Phishing simulation + AI email detection.
Built for Italian enterprise security teams.

A closed-loop platform that connects simulated phishing campaigns to real-time email threat detection. Every blocked threat informs the next training scenario. Every failed simulation refines the detection model.

How the engine works.

Two core modules connected by a feedback loop that continuously improves both detection accuracy and training relevance.

Phishing Simulation Engine

Automated campaign orchestration with industry-specific templates and behavioral tracking.

// Simulation Engine Specs
campaign_types: ["email", "sms", "landing_page"]
template_library: 200+ industry-specific templates
personalization: dynamic per-user (name, role, department)
tracking: ["open", "click", "credential_submit", "report"]
scheduling: cron-based with randomized delivery windows
difficulty_levels: 5 (auto-adjusting per user history)
landing_pages: pixel-perfect clones with credential capture
training_trigger: instant on-click, contextual micro-learning

AI Email Scanner

Real-time analysis pipeline processing every inbound email before it reaches the user's inbox.

// AI Scanner Performance
avg_latency: <800ms per email
false_positive_rate: <0.3%
detection_rate: 99.2% (phishing), 97.8% (BEC)
analysis_layers: [
  "header_analysis",    // SPF, DKIM, DMARC validation
  "url_inspection",    // real-time URL detonation
  "content_nlp",      // urgency/social engineering detection
  "sender_reputation", // domain age, history, lookalike check
  "attachment_sandbox",// static + dynamic analysis
  "visual_similarity", // brand impersonation via CV
]
model: fine-tuned transformer, retrained weekly
data_residency: EU-only (Frankfurt, DE)

Detection-to-Training Feedback Loop

The two modules feed each other, creating a system that gets smarter over time.

// Feedback Loop Flow

1. DETECT → Scanner blocks real phishing email
2. ANALYZE → Extract attack patterns (techniques, lures, timing)
3. GENERATE → Auto-create simulation template from real attack
4. SIMULATE → Deploy to users who match target profile
5. TRAIN → Deliver contextual training on click
6. MEASURE → Track improvement, update user risk score
7. REFINE → User report data improves detection model

// Result: avg. click rate drops from 32% to 4.7% in 6 months

Technology Stack

backend: Python 3.12 / FastAPI
ml_pipeline: PyTorch, Hugging Face Transformers
queue: Redis + Celery (async email processing)
database: PostgreSQL 16 + TimescaleDB
search: Elasticsearch (threat intel indexing)
infrastructure: Kubernetes on Hetzner Cloud (EU)
monitoring: Prometheus + Grafana
ci_cd: GitHub Actions, ArgoCD
encryption: AES-256 at rest, TLS 1.3 in transit

Works with your existing stack.

Native connectors for the platforms your organization already uses. Deploy in under 30 minutes.

Microsoft 365 / Azure AD

OAuth 2.0, mail flow rules, directory sync

Google Workspace

Admin SDK, Gmail API, Groups sync

🔒

Active Directory / LDAP

On-prem sync via secure agent

🔌

Webhook / SIEM

Splunk, QRadar, Sentinel, custom endpoints

📄

Export CSV / PDF

Automated scheduled reports for management

🛠

REST API

Full API access for custom integrations

Built for European regulatory requirements.

Every feature designed with data protection and compliance reporting in mind from day one.

GDPR Art. 32

Technical and organizational measures to ensure security appropriate to the risk. To Shield provides documented evidence of ongoing employee security awareness programs.

NIS2 Directive

Mandatory cybersecurity risk management and incident reporting for essential and important entities. Our platform covers the human factor requirements of Articles 21 and 23.

ISO 27001

Information security management system controls. To Shield maps directly to Annex A controls A.6.3 (awareness), A.7.2.2 (training), and A.8.23 (web filtering).

ACN Framework

Italian National Cybersecurity Agency guidelines for critical infrastructure. Full alignment with the minimum security measures for essential service operators.

Ready to see it in action?

Schedule a 30-minute technical walkthrough with our engineering team. We'll show you the full platform running against your email infrastructure.