The platform

Block the smish before the tap. Capture everything else.

SmishAlert is built around three jobs: prevent the attack on iOS before anyone taps, capture every attempt we can't block across the other channels, and prove all of it in a record your team can defend in a board review or audit.

A threat blocked upstream is a log entry. A threat that gets through is a ticket. We sell the log entry.

How it works

Prevent · Capture · Prove

iOS prevention is the point of the spear. The other channels are the sensor network that makes the blocking smart — one report anywhere becomes a block everywhere.

Prevent

Block the smish before the tap.

iOS · managed and BYOD

Inline blocking of unknown-sender messages on iOS, before they reach the tap. The moment an attack is fingerprinted anywhere — any tenant, any device, any channel — it becomes an automatic block on every iPhone in the network.

  • On-device filtering of unknown-sender SMS and iMessage via Apple's Message Filtering extension
  • Runs on any iPhone — company-managed or personal (BYOD) — with no MDM required to protect the device
  • Cross-tenant intelligence: the first phone to see it is the last one that has to
Capture

Nothing gets through invisibly.

Android, WhatsApp, iMessage, social DMs

Where we can't block, employees report suspicious messages in a tap. Those reports don't sit in a queue — they're correlated into named campaigns and they feed the fingerprint database that hardens iOS blocking for everyone.

  • One-tap reporting across Android, WhatsApp, iMessage, and social DMs
  • Fingerprint-grade correlation clusters lookalike reports into named campaigns
  • Report-only is the honest boundary — and the network's early-warning system
Prove

An audit-grade record of everything.

SIEM · API · executive readout

Every block and every report becomes a defensible record — executive impersonation, payroll and HR fraud, credential harvesting, vendor impersonation — streamed to your SIEM and available over API.

  • Board-ready executive reporting on what was blocked and what was captured
  • SIEM/SOAR routing and API access for teams that want signal in their stack
  • The system of record beneath prevention — governance, not the headline

Every attack one employee reports makes the whole network safer — automatically.

Where the stack stops

Your defenses stop before the phone. The attackers didn't.

Every layer you already own stops at a boundary the attacker walks right past. The message is the last mile — and it's the one nobody else covers.

Email security (SEG)
Stops at:The inbox
Doesn't see SMS, iMessage, WhatsApp, or DMs at all
EDR / XDR
Stops at:The managed endpoint
No agent on the messaging layer; nothing on a personal phone
SWG / SSE
Stops at:Traffic routed through the gateway
A personal iPhone on cellular never routes through it — and it has to decrypt TLS to see anything
SmishAlert
Stops at:The message, before the tap
Any iPhone, managed or BYOD, blocked upstream — without reading message content

Privacy & deployment

Runs on any iPhone. Never reads a message.

The iOS filtering layer runs on any iPhone — company-managed or personal (BYOD)— via Apple's Message Filtering extension, with no MDM required to protect the device. Classification runs on-device; only coded fingerprints of unknown-sender messages ever leave the phone. For assessment-grade measurement, SmishAlert runs in Workforce mode on a managed fleet (every unknown SMS / iMessage reviewed, with Android employees reporting into the same dashboard); for individuals and BYOD it runs in Report-Only / Personal mode. The choice is made at deployment and surfaced in the admin console — what procurement reviews is what users experience on day one.

Each mode's data flow is spelled out on the Trust page.

FAQ

Questions security leaders ask

How does SmishAlert block smishing before an employee taps?

On iOS, SmishAlert uses Apple's Message Filtering extension to classify unknown-sender SMS and iMessage on-device and block the known-bad before it reaches the tap. The moment an attack is fingerprinted anywhere in the network, it becomes an automatic block on every enrolled iPhone — so the first target is the last target. It runs on any iPhone, managed or personal (BYOD).

Does SmishAlert work on personal (BYOD) iPhones?

Yes. SmishAlert's iOS filtering runs on any iPhone — company-managed or personal — with no MDM required to protect the device. That's the exact blind spot EDR, MDM, and the secure web gateway can't reach, and the one Verizon's 2026 DBIR calls a 'risky gap in your visibility.' For assessment-grade measurement across a fleet, the pilot runs in Workforce mode on managed devices.

Does SmishAlert read employees' messages?

No. Classification runs on-device, and only coded fingerprints of unknown-sender messages ever leave the phone — never the content, and never a message from a contact. That privacy-first posture is what makes deployment on a personal device feasible, and it's a clean one-up on secure web gateways, which have to decrypt TLS to see anything at all.

How do I measure my workforce's exposure to social engineering?

Book a scoping call and run the SmishAlert 30-day exposure pilot. We deploy our app to 25–100 of your employees, block the known-bad on iOS, capture every attempt we can't block, correlate reports into named campaigns, and end with an executive-grade findings report your CEO and board will read. $2,500 for up to 50 users, credited toward an annual subscription if you move forward.

What's the difference between SmishAlert and a secure email gateway (SEG)?

Your SEG stops at the inbox. SmishAlert blocks the attack on the phone — in SMS, iMessage, and chat — before anyone taps, and keeps an audit-grade record of everything it can't block. We don't replace your email security; we cover the messaging-channel attack surface it was never built to see, which is now where the highest-leverage attacks land first.

What does the SmishAlert 30-day exposure pilot include?

Deployment of the SmishAlert mobile app across 25–100 enrolled users, a reporting portal with classified and correlated message data, a 60-minute executive readout call, a written findings report (branded for your leadership team), and a vertical-specific threat intelligence summary. Pricing is $2,500 for up to 50 users or $5,000 for 51–100 users.

Can SmishAlert deploy across a managed iOS and Android fleet via MDM?

Yes. SmishAlert ships native apps for iOS and Android, both MDM-deployable via Jamf, Addigy, Intune, or any provider that supports iOS Message Filtering extensions and Android Enterprise. On iOS we capture every unknown SMS / iMessage