Human risk management, built for Africa

Human risk is a security problem.
Trawl helps you manage it.

Trawl helps organizations assess, understand, and reduce human-driven security risk — through realistic simulations, security awareness training, behavioral analytics, and investigation-driven learning. Know where your people are vulnerable. Know why. Build better security behavior.

◈

ContinuousNot a once-a-year test

↗

MeasurableBehavior & risk analytics

◎

ActionableTraining triggered by risk

trawl.vetari.org / human-risk LIVE
Trawl human risk dashboard interface
HUMAN RISK INDEX 38% ↓ 21% this quarter
PEOPLE TRAINED 50K+ Across active programs
The problem

Attackers target people first.

Technology can be hardened in an afternoon. Human behavior changes every day. Employees face phishing emails, fake login pages, SMS scams, impersonation, business email compromise, and fraudulent requests — every single week.

Phishing emailsMalicious linksFake login pagesSocial engineering SMS scamsImpersonationBusiness email compromiseCredential theft Fraudulent requestsMalicious attachmentsInformation disclosure

Traditional awareness programs measure completion. Trawl measures behavior.

01

Simulate

Recreate the social-engineering techniques attackers actually use against your organization.

02

Measure

Track clicks, submissions, reporting behavior, and risk trends over time, not just once.

03

Investigate

Give people realistic cases to examine suspicious messages, domains, and digital evidence.

04

Educate

Turn mistakes and risky behavior into short, targeted learning opportunities.

05

Improve

Use behavioral data to close recurring gaps, quarter over quarter.

The platform

Everything you need to manage human risk.

One console for simulation, awareness, analytics, AI-assisted workflows, and compliance evidence — not five separate logins.

⌁

Phishing simulation

Launch realistic email and SMS simulations with controlled landing pages, OTP flows, target groups, and full campaign automation.

EmailSMSWhatsAppLogin pagesCredential harvestingImpersonation
◫

Security awareness

Short training, micro-lessons, and assessments triggered by real behavior.

◌

Human risk assessment

See risk by organization, department, team, and individual, updated live.

Phishing susceptibilityReporting behaviorKnowledge gaps
✦

AI tools

AI-assisted campaign content and scenario generation, tuned to your org.

◎

Email analyzer

Inspect SPF, DKIM, DMARC, headers, links, and sender signals on any email.

▣

Compliance reports

Turn awareness activity into board- and audit-ready evidence, on demand.

Configure every campaign
Target groupsSending profilesEmail templatesLanding pages Training contentCampaign schedulesEscalation workflowsTrackingNotifications
AI-assisted

AI helps your team move faster, not replace judgment.

AI accelerates the work of running a human-risk program — it doesn't decide what happens to an employee's data.

⌁

Scenario generation

Realistic training & simulation scenarios based on your organizational context.

◎

Email analysis

Analyze suspicious messages and highlight potentially relevant indicators.

◈

Training assistance

Help create targeted learning content, fast.

↗

Risk insights

Identify patterns across behavioral data that may warrant attention.

✦

Investigation assistance

Help learners organize evidence and investigative reasoning.

Beyond phishing simulations

Don't just test who clicks. Test who can investigate.

Real attacks rarely stop at one email — neither should your training. Investigation Lab turns real phishing techniques into safe, interactive investigations, so people learn to spot, investigate, verify, and respond, not just recognize a suspicious subject line.

Investigate. Don't guess.

Employees examine a case the way they would during a real security incident — the goal isn't just to flag it as suspicious, it's to understand why.

  • Sender addresses, headers & authentication results
  • Suspicious domains, URLs & redirect chains
  • Attachments, file metadata & embedded content
  • Reply-To mismatches & domain registration intel
  • Fake login pages & multi-stage attack sequences
CASE_2847.EML / under investigation LIVE
FROMbilling@paypa1-secure.comlookalike domain
REPLY-TOsupport@paypal-billing.rumismatch
LINKbit.ly/3xQ2•• → paypal-verify.xyzredirect
ATTACHMENTinvoice_2847.docmmacro detected
SPF / DKIMfailauth failure
VERDICTphishing — reported
5/5 red flags identified Mockup — sample investigation
Email Detective — how an investigation unfolds
01Sender
02Domain
03Links
04Headers
05Context
06Evidence
07Verdict

Learners inspect clues, uncover inconsistencies, and document findings — turning "watch this video" into "can you figure out what happened?"

