Security awareness training and phishing simulation from Germany
SentryMail turns your employees into your strongest line of defense: realistic phishing simulations, short trainings with real “aha” moments, and reporting that proves progress. The core is open source and can be fully self-hosted – your employee data never leaves your infrastructure.
Built & sold in Germany · GDPR-compliant · NIS2-ready

The platform
Everything for an effective awareness program
From the first simulated attack to measurable cultural change – no bloat, no overhead. The training records NIS2 and ISO 27001 ask for fall out of it automatically.
LMS – Automated mandatory training
Anyone who drops below the threshold in a phishing simulation is automatically assigned the right mandatory video course – from trigger to audit-proof completion record, entirely within your own infrastructure.
- Automatic course assignment when the awareness score is too low – with deadline, reminders and escalation
- Self-hosted videos without YouTube or Vimeo – full data sovereignty for critical infrastructure and public sector
- Tamper-proof tracking – only real watch time counts, validated server-side
- Audit-proof completion with quiz gate, certificate and SIEM logging – NIS2, BSI ORP.3 & GDPR
Phishing simulations
Realistic, customizable campaigns show your employees what today’s attacks really look like – without any real risk.
Training that sticks
Short, interactive learning units instead of hour-long mandatory videos – easy to fit into everyday work.
Reporting & metrics
Click rates, reporting rates, and learning progress at a glance – prove the success of your awareness program.
GDPR-compliant and self-hosted
Built for the European market: data-minimizing, pseudonymized reporting instead of individual surveillance, and fully self-hostable inside your own infrastructure – no US cloud.
Open source at the core
Audit the code, run the phishing simulation on-premise – or start right away with Business if you would rather not operate it yourself.
Signed licenses
Licenses are signed and validated against our license server – keeping your license status always up to date and tamper-proof.
How it works
Three steps to better security
Set up a campaign
Choose from templates for phishing simulations and training – ready to launch in just a few minutes.
Train your team
Employees experience realistic attacks, learn from mistakes, and confidently report suspicious emails.
Measure progress
Dashboards show how click rates fall and reporting rates rise – measurable security instead of gut feeling.
Made in Germany
Security awareness without US cloud
Awareness platforms handle sensitive data: who clicked, who reported, who failed to complete a mandatory course. SentryMail is built and sold in Germany, processes data sparingly and can run entirely inside your own infrastructure – from development and sales all the way to support.
Made in Germany
SentryMail is fully developed and sold in Germany – with support and short, direct lines to the developers.
GDPR-compliant
Data-minimizing by design: only the most necessary personal data is processed – and fully self-hostable on your own infrastructure if you wish.
NIS2-ready
The NIS2 directive requires affected companies to provide cyber-hygiene training (Art. 21). SentryMail helps you meet your training and documentation obligations.
Open core
Self-hosted open source phishing simulation
The core of SentryMail is open source: audit the code, run the platform on your own hardware for free, and keep full control of your data. No vendor lock-in, no black box. Business and Enterprise extend the core with features for professional use – fairly licensed as an annual subscription.
Ready to strengthen your team?
Calculate your price in seconds – or start for free with the Community edition.