Master Services & Authorized-Use Agreement

Last updated September 20, 2026

This Master Services & Authorized-Use Agreement (the "Agreement") governs your organization's use of phish.co's phishing, smishing (SMS), and vishing (voice) security-assessment service (the "Service"). It is entered into between phish.co, a service of Fulcrum LLC ("phish.co," "we," "us," or "our") and the organization that creates an account and accepts this Agreement ("Customer," "you," or "your"). It works alongside our Terms of Service, Acceptable Use Policy, Privacy Policy, and Data Processing Addendum; where this Agreement and the Terms of Service address the same subject, this Agreement controls for the authorized-use and campaign-conduct terms.

By creating an account, accepting this Agreement, or running any campaign, the individual doing so represents that they are authorized to bind the Customer, and the Customer agrees to this Agreement. If you do not agree, do not use the Service.

1. The Service, in brief

phish.co is a subscription software service that lets your organization run simulated phishing, smishing, and vishing assessments against your own workforce, to measure and improve their ability to recognize and report real attacks. The Service is designed so that a campaign can only ever reach people at a domain your organization has verified it controls; that restriction is enforced by the software on every send, not by policy alone. See Responsible Use for the plain-language description of how this works.

2. Customer warranties — the core of this Agreement

Simulated social-engineering is a serious capability. This section is the heart of what you are agreeing to. Each time you create an account, configure a campaign, or authorize a send, you represent and warrant, on behalf of the Customer, that:

2.1 Own workforce only

You will use the Service to target only your organization's own current employees and contractors, at one or more domains your organization has verified ownership of through the Service. You will never use the Service to target any person outside your own organization — including former employees, customers, prospects, vendors, partners, or any member of the general public.

2.2 Organizational authority

You hold the organizational authority to authorize security-awareness testing of the people you target, whether that authority derives from your role, your organization's policies, or an internal delegation. You are responsible for ensuring the right people within your organization have approved the testing program.

2.3 Internal notice

You have given, or will give, internal notice consistent with your own organization's policies — for example, an acceptable-use or security-awareness policy informing staff that periodic assessments occur. This is a general notice that assessments happen, not advance warning of any specific campaign, which would defeat the purpose of the test. Where your workforce includes people in jurisdictions that require a documented legal basis for processing (for example, an employer's legitimate-interest assessment under the GDPR), you are responsible for maintaining that basis; the consent/authorization question sits at the organization level, not at per-employee, per-message consent.

2.4 Channel-specific consent and law

2.5 Rules-of-engagement attestation

For campaigns that present a data-entry (simulated login or form) landing page, and before such a send, you will complete the in-product rules-of-engagement confirmation — which shows the exact target count and verified domain(s), requires explicit confirmation, and is logged. Your acceptance of the current rules-of-engagement policy version is a condition of running these campaigns, and a revised policy version requires re-acceptance.

3. Permitted use

Subject to this Agreement, you may use the Service to design, schedule, and run authorized simulated assessments against your verified workforce; to view aggregate and per-target engagement results (for example, whether a message was opened, clicked, submitted-to, or reported); and to use the resulting reporting to run your own security-awareness program. You may grant access to your own personnel who are bound by obligations at least as protective as this Agreement.

4. Prohibited use

You will not, and will not permit anyone to, use the Service to:

We may suspend or terminate, without notice, any account we reasonably believe is being used outside a verified, authorized engagement or in violation of this section, in addition to any other remedy available to us.

5. Acceptable content

You are responsible for the content of the campaigns you create. Content must be consistent with a good-faith security-awareness assessment of your own workforce and must comply with section 4. Certain template categories are restricted or denied by the Service by design — most notably clinical/EHR-style templates, consistent with the HIPAA-avoidance rule above. We may add, withhold, or remove template categories to keep the Service within its intended, lawful scope.

6. Data handling and compliance-by-design

Compliance is built into how the Service works, not bolted on afterward:

Because a campaign necessarily processes personal data about your employees, phish.co acts as a processor and you act as the controller for that data. Roles, sub-processors, retention, and security are described in our Privacy Policy, Security overview, and Data Processing Addendum.

7. Fees

The Service is offered on subscription plans billed through our payment processor, with metered add-ons for SMS and voice usage on paid tiers. Prices, tiers, and billing intervals are shown at checkout and in our Terms of Service; cancellation and refund treatment is described in the Refund & Cancellation Policy.

8. Indemnification

You will defend, indemnify, and hold harmless phish.co and Fulcrum LLC from and against claims, damages, and costs arising out of your breach of the customer warranties in section 2, the prohibited-use terms in section 4, or your use of the Service to target any person you were not authorized to target. This indemnity runs one way: phish.co has no reciprocal obligation to indemnify you, including for any intellectual-property claim. phish.co will notify you promptly of any claim for which it seeks indemnification, and you will have sole control of its defense and settlement, except that any settlement imposing a non-monetary obligation or an admission of fault on phish.co requires phish.co's prior written consent; phish.co may participate in the defense at its own expense.

9. Warranties and disclaimers

The Service is provided "as is" and "as available," without warranties of any kind, express or implied, to the maximum extent permitted by law. A simulated assessment cannot guarantee any particular security outcome; you remain responsible for your own organization's security posture and decisions.

10. Limitation of liability

To the maximum extent permitted by law, neither party is liable for indirect, incidental, special, or consequential damages. Given the nature of authorized security testing, phish.co accepts no liability for any misuse of the Service — including any use of the Service to target a person you were not authorized to target, or any other breach of the customer warranties in section 2 or the prohibited-use terms in section 4.

11. Term and termination

This Agreement applies for as long as you have an account or use the Service. You may stop using the Service and cancel at any time, as described in the Terms of Service. We may suspend or terminate access for violation of this Agreement — including the customer warranties (section 2) and the prohibited-use terms (section 4) — with or without notice depending on the severity of the violation. Provisions that by their nature should survive termination (including sections 4, 6, 8, 9, 10, and this sentence) survive.

12. Governing law

This Agreement is governed by the laws of the United States and the State of Louisiana, without regard to conflict-of-law rules. Any dispute arising out of or relating to this Agreement will be brought exclusively in the courts located in the State of Louisiana, and each party consents to the jurisdiction of those courts.

13. Changes

We may update this Agreement from time to time. If we make material changes we will post the updated Agreement here with a new date and, where the change is material to your obligations, seek renewed acceptance. Continued use after changes take effect means you accept them.

14. Contact

Questions about this Agreement: hello@phish.co.