LiveIntel security and privacy model
This page explains how LiveIntel operates, what data is needed to run the service, and where the simulation boundaries are. Security claims should be clear, specific, and reviewable.
Security Overview
LiveIntel is a phishing simulation and awareness measurement platform. The security model is built around customer-controlled execution, limited data collection, and measurement focused on campaign outcomes.
Deployment Model
LiveIntel uses a lightweight local agent to execute phishing simulations from the customer environment. The cloud platform provides campaign management, coordination, and campaign results.
What Stays Local
- Simulation execution is performed by the local agent in the customer environment.
- Customer mail flow and environment-specific configuration remain under customer control.
- Simulated credential values are not collected by LiveIntel. A simulation may record that a form submission happened, but not the real value typed into the field.
What LiveIntel Collects
LiveIntel limits collection to the campaign metadata, account details, operational logs, and simulation results needed to operate the service. Depending on configuration, this may include:
- Account and administrator contact details.
- Campaign configuration, template selection, launch timing, and target group metadata.
- Simulation events such as delivery status, opens, clicks, remote content exposure, and simulated form submission events.
- Report events, if configured, such as user-submitted phishing reports and related timestamps.
- Operational logs needed to troubleshoot the agent, platform, and result review workflow.
What LiveIntel Does Not Collect
- LiveIntel does not intentionally collect real passwords or real credential values through phishing simulations.
- LiveIntel does not need mailbox contents to provide campaign results.
- LiveIntel does not sell customer data.
Data Retention
Campaign and simulation result data is retained for as long as needed to provide the service, support customer review, meet legal obligations, and maintain operational integrity. Customers can contact LiveIntel to request deletion or retention details for their account.
Encryption
LiveIntel uses encryption in transit for communications between browsers, the cloud platform, and connected agents. Stored service data is protected with encryption at rest where supported by the underlying hosting and database services.
Responsible Disclosure
If you believe you have found a vulnerability in LiveIntel, email security@liveintel.com with a clear description, affected URL or component, steps to reproduce, and potential impact. Please avoid accessing customer data, modifying data, or performing denial-of-service testing.
Security Contact
Security reports: security@liveintel.com
General questions: hello@liveintel.com