Security awareness training, built in Jakarta
Phishing simulationthat changes behaviour.
Send realistic phishing over email, voice, SMS and WhatsApp. Catch the click, teach on the spot, and watch your reporting rate climb. Then export the evidence your regulator asks for.
Hosted in Southeast Asia. English and Bahasa Indonesia as standard.
Q3 Credential Harvest, All Staff
- OJK POJK 11/202211
- Bank Indonesia PBI 2/20248
- ISO/IEC 27001:20227
- NIST CSF 2.06
- UU PDP3
Recognizing Phishing Emails
Triggered by a credential submit
Illustrative interface. Sample data.
Your auditors already have a control language. Claro reports in it, so the awareness section of your next examination is mostly written before you start.
- OJK POJK 11/2022
- Board-ready reporting on awareness activity, incident readiness and staff competency, on whatever schedule you set.
- Bank Indonesia PBI 2/2024
- Cyber resilience and security programme records for banks supervised under the KKS regime.
- ISO/IEC 27001:2022
- A.6.3 awareness and training evidence, exported with dates, cohorts and outcomes attached.
- NIST CSF 2.0
- Govern, Identify, Protect, Detect, Respond and Recover outcomes evidenced from live campaign data.
- UU PDP
- Training records for personal data handling, retention settings and per-user erasure logs.
Claro generates the evidence and the control mapping. Certification and regulatory findings stay with your auditor and your supervisory authority.
Human risk scoring your board can read
Attendance is easy to hit and tells you nothing. Two numbers predict whether a real attack lands: how many people click, and how many people report it. Claro moves both.
- Click rate
- 24.1%6.9%
- Report rate
- 6.2%51.3%
- Median time to report
- 42 min6 min
Sample tenant data over six campaign cycles. Yours will look different.
Most improvedBranch Operations went from elevated to low in two quarters. No extra classroom sessions.
See how the scoring worksHow your security awareness programme runs
Most tools stop when someone finishes a module. Claro keeps going. It provokes a real decision, records what people actually did, and coaches them at the moment of the mistake. What comes out the other end is a score you can defend and a report you can file.
- 01Simulate
Every channel your staff actually use
Email is where most programmes stop. Attackers moved on years ago. Claro runs voice, SMS and WhatsApp simulations from the same console, using lures written for Indonesia rather than translated from somewhere else.
- Four channels live: email, voice, SMS, WhatsApp
- AI-written spear phishing and double-barrel sequences
- 71 email templates, including Indonesian lures written locally
- BPJS Kesehatan, membership data checkGovernmentID
- J&T Express, customs charge confirmationLogisticsID
- Finance, urgent CFO wire requestFinanceEN
71 email templates in the global libraryAI personalisation on - 02Observe
Behaviour, timestamped
You get more than a click count. Every delivery, open, click, credential submit and report lands on a per-person timeline. When somebody reports the email straight from Outlook or Gmail, that counts too.
- Per-recipient event timeline
- One-click reporting from Outlook and Gmail
- Breakdowns by department, device and browser
Event streamRecipient 0412- Email delivered09:12:04
- Opened09:14:37
- Link clicked09:15:02
- Credentials submitted09:15:48
- Awareness page shown09:15:49
- Training assigned09:16:03
One second between the password going in and the lesson coming up.
- 03Teach
Coaching at the moment it lands
Nobody learns from a reminder three weeks later. The second someone submits a password, Claro shows them what they missed, in their own language, and books the matching module before they close the tab.
- Just-in-time awareness page per attack type
- Rules assign training by trigger, department or schedule
- Runs your existing SCORM and xAPI content alongside ours
Awareness pageThis was a simulation
You entered your password on a page that was not ours. Here is what gave it away.
- The sender domain was not the bank's real domain
- The link went to a lookalike address
- The message pushed for action within the hour
Assignment ruleOn credential submit, assign the matching module and set a 7 day due date.
Assigned moduleRecognizing Phishing Emails
6 min, pass mark 80%
- 04Measure
A risk score you can defend line by line
One number per person, plus the factors behind it. Show a department head exactly why their team scores the way it does and what has moved since last quarter. No arguing with the methodology in front of the board.
- Scoring per user, team and department
- Every factor visible, nothing hidden in a black box
- Reporting rate treated as a headline metric
Average risk scorevs previous quarter3114- Low62%
- Moderate24%
- Elevated10%
- Critical4%
Largest movements- Repeat clicks, Operations+18
- Time to report, all staff-12
- Credential submits, Finance-9
- 05Prove
The audit pack, already written
Pick a framework and a period. Claro builds the report from live data, in English or Bahasa Indonesia, and emails it to your risk committee every quarter. Nobody touches a spreadsheet.
- Five report types across five frameworks
- Scheduled generation and delivery
- Full evidence bundle with CSV exports
Evidence packQ3 2026, generated- OJK supervisory reportPDF, Bahasa Indonesia
- ISO 27001 control mappingPDF, English
- Campaign and training recordsCSV, 4 files
Mapped controls35Every control links back to the campaigns, modules and reports behind it.
Made in Jakarta for Indonesian compliance
Claro was built by an Indonesian team for organisations that answer to OJK and BSSN, run bilingual workforces, and get asked hard questions about where their data sits.
- Bahasa Indonesia is not a plugin
- Training modules, awareness pages, the learner interface and every generated report ship in both languages. The phishing library carries Indonesian lures written locally, not translated ones.
- Your data stays in the region
- Claro is a managed service hosted in Southeast Asia, with a separate encryption key for every tenant and deletion on request.
- Lures your staff have already seen
- Account re-verification, customs charges, delivery fees, government notices, e-wallet prizes. Modelled on what is circulating here, not on American gift-card scams.
J&T Express: Status bea cukai paket Anda
Paket Anda tertahan di bea cukai. Konfirmasi pembayaran dalam 1 x 24 jam agar pengiriman dapat dilanjutkan.
Konfirmasi pembayaran- Managed and hosted
- Nothing for your team to run or patch. Fixes and features ship continuously.
- A key per tenant
- Personal data is encrypted at rest. Destroy the key and it becomes unreadable for good.
- Regional residency
- Hosted in Southeast Asia so employee records never leave the region.
Questions buyers ask
A safe, controlled phishing email sent by your own security team to your own staff. Nobody gets punished. The point is to find out who is exposed and coach them at the moment they slip, before a real attacker gets there first.
Show your board a number that moved
Thirty minutes to scope it. A pilot on one department. An evidence pack you can take into your next audit.
- A 30 minute call on your channels, languages and reporting obligations.
- A pilot on one department, with a baseline and a follow-up campaign.
- The evidence pack from that pilot, in the framework you report on.