Questions and answers
Short answers to the questions people ask most, grouped by product and topic. Each one links to the full answer.
HRS Triage HRS Exposure HRS Simulation Platform and account For employees Security and privacy
HRS Triage
All HRS Triage guidesTriage questions
Quick answers about how HRS Triage scores reported email, what it does on its own, and what stays with a person.
- Where do reports come from?
- How does Triage decide whether an email is malicious?
- Is confidence a probability?
- What happens when someone reports a practice phishing email?
- Does Triage remove emails on its own?
- Can a removal be undone?
- What protects our executives?
- Will a spoof of a trusted partner get through?
- Do the people who reported hear back?
- Does Triage need access to our mailboxes?
- Can Triage open tickets or post to chat?
- How does Triage handle our data?
- Where do I check whether Triage is working normally?
HRS Exposure
All HRS Exposure guidesExposure questions
Common questions about HRS Exposure, from what it scans and stores to how it affects scores and what it costs to try.
- Is Exposure part of HRS Learn?
- Can I try it before buying?
- Why do I have to verify my domain?
- Does Exposure scan our network or log in to anything?
- Does Exposure store leaked passwords?
- How often are domains re-scanned?
- How does Exposure affect ShieldScore?
- Will Exposure reset someone's password for us?
- What does a critical finding mean?
- Can we pull findings into our own tools?
- Who can do what in Exposure?
HRS Simulation
All HRS Simulation guidesSimulation questions
Answers for admins running practice phishing: delivery, exclusions, channels, timing, what counts as a click, and limits.
- Do we need to allowlist anything?
- Can I send a test to myself first?
- How do I keep some people or addresses out of every simulation?
- Who can a campaign go to?
- Should we send to everyone at once?
- Can we send by text message or Microsoft Teams?
- What kinds of lure can we use?
- Is anything typed into a practice sign-in page stored?
- What counts as a click?
- Someone clicked and then reported. How is that counted?
- How long should a campaign stay open?
- Is there a limit on campaigns?
- Can we run simulations continuously instead of one at a time?
- Where do we see results?
Platform and account
All Platform and account guidesPlans and billing questions
How plans, seats, add-ons, invoices and cancellation work in HumanRisk Shield.
For employees
All For employees guidesQuestions from employees
Straight answers for people who take HRS training, get practice phishing and report suspicious email at work.
- Why did I get a practice phishing email?
- Will I get in trouble if I click one?
- I typed my password into a practice page. Is it stored?
- How can I tell a practice email from a real one?
- How do I report an email?
- Who can see my results?
- What is my Personal risk score?
- Why have I been assigned training?
- Can I stop the reminder emails?
- Can I retake a knowledge check I already passed?
- Where is my certificate?
- Is training available in my language?
- Do videos have captions?
- Can I use my phone?
- What is Ask HRS AI?
- How do I get my data deleted?
- Who do I contact for help?
Security and privacy
All Security and privacy guidesSecurity and privacy questions
Short answers on where data is hosted, how it is protected, who can see it, and what happens when you leave.
- Where is our data hosted?
- Is our data encrypted?
- Is HRS SOC 2 certified?
- Do you sign a DPA?
- Who at HRS can see our data?
- Who inside our organization can see an individual's results?
- Does HRS store passwords typed into a practice phishing page?
- Is our data used to train AI models?
- Can a risk score be used to discipline someone?
- What happens to our data if we leave?
- Can we delete one person's data?
- How do we report a vulnerability?
- Where can I check whether something is down?