Five ways to investigate.

Security teams build scenarios from real phishing campaigns and observed attacks — employees investigate the evidence, not a template.

✉

Email investigations

Analyze realistic phishing and business-email-compromise scenarios end to end.

◫

Screenshot investigations

Examine screenshots of suspicious messages and spot the clues hiding in plain sight.

◈

Attachment investigations

Safely investigate suspicious documents and files through simulated analysis and metadata.

⊞

Landing page investigations

Analyze realistic replicas of credential-harvesting pages, built on dummy training data.

↗

Multi-stage investigations

Follow an attack from the initial email through links, attachments, and fake login pages.

✦

Built from real threats

Security teams and MSSPs turn newly observed attacks into fresh scenarios, continuously.

From real attack to measurable skill
REAL ATTACK→ RECREATE→ INVESTIGATE→ MEASURE→ TRAIN→ RETEST
Measures skills, not just clicks
Sender verificationURL analysisDomain analysis BEC detectionHeader analysisAttachment analysis Social engineering awarenessInvestigation methodologyDecision-making
Custom scenarios

Your threat landscape isn't generic. Your training shouldn't be either.

Build scenarios based on the threats relevant to each department — and the industry you operate in.

Scenarios by department

Finance

Fake payment requests

HR

Employee-document phishing

Executives

Executive impersonation

IT

Fake password-reset requests

Procurement

Supplier invoice fraud

Energy & Oil

Vendor impersonation, OT awareness, physical security

Government

Official-document impersonation, public-sector fraud

Focus by industry
FINANCIAL SERVICES

Protect financial operations

Customer information, payment workflows, and financial operations.

GOVERNMENT

Strengthen public-sector defenses

Awareness around sensitive information, impersonation, fraud, and targeted attacks.

ENERGY & OIL

Cover every environment

Human risk across corporate, operational, contractor, and field environments.

HEALTHCARE

Protect sensitive information

Awareness around sensitive data and social engineering.

TECHNOLOGY

Strengthen every team

Security behavior across technical and non-technical teams.

Adaptive learning

When someone struggles, Trawl responds.

Human risk isn't static. Someone who falls for one simulation needs a different intervention than someone who repeatedly ignores warnings — so the loop keeps running, and keeps adjusting.

CONTINUOUS Improvement Cycle
01

Simulation

02

Behavior captured

03

Risk identified

04

Targeted intervention

05

Training

06

Reassessment

07

Risk trend

01

Simulation

A controlled real-world scenario reaches the employee.

02

Behavior captured

Clicks, submissions, and reporting are logged automatically.

03

Risk identified

The behavior rolls into that person's individual risk profile.

04

Targeted intervention

The right response — not a generic one — is triggered.

05

Training

A short, specific lesson lands while the moment is still fresh.

06

Reassessment

A follow-up scenario checks whether the behavior changed.

07

Risk trend

The result feeds back into the cycle — continuously.

Human risk dashboard

Know where your organization needs attention.

The goal isn't another dashboard. The goal is to help security teams decide what to do next.

0 / 100

Human Risk Score

0Phishing exposure
0Reporting rate
0High-risk users
0Training completion
0Improvement, quarter over quarter
0Simulation campaigns run
Tracked signals
Simulation engagementClick behaviorSubmission behavior Reporting behaviorTraining completionRisk trends Department patternsCampaign performanceUser-level history
Example platform metrics for illustration — replace with your verified figures before publishing.
Interactive product tour

Explore the Trawl console.

Move through the workflows your security team actually uses, day to day.

Trawl / product preview Dashboard / human risk overview
Trawl dashboard preview
Product preview Add a matching screenshot to assets/ to fill this in
Why Trawl

From a phishing test to a security culture.

