Security Measures & Privacy Policy



  1. Where is customer and campaign data hosted?

Goldphish services and customer data are hosted with IONOS in ISO 27001-certified data centers located in the EU/EEA. Goldphish operates in full compliance with UK and EU GDPR standards and utilises lawful transfer mechanisms for international clients, including Australian and global customers.


  1. What campaign data is retained from phishing simulations?

Goldphish retains standard campaign metrics necessary for training analysis, including:

  • Interaction Metrics: Email opens, link clicks, reported emails, and simulation pass/fail statuses.
  • Training Progress: Learning module completions and test scores.
  • Technical Metadata: IP addresses, timestamps, and user location/time zone details.

  1. Are actual user credentials or form inputs captured during phishing simulations?

No. Goldphish landing pages do not capture, log, or store any text entered into input fields.

  • Zero Credential Retention: Usernames, passwords, MFA codes, or other sensitive inputs are never recorded, logged, or retained in any form.
  • Event-Only Logging: By default, the platform records solely that a user reached and failed the data entry portion of the simulation exercise, without storing or capturing any submitted values.

  1. Are submitted credentials included in reports, exports, backups, or audit logs?

No. Because credentials are never collected or stored by the system in the first place, they do not exist anywhere within platform databases, generated reports, data exports, backups, or audit logs.


  1. What security certifications and policies govern the platform?

Goldphish maintains strict data governance standards backed by official security measures, including:

  • Cyber Essentials Accreditation: Certified under the UK IASME framework.
  • Encryption Standards: Data encrypted using TLS 1.2 or higher in transit over public networks and AES-256 encryption at rest.
  • Compliance & Retention: Full compliance with UK and EU GDPR standards, with customer data permanently removed within 90 days of contract termination (or within 7 days for user-deleted items).

You can find our Privacy Policy,  Security Measures and Terms of Service directly on our website, or contact your account representative or our support team for further details.

Did this answer your question? Thanks for the feedback There was a problem submitting your feedback. Please try again later.

Still need help? Contact Us Contact Us