sentrymail.Security Awareness

Capabilities

Features for phishing simulation and awareness training

The free Core version includes all the basics to get started: phishing campaigns, trainings and basic reporting. Business and Enterprise unlock additional features as an annual subscription – here you can see which feature sits in which add-on.

Core – free+ Business+ Enterprise
Core

Free, open source and self-hosted

The open-source foundation of SentryMail – free to use and self-hostable. It includes all the essentials to get started; Business and Enterprise build on top.

Templates

  • HTML or Markdown editor with live preview
  • Personalization variables in subject, HTML and text
  • Preview with sample data
  • Attachments added manually and sent with the campaign

Recipient groups

  • Reusable lists with position, department and criticality
  • Populate via manual entry or CSV
  • Flagging of management bodies (§ 38 BSIG)

Sending profiles

  • SMTP profiles with sender identity and test mail
  • Provider-independent (IONOS, Hetzner, Mailgun, SES, Postmark …)
  • Global fallback SMTP without a dedicated profile

Delivery

  • Allowlisting generator for Exchange Online, Postfix, Proofpoint, Sophos and Barracuda
  • Delivery self-test via the exact path the campaign will take
  • Delivery diagnostics with per-recipient SMTP status codes
  • Greylisting detection from three temporary rejections onwards
  • Checks SPF, DMARC and duplicate records of the sender domain
  • A delivery analysis, not an analysis of people

Landing pages

  • Target pages as HTML or Markdown
  • Data capture, credential harvesting and redirect
  • Forms automatically rewired to the tracking URL

Campaigns

  • Assistant combining template, profile, landing page and groups
  • Optional scheduling
  • Re-run for incompletely delivered campaigns

Campaign preflight

  • Mandatory dialog before every launch with recipient count, timing and findings
  • Quiet hours, blackout windows and a per-person cooldown (default 30 days)
  • Time zone per instance as an IANA name, UTC by default
  • Risk class of the lure topic, maintained on the template
  • Four-eyes approval for high risk, enforced in the database as well
  • Group exclusions right in the dialog, effective at send time

Tracking & results

  • Per-recipient tracking token in links and pixel
  • Send, open, click and form data with timestamps
  • Per-campaign results page with CSV export
  • Control-center dashboard with risk score (0–100, traffic light)
  • Human Risk Management across all campaigns
  • Management report with campaign comparison

Users & roles

  • Roles administrator, data protection officer and user
  • Local login and optional OIDC/SSO (Authentik, Keycloak, Entra ID, Okta …)
  • Two-factor authentication via app or email code, plus backup codes
  • 2FA enforceable – for everyone or for administrators only
  • Audit log of logins and system changes

Chain of evidence

  • Hash chaining of every audit entry (SHA-256, gapless position)
  • Chain status in the dashboard, a break is named with its position
  • Evidence package as ZIP with manifest and bilingual verification guide
  • Standalone verifier – a single file, standard library only
  • Separate retention period for audit content, chaining kept as a tombstone
  • Access for administrators and the data protection officer

Privacy & co-determination

  • Privacy mode blocks individual-level evaluations
  • k-anonymity for group evaluations (default 5)
  • Four-eyes approval for temporary lifting
  • Retention period with automatic anonymization
  • Client fingerprinting only after explicit opt-in
  • Templates for works agreement and privacy notice

Operations

  • Docker Compose (rootless, hardened) with Caddy and automatic TLS
  • PostgreSQL and Redis, all data stays in your own installation
  • German and English, light and dark mode
Business

The full feature set – tiered by number of employees

The Business add-on unlocks all of the following features on top of the free Core version – as an annual subscription, tiered by number of employees.

