Master Services & Authorized-Use Agreement
Last updated September 20, 2026
This Master Services & Authorized-Use Agreement (the "Agreement") governs your organization's use of phish.co's phishing, smishing (SMS), and vishing (voice) security-assessment service (the "Service"). It is entered into between phish.co, a service of Fulcrum LLC ("phish.co," "we," "us," or "our") and the organization that creates an account and accepts this Agreement ("Customer," "you," or "your"). It works alongside our Terms of Service, Acceptable Use Policy, Privacy Policy, and Data Processing Addendum; where this Agreement and the Terms of Service address the same subject, this Agreement controls for the authorized-use and campaign-conduct terms.
By creating an account, accepting this Agreement, or running any campaign, the individual doing so represents that they are authorized to bind the Customer, and the Customer agrees to this Agreement. If you do not agree, do not use the Service.
1. The Service, in brief
phish.co is a subscription software service that lets your organization run simulated phishing, smishing, and vishing assessments against your own workforce, to measure and improve their ability to recognize and report real attacks. The Service is designed so that a campaign can only ever reach people at a domain your organization has verified it controls; that restriction is enforced by the software on every send, not by policy alone. See Responsible Use for the plain-language description of how this works.
2. Customer warranties — the core of this Agreement
Simulated social-engineering is a serious capability. This section is the heart of what you are agreeing to. Each time you create an account, configure a campaign, or authorize a send, you represent and warrant, on behalf of the Customer, that:
2.1 Own workforce only
You will use the Service to target only your organization's own current employees and contractors, at one or more domains your organization has verified ownership of through the Service. You will never use the Service to target any person outside your own organization — including former employees, customers, prospects, vendors, partners, or any member of the general public.
2.2 Organizational authority
You hold the organizational authority to authorize security-awareness testing of the people you target, whether that authority derives from your role, your organization's policies, or an internal delegation. You are responsible for ensuring the right people within your organization have approved the testing program.
2.3 Internal notice
You have given, or will give, internal notice consistent with your own organization's policies — for example, an acceptable-use or security-awareness policy informing staff that periodic assessments occur. This is a general notice that assessments happen, not advance warning of any specific campaign, which would defeat the purpose of the test. Where your workforce includes people in jurisdictions that require a documented legal basis for processing (for example, an employer's legitimate-interest assessment under the GDPR), you are responsible for maintaining that basis; the consent/authorization question sits at the organization level, not at per-employee, per-message consent.
2.4 Channel-specific consent and law
- SMS (smishing). The SMS channel is off by default. Where you enable it, you are solely responsible for obtaining whatever consent or authorization the Telephone Consumer Protection Act (TCPA) and any applicable state law require before messaging the numbers you enroll, and for confirming this via the in-product attestation. You will strongly prefer company-issued or company-managed numbers; targeting personal devices is a distinct, higher-risk choice you make knowingly.
- Voice (vishing). The voice channel defaults to metadata-only capture (whether a call connected, whether a scripted prompt was followed) with no audio recording of the target. Where you enable full call-audio capture, you are solely responsible for confirming that your organization operates only in one-party call-recording-consent jurisdictions, or that you have independently obtained all-party consent where required.
2.5 Rules-of-engagement attestation
For campaigns that present a data-entry (simulated login or form) landing page, and before such a send, you will complete the in-product rules-of-engagement confirmation — which shows the exact target count and verified domain(s), requires explicit confirmation, and is logged. Your acceptance of the current rules-of-engagement policy version is a condition of running these campaigns, and a revised policy version requires re-acceptance.
3. Permitted use
Subject to this Agreement, you may use the Service to design, schedule, and run authorized simulated assessments against your verified workforce; to view aggregate and per-target engagement results (for example, whether a message was opened, clicked, submitted-to, or reported); and to use the resulting reporting to run your own security-awareness program. You may grant access to your own personnel who are bound by obligations at least as protective as this Agreement.
4. Prohibited use
You will not, and will not permit anyone to, use the Service to:
- Target anyone outside your verified, authorized workforce — the prohibition in section 2.1 is absolute and is enforced by the Service on every send.
- Impersonate a real third party. You will not create content that impersonates a specific real person, brand, company, government body, or other authority, or that uses a real third party's trademarks, logos, or identity in a way that suggests the message genuinely comes from them. Simulations use generic or fictitious senders and scenarios.
- Handle regulated or clinical content. You will not use the Service to build or send content that mimics clinical, electronic-health-record, or other HIPAA-regulated portals, or that solicits protected health information. The Service is designed to stay structurally clear of HIPAA-regulated data; we do not offer and will never sign a Business Associate Agreement.
