds of messages real attackers send.
- Use the aggregate and per-target results to run and improve your own security-awareness program.
What you must not do
People and scope
- Target anyone outside your own verified workforce — including former employees, customers, prospects, vendors, partners, or the public. This is enforced by the Service and is also an absolute contractual prohibition.
- Run assessments you lack the organizational authority to authorize.
- Use the Service on behalf of, or as a service to, a third party except under a separate written agreement with us.
Content
- Impersonate a specific real person, brand, company, government agency, or other authority, or use a real third party's trademarks, logos, or identity so a message appears to genuinely come from them.
- Build or send content that mimics clinical, electronic-health-record, or other HIPAA-regulated portals, or that solicits protected health information.
- Include unlawful, harassing, discriminatory, or gratuitously distressing content, or content designed to cause real-world harm rather than a measured, disclosed simulation.
Data
- Attempt to capture, reconstruct, or exfiltrate the real values a person enters into a simulated page (passwords, financial account numbers, government identifiers, or other sensitive data). The Service is built never to store these; do not attempt to circumvent that design.
- Use the Service to collect real regulated data of any kind.
Channels
- Enable SMS without making the required TCPA/state-law attestation and holding the consent or authorization it represents. Prefer company-issued or company-managed numbers.
- Enable full voice-audio capture unless you operate only in one-party-consent jurisdictions or have independently obtained all-party consent. The default is metadata-only, no audio.
The Service itself
- Probe, scan, overload, disrupt, or reverse-engineer the Service or its infrastructure, or try to reach another customer's data or break tenant isolation.
- Share sign-in links or credentials, or let anyone not bound by these terms use your account.
Reporting misuse
If you believe the Service is being misused — by your own organization or anyone else — tell us at hello@phish.co. If you received a message you think is a phishing simulation and have questions, Responsible Use explains what to do.
Enforcement
We may investigate suspected violations and may suspend or terminate access — with or without notice, depending on severity — for any breach of this AUP, in addition to any other remedy available to us under the Master Services & Authorized-Use Agreement. We may also restrict or remove template categories that fall outside the Service's intended, lawful scope.
Changes
We may update this AUP from time to time and will post the updated version here with a new date. Continued use after changes take effect means you accept them.
Contact
Questions about this policy: hello@phish.co.