Authorized use & rules
Sinon is a security-awareness tool. It exists so an organization can safely test its own consenting people against simulated phishing, learn where the gaps are, and coach them to spot the real thing. Powerful testing tools can be abused — so using Sinon means agreeing to the boundaries below. Creating an account requires confirming you accept them.
What Sinon is for
- Running simulated phishing campaigns against employees, contractors, or members of an organization you own or are explicitly authorized to test.
- Measuring how people respond to simulated phishing so you can improve training and reduce real breach risk.
- Directing anyone who interacts with a simulation to an educational teaching page — training, never punishment.
- Keeping an audit trail of who authorized each campaign and when.
What Sinon must never be used for
- Testing anyone outside your organization, or anyone who has not been placed under your authority to test.
- Attempting to capture, store, or exfiltrate real credentials, payment details, or other sensitive data. Sinon records that a form was submitted — never the values entered.
- Impersonating a real third-party brand, person, or government body in a way intended to deceive for anything other than internal awareness training.
- Using Sinon to harass, intimidate, retaliate against, or single out individuals.
- Any activity that is illegal in your jurisdiction or your target audience's jurisdiction, including violating applicable privacy, labor, or computer-misuse laws.
Your obligations as an account owner
- 1Obtain authorization. Before running any campaign you must have documented authorization from your organization's leadership (or the appropriate data/HR/legal owner).
- 2Respect local law. You are responsible for complying with all laws that apply to you and to the people you test — including notice, consent, and works-council or labor requirements where they apply.
- 3Handle data responsibly. Only upload employee data you are permitted to process, and only for the purpose of running awareness simulations.
- 4Debrief and educate. Simulations exist to teach. Follow up with training, not disciplinary action, so people learn to spot real attacks.
Built to keep you honest
Sinon never stores credentials or form values — only the fact that a simulated form was submitted. Every campaign records who authorized it, and everyone who interacts with a simulation is redirected to a teaching page. These safeguards are what separate a legitimate training tool from an attack tool.
Misuse — including testing people you are not authorized to test, or attempting to capture real credentials — is a violation of this policy and may result in suspension of your account and, where applicable, referral to the relevant authorities. If you are unsure whether a use is permitted, check the FAQ before you run a campaign.