Acceptable Use Policy

Last updated September 20, 2026

This Acceptable Use Policy ("AUP") sets the operational rules for every organization that uses phish.co's phishing, smishing, and vishing assessment service (the "Service"). It is part of, and incorporated into, our Master Services & Authorized-Use Agreement and Terms of Service; where a term is defined there, it has the same meaning here. If those documents and this AUP conflict on acceptable use, the stricter provision applies. This AUP is written for the customer organization; if you received an assessment and want the plain-language explanation, see Responsible Use instead.

The one rule everything else follows from: the Service may be used only to assess your own organization's verified workforce, under proper authority, and never to deceive, harm, or collect real sensitive data from anyone. The Service enforces the "own verified workforce" part on every send; the rest is on you.

What you may do

What you must not do

People and scope

Content

Data

Channels

The Service itself

Reporting misuse

If you believe the Service is being misused — by your own organization or anyone else — tell us at hello@phish.co. If you received a message you think is a phishing simulation and have questions, Responsible Use explains what to do.

Enforcement

We may investigate suspected violations and may suspend or terminate access — with or without notice, depending on severity — for any breach of this AUP, in addition to any other remedy available to us under the Master Services & Authorized-Use Agreement. We may also restrict or remove template categories that fall outside the Service's intended, lawful scope.

Changes

We may update this AUP from time to time and will post the updated version here with a new date. Continued use after changes take effect means you accept them.

Contact

Questions about this policy: hello@phish.co.