Trawl closes the loop between what people do, what they learn, and how their risk actually changes. Click a stage to read how it works.

Drag, or click a stage
01 / ASSESS

Assess

Every organization starts from a different place. Trawl begins by mapping your current human risk baseline — who's been tested before, which departments handle sensitive data, and where past incidents point to elevated exposure. That baseline becomes the reference point every later stage measures against, so improvement is never a guess.

Traditional awareness vs. Trawl.

Traditional approachTrawl
Annual trainingContinuous learning
Completion-focusedBehavior-focused
Generic contentContextual scenarios
Passive videosInteractive investigations
Campaign statisticsHuman-risk intelligence
One-size-fits-allAdaptive interventions
Training as complianceTraining as security capability
Trawl philosophy
SIMULATE→ MEASURE→ INVESTIGATE→ EDUCATE→ IMPROVE

What happened? Why did it happen? What did the user learn? Did behavior improve? Where does the organization remain exposed?

Learning center

A security awareness experience people actually want to use.

Learn. Investigate. Test. Improve. Reward secure behavior, not just training completion.

MicrolearningVideo lessonsInteractive investigationsQuizzes ChallengesSecurity scenariosAssessmentsProgress trackingGamification
Turn training into a skill, not paperwork
Points Badges Levels Streaks Investigation scores Leaderboards Team competitions
Compliance & reporting

Turn awareness activity into evidence.

Document participation, results, and risk trends — and give every audience the report they actually need.

SECURITY TEAMS

Full detail

Detailed behavioral and campaign information.

MANAGEMENT

The big picture

High-level risk trends and program performance.

COMPLIANCE TEAMS

Audit-ready evidence

Training and awareness evidence, on demand.

MSSPs

Per-client reporting

Client-level program reporting, at scale.

Built for

For the teams responsible for security.

CISO

Executive visibility

Translate human exposure into a measurable, board-ready security story.

SOC

Better reporting

Strengthen the behavior your defenders rely on when a real attack arrives.

AWARENESS

Targeted training

Use simulation results to make learning relevant and continuous, not generic.

COMPLIANCE

Audit evidence

Keep awareness activity, outcomes, and training coverage visible on demand.

MSSP

Scale programs

Build repeatable human-risk programs across multiple client organizations.

SMB

Start lean

Bring core human-risk workflows together without a large security stack.

For employees — become harder to trick

Trawl doesn't exist to punish employees for making mistakes. It exists to help them recognize threats before real attackers do.

PAUSE→ QUESTION→ INVESTIGATE→ VERIFY→ REPORT
Pricing

Priced for how your organization actually runs.

Per-seat pricing in your local currency, scoped to your headcount and the modules you need. Every tier includes onboarding support.

Starter

Small teams getting a baseline in place

  • Scheduled phishing campaigns
  • Core dashboard & reporting
  • Email & chat support
Talk to sales
Enterprise

Larger organizations & regulated industries

  • Full PAAS + SATAAS + HRAAS suite
  • Investigation Lab with custom scenario builder
  • Board-ready reporting & export
  • Custom compliance mapping
  • Dedicated onboarding & account team
Talk to sales

Want an exact number before talking to us? See full pricing & try the seat calculator →

Vetari

Human risk is one part of a bigger security picture.

Vetari brings three complementary cybersecurity pillars together.

01

Trawl

HUMAN RISK

Phishing simulation, security awareness, behavioral analytics, and compliance.

02

Intelligence

INVESTIGATION

OSINT, cyber threat intelligence, due diligence, and digital risk investigations.

03

Defense

SECURITY

VAPT, ethical hacking, application security, and infrastructure protection.

Built for Africa

Designed around African organizations. Ready to scale.

Trawl is built with African business, regulatory, language, and operational realities in mind, while supporting globally familiar security practices.

ENFRAR+
Get started

Your people are already part of your security perimeter.

The question is whether you can measure and improve how they respond to threats. Start building a stronger human firewall.