Security awareness training built for US compliance requirements
Brightside AI runs AI-powered phishing, vishing, and deepfake simulations, then turns the results into audit-ready training records and risk reporting your compliance team can stand behind.
Teams loved our cybersecurity solution:
...and more.
Automated campaign setup
Launch complex phishing and vishing simulations in minutes. Let AI help you build attack simulations or build manually.
Risk reporting
Track aggregate click rates, credential submissions, and organizational risk trends by department.
NIST phish scale compliant
Align email simulations with the NIST difficulty model for structured, progressive employee training.
Gamified learning
Replace boring annual compliance content with short, interactive modules that turn failures into structured learning opportunities.
Run realistic AI vishing tests
Use live voice agents that adapt to employee responses in real time. Set caller personas, clone approved voices, and combine email and phone scenarios with full transcripts for review.
Call us & start trial
Launch campaigns faster
Turn a training goal into a tailored campaign across email and voice. Generate scripts, choose attack strategies, and match vendor impersonation templates to the risks your workforce faces.
Call us & start trial
Match training to employee risk
Use role, tools, location, tenure, and language to select relevant scenarios for each employee. Scale difficulty from basic credential tests to NIST Phish Scale-aligned spear phishing as awareness improves.
Call us & start trial
Enterprise integrations
Pre-built integrations with Google Workspace, Microsoft 365, Okta, and Vanta enable rapid deployment and automated user provisioning. Custom HR system connectors are available on demand, and 36+ integrations are coming soon.


Employee reporting
Brightside report phishing
Awareness is only half the control. The reporting add-on turns what an employee notices into a logged, timestamped event your security team can act on and your auditors can see.
Reporting that fits the way people already work
The add-on sits in the Gmail side panel, where employees already read their mail. Flagging something suspicious takes a single click, with nothing to forward, attach, or write up, which is what keeps reporting rates from collapsing after the first month.
Measured response times, not guesses
Each report is scanned for malware and classified on arrival, then handed to your security team as the original message with every header intact. Because the handoff is automatic, the interval between an employee noticing an attack and your team seeing it becomes something you can measure and improve.
A metric worth putting in front of leadership
Click rate tells you how many people failed. Report rate tells you how many people acted, and it is the number that moves once training starts working. Both sit in the same per-employee record as course completions, so a rising report rate becomes evidence your program is doing its job.
Scoped to the minimum access Gmail allows
The add-on can only see the one message an employee chooses to report, and only at the moment they report it. It cannot read the rest of the mailbox, send mail, or alter the inbox. Full details are in our privacy policy.
Scalable plans
Plans for every organization size
Start free and scale with flexible pricing. Prices are shown in US dollars, per seat.
Let's talk enterprise solutionsStart
Free
Plan features:
- Courses.
Basic
from $0.59/ mo. per seat
Plan features:
- Courses.
- Template simulations.
Pro
from $1.49/ mo. per seat
Plan features:
- Courses.
- Template simulations.
- AI OSINT spear-phishing simulations.
- AI-powered vishing simulations.
Vishing (standalone)
from $1.19/ mo. per seat
Features:
- Voice-only and hybrid attack simulations (voice + email).
- Multilingual voice library with custom voice cloning.
- Granular scenario builder for custom tactics, urgency levels, and caller personas.
- AI-assisted scenario creation.
- Detailed analytics tracking with one-click CSV export.
Ask AI about Brightside
Let ChatGPT, Gemini or Perplexity share what they know. Click a button and see what your favorite AI says about Brightside.
Is Brightside AI available to companies in the United States?
Yes. The platform is delivered over the web, so a US company can subscribe, onboard employees, and start running campaigns without installing anything locally. Subscriptions are billed in US dollars, and onboarding is handled remotely by our team.
What services does Brightside AI provide?
Two. First, online cybersecurity awareness training: non-downloadable courses and educational materials that employees work through in the browser. Second, a software as a service platform that lets security teams build and run simulated phishing, vishing, and deepfake attacks, then measure how their workforce responded.
What evidence do we get for audits and internal reporting?
Every campaign and course leaves a record. Administrators can see who completed which module and when, alongside click rates, credential submissions, reported messages, and per-department risk trends over time. Vishing campaigns keep full call transcripts, and results export to CSV in one click for board decks and evidence requests.
How is Brightside AI billed for US customers?
Per seat, per month, in US dollars. The Start plan is free to use, paid plans scale with headcount, and enterprise agreements and volume pricing are quoted on request. Prices shown on this page apply to customers in the United States.
Do employees need to install anything?
No. Brightside AI runs in the browser. Employees sign in to the personal portal to take courses, and administrators run campaigns from the admin portal. An optional Gmail add-on lets employees report suspicious mail in one click, but it is not required to use the training or simulation services.
How long does it take to get a US team up and running?
Most organizations are running their first campaign within days rather than months. Pre-built integrations with Google Workspace, Microsoft 365, Okta, and Vanta handle user provisioning, so employee lists stay current without manual uploads. We also run scoped pilots — a single department, one campaign, and a debrief on the results — before a company-wide rollout.