Lures that read like the real inbox, for authorised simulations

A simulation that uses the same three templates every quarter trains people to spot the exercise, not the attack. You need copy that sounds like finance, like HR, like the vendor you actually use, and a model that will write it.

Security awareness leads, purple teams, and MSSPs running programmes for clients who have signed the simulation scope.

Why the mainstream APIs fail here

Mainstream APIs refuse "write a convincing invoice from our CFO" even when the next sentence is the landing page on your own phishing host. They will lecture you about harm and leave you with a blank editor. Local models will write it, but then you have no cap, no per-client key, and no bill.

How Redline is used for this

Each client or campaign gets its own Redline key with a monthly cap. The model writes the lure, the follow-up and the debrief. You host the landing page. Redline never sees the employee list because you do not send it; you send the scenario.

A working loop

  1. Write the scenario, not the target list, into the prompt.
  2. Generate variants until the copy matches the department you are testing.
  3. Debrief with the same model: why this lure would have worked, and what the control should have caught.

Prompts are not stored. A signed receipt of the hash comes back on every call, so you can prove later what Redline logged. Details are on the privacy page. Per-model prices are on /models and the pricing model is on /pricing.

Related