- Harvest real credential or sensitive values. You will not attempt to use the Service to capture the actual values a person types into a simulated page — real passwords, financial account numbers, government identifiers, or other sensitive data. The Service is built never to store these (see section 6); you will not attempt to circumvent that design.
- Use the Service for any unlawful, infringing, harassing, or harmful purpose beyond the authorized-use terms above; or to cause real financial loss, data exfiltration, or system compromise as opposed to a measured, disclosed simulation.
- Probe, interfere with, overload, reverse-engineer, or attempt to gain unauthorized access to the Service, its infrastructure, or any other customer's data; or resell or provide the Service to third parties except as expressly permitted in writing.
We may suspend or terminate, without notice, any account we reasonably believe is being used outside a verified, authorized engagement or in violation of this section, in addition to any other remedy available to us.
5. Acceptable content
You are responsible for the content of the campaigns you create. Content must be consistent with a good-faith security-awareness assessment of your own workforce and must comply with section 4. Certain template categories are restricted or denied by the Service by design — most notably clinical/EHR-style templates, consistent with the HIPAA-avoidance rule above. We may add, withhold, or remove template categories to keep the Service within its intended, lawful scope.
6. Data handling and compliance-by-design
Compliance is built into how the Service works, not bolted on afterward:
- We never store submitted credential or form values. If a person enters data into a simulated landing page, the Service records only that a submission occurred (a boolean and a timestamp) — never the values entered. There is deliberately no field anywhere in the Service for a submitted credential or sensitive value, the same way we never store the payload of a click.
- Structured interaction data only. Engagement is recorded as structured states (for example, clicked / did-not-click, submitted / did-not-submit, reported), not freeform captured text, wherever the product can.
- Immediate disclosure. A person who submits to a simulated data-entry page is shown that it was a simulation immediately after they submit.
- No cross-tenant pooling. Identifiable interaction data is not pooled across customers; tenant isolation is a hard invariant of the Service.
Because a campaign necessarily processes personal data about your employees, phish.co acts as a processor and you act as the controller for that data. Roles, sub-processors, retention, and security are described in our Privacy Policy, Security overview, and Data Processing Addendum.
7. Fees
The Service is offered on subscription plans billed through our payment processor, with metered add-ons for SMS and voice usage on paid tiers. Prices, tiers, and billing intervals are shown at checkout and in our Terms of Service; cancellation and refund treatment is described in the Refund & Cancellation Policy.
8. Indemnification
You will defend, indemnify, and hold harmless phish.co and Fulcrum LLC from and against claims, damages, and costs arising out of your breach of the customer warranties in section 2, the prohibited-use terms in section 4, or your use of the Service to target any person you were not authorized to target. This indemnity runs one way: phish.co has no reciprocal obligation to indemnify you, including for any intellectual-property claim. phish.co will notify you promptly of any claim for which it seeks indemnification, and you will have sole control of its defense and settlement, except that any settlement imposing a non-monetary obligation or an admission of fault on phish.co requires phish.co's prior written consent; phish.co may participate in the defense at its own expense.
9. Warranties and disclaimers
The Service is provided "as is" and "as available," without warranties of any kind, express or implied, to the maximum extent permitted by law. A simulated assessment cannot guarantee any particular security outcome; you remain responsible for your own organization's security posture and decisions.
10. Limitation of liability
To the maximum extent permitted by law, neither party is liable for indirect, incidental, special, or consequential damages. Given the nature of authorized security testing, phish.co accepts no liability for any misuse of the Service — including any use of the Service to target a person you were not authorized to target, or any other breach of the customer warranties in section 2 or the prohibited-use terms in section 4.
11. Term and termination
This Agreement applies for as long as you have an account or use the Service. You may stop using the Service and cancel at any time, as described in the Terms of Service. We may suspend or terminate access for violation of this Agreement — including the customer warranties (section 2) and the prohibited-use terms (section 4) — with or without notice depending on the severity of the violation. Provisions that by their nature should survive termination (including sections 4, 6, 8, 9, 10, and this sentence) survive.
12. Governing law
This Agreement is governed by the laws of the United States and the State of Louisiana, without regard to conflict-of-law rules. Any dispute arising out of or relating to this Agreement will be brought exclusively in the courts located in the State of Louisiana, and each party consents to the jurisdiction of those courts.
13. Changes
We may update this Agreement from time to time. If we make material changes we will post the updated Agreement here with a new date and, where the change is material to your obligations, seek renewed acceptance. Continued use after changes take effect means you accept them.
14. Contact
Questions about this Agreement: hello@phish.co.