Directories & sign-in

  • LDAP directory import with LDAPS and StartTLS
  • Azure AD / Entra ID via Microsoft Graph
  • SCIM 2.0 provisions users and groups automatically
  • Passkeys as a second factor (WebAuthn)

Templates & attack types

  • Template library (DHL, Amazon, Microsoft 365, bank, PayPal, LinkedIn …)
  • A matching landing page for every mail template
  • .eml import of real emails including attachments
  • AI-assisted creation via an OpenAI-compatible interface
  • Spear phishing, whaling and file-based attacks
  • QR code phishing (quishing) per recipient

Campaign depth

  • Recurring campaigns at a fixed interval
  • Multi-stage campaigns with a template per stage

Reporting channel

  • Reporting of suspicious mails with deduplication
  • Mail report button for Thunderbird and Outlook
  • Report without an account via a reporting token with limits

Analysis & records

  • Credential capture masked and encrypted
  • Executive report, trend analysis and user development
  • PDF export with logo and company details
  • Compliance center (GDPR, NIS2, ISO 27001, BSI ORP.3, § 38 BSIG)
  • PDF/A-3b with embedded fonts
  • Webhooks on every tracking event
Enterprise

Business plus platform, AI & SSO – as an upgrade (+40%)

The Enterprise add-on is an upgrade to Business – not a standalone add-on. It costs a fixed surcharge of +40% on top of the Business price and includes all Business features plus the following extensions.

Branding & automation

  • White-label with app name, accent colors and logo, incl. login page
  • Automated and risk-based campaigns
  • AI scoring of human-risk metrics with prioritized actions
  • Enterprise reporting with training progress and certificate status

Integration with existing systems

  • SAML single sign-on (ADFS, Entra ID, Keycloak, Okta …)
  • SIEM export to Splunk HEC, Elasticsearch, Microsoft Sentinel or JSON

Evidence for third parties

  • Third-party RFC 3161 timestamp on the head of the chain of evidence
  • Token stored verbatim, verifiable externally with openssl ts -verify
  • A failed stamp is kept as an anchor with status “failed”
  • Time-limited auditor access, read-only and logged separately
  • An expiry date is mandatory, privacy mode still applies

Training module (LMS)

  • Mandatory video training, self-hosted (file system or S3/MinIO)
  • Automatic course assignment on low awareness scores
  • Tamper-proof progress tracking
  • Comprehension quiz, graded server-side
  • Deadlines with reminders and escalation
  • Audit-proof training records as PDF with integrity hash
  • SCORM 1.2 import (beta)
  • xAPI 1.0.3 export to a Learning Record Store

Analysis of reported mails

  • Automatic analysis with SPF/DKIM/DMARC and an explainable score
  • Defanged URLs and attachment hashes
  • Waves group similar reports together
  • Attachment scanning via ClamAV and YARA rules
  • MISP enrichment against your own threat intel
  • Unreachable scanners count as “not scanned”

Effectiveness of your own defenses

  • Control effectiveness test measures which layer catches what
  • Eight stages from display-name spoofing to HTML smuggling
  • Sent to your own test mailbox only, enforced server-side
  • Deliberately harmless payloads – EICAR instead of malware
  • “blocked” is the good result, an IMAP issue is never a test result
  • BSI mapping per stage (APP.5.3.A4, APP.5.3.A5, NET.1.1.A3)

Reporting obligations

  • NIS2 reporting assistant with a deadline clock (24 h, 72 h, one month)
  • No automatic transmission – the output is a draft to download
  • Guided checklist, no legal advice, with a notice in every output
  • Justification required both ways, including a decision not to report
  • Parallel GDPR track with its own clock and recipient (Art. 33)
  • Escalation to named roles with deputies, exactly once per stage

Response

  • Bulk quarantine via Microsoft Graph or Postfix/Dovecot
  • Search by Message-ID only, dry run mandatory
  • Only moved, never deleted

Simulations across more channels

  • SMS via a generic HTTP gateway
  • Matrix and Nextcloud Talk as direct messages
  • USB drop without any program or script
  • Corporate devices only

Ready for the full feature set?

Calculate your price or start for free with the Core version.