Editorial depth draft · score N/Pub · noindex
Published by By SecurityChecklist
Reviewed Independent reviewer role open
Editorial depth draft · score N/Pub · noindex
Experts policyKnowBe4 Review
KnowBe4 is not scored on SecurityChecklist yet. Treat this review as pack-verified diligence on AI-Native Security Awareness Training scope, not as an inbound email gateway endorsement or a ranked winner.
Direct answer (claim-safe)
KnowBe4 is not scored on SecurityChecklist yet. Treat this review as pack-verified diligence on AI-Native Security Awareness Training scope, not as an inbound email gateway endorsement or a ranked winner.
Pack summary (unscored): training content in 35+ languages, AI-generated phishing and vishing simulations, Real-Time Coaching, and SmartRisk analytics for continuous human-risk reduction. Add-ons such as PhishER Plus are separate SKUs per pack limitations.
- Inventory ID
- E070
- Cluster
- Email security
- Editorial score
- N/Pub (null) until E006 score gate clears; never invent a numeric ranking.
- Indexation
- noindex, follow=false · excluded from sitemap
- Conversion intent (not a ranking input)
- Partner lead
SAT seats do not replace MFA, offboarding, or DMARC. Finish free controls first.
Before buying KnowBe4 seats
- Enforce MFA on mailboxes and privileged cloud roles
- Name an owner for simulation exceptions and reported phish
- List languages and locations that must be covered
- Decide whether you need PhishER-class triage add-ons before demo scripts expand scope
- Confirm IdP SCIM readiness for Azure, Okta, or OneLogin
Product scope from verified pack rows
KnowBe4 product pack describes AI-Native SAT with multi-language content, AI phishing/vishing simulations, Real-Time Coaching, and SmartRisk analytics. This is human-risk and awareness scope. Do not rewrite it as a secure email gateway review.
Admin identity and pricing transparency
Pricing feature matrix includes SSO/SAML on all subscription levels, AD or SCIM provisioning for Azure/Okta/OneLogin, Security Roles, and Smart Groups (Advanced tier required for unlimited Smart Groups per pack limitations).
MSRP capture: SAT Foundation for 25-50 seats at $2.40 USD per seat per month on a 3-year term (vendor May 2026 note on pricing page; re-check before purchase). Global Technical Support languages are listed; response-time SLAs were not specified on the pricing page reviewed.
Architecture and standards claims
Security statement: TLS 1.2+ in transit, AES-GCM 256 at rest via AWS KMS and Azure Key Vault, mandatory MFA for confidential data access. Independent/standards slot cites FedRAMP Moderate ATO for KSAT + PhishER since 11/14/2023, SSAE18 SOC 2 Type 2, and multiple ISO audit claims. All vendor-stated; SecurityChecklist has not independently audited infrastructure or certificates.
Evidence
Vendor evidence status
Draft packs from E006. Conflicted or missing slots block scores. Public partner pages are not program acceptance.
KnowBe4
Source packN/PubPack status: draft. Claim slots: 6 verified, 0 conflicted, 0 missing. Pricing status: public. Commercial status: application_pending. Editorial score: N/Pub. Score gate ready: no.
Claim ledger
Pack-verified citations used on this draft
Only E006 verified evidence rows. Conflicted slots are omitted. evidenceLabel stays unverified until reviewer approval.
KnowBe4 · knowbe4:product-scope
KnowBe4 AI-Native Security Awareness Training combines training content in 35+ languages, AI-generated phishing and vishing simulations, Real-Time Coaching, and SmartRisk analytics for continuous human-risk reduction.
Source (official, accessed 2026-08-09): https://www.knowbe4.com/products
- Vendor product marketing; add-ons such as PhishER Plus are separate SKUs.
KnowBe4 · knowbe4:security-architecture
KnowBe4 security statement states data encryption in transit (TLS 1.2+) and at rest (AES-GCM 256) via AWS KMS and Azure Key Vault; mandatory MFA for confidential data access and IP restrictions where applicable.
Source (official, accessed 2026-08-09): https://www.knowbe4.com/security
- Architecture claims are vendor-stated; SecurityChecklist has not independently audited infrastructure.
KnowBe4 · knowbe4:admin-identity
KnowBe4 pricing feature matrix includes SSO/SAML integration on all subscription levels, user provisioning via Active Directory or SCIM for Azure/Okta/OneLogin, Security Roles for delegated console access, and Smart Groups for tiered campaigns.
Source (official, accessed 2026-08-09): https://www.knowbe4.com/pricing
- Advanced tier required for unlimited Smart Groups; verify IdP-specific SCIM behavior before procurement.
KnowBe4 · knowbe4:pricing-transparency
KnowBe4 publishes MSRP USD monthly pricing per seat on a 3-year term; SAT Foundation for 25-50 seats is listed at $2.40 USD per seat per month (pricing as per May 2026 on vendor page).
Source (official, accessed 2026-08-09): https://www.knowbe4.com/pricing
- List pricing may vary by region; taxes and discounts not included.
- Re-check before publication; vendor pricing is volatile.
KnowBe4 · knowbe4:support-response
KnowBe4 pricing page lists Global Technical Support in multiple languages including English, German, Japanese, Portuguese (Brazil), and Spanish (Latin America).
Source (official, accessed 2026-08-09): https://www.knowbe4.com/pricing
- Support hours and response SLAs not specified on pricing page reviewed.
KnowBe4 · knowbe4:independent-or-standards
KnowBe4 security statement states KSAT + PhishER holds FedRAMP Moderate ATO (since 11/14/2023), all products are SSAE18 SOC 2 Type 2 certified, and KnowBe4 is audited against ISO 27001:2022, ISO 27701:2019, ISO 27017:2015, ISO 27018:2019, and ISO 42001:2023.
Source (official, accessed 2026-08-09): https://www.knowbe4.com/security
- Certification claims are vendor-stated; full SOC 2 reports require sales or CSM request.
- SecurityChecklist has not independently verified certificates.
Methodology and limitations
SecurityChecklist keeps editorialScore null (N/Pub) and evidenceLabel unverified on these drafts. Commercial status is not program acceptance. Affiliate or lead payout never sets shortlist order. Re-check volatile pricing before any purchase decision. Commercial status application_pending is not partner acceptance.
Publication gates
What still blocks indexation
Money pages remain noindex until every blocker below clears with dated sources.
- editorialScore null / N/Pub until reviewer-approved evidence packs
- evidenceLabel remains unverified on public money pages
- Partner applications (E007) unfinished; public partner pages are not acceptance
- INDEXABLE_PATHS must not include business-security money routes
- Featured vendor packs still unverified or conflicted for: knowbe4
Related drafts
More in Email security
Cross-links stay inside the noindex enterprise surface.
Who should not buy / use this page yet
- Buyers who need a published editorialScore before deciding
- Teams looking for an MX-changing or API email gateway under the KnowBe4 brand alone
- Organizations that will not staff simulation operations after purchase
- Anyone treating FedRAMP or SOC badges as SecurityChecklist lab validation
Affiliate or lead payout never sets editorial score. See enterprise methodology (also a noindex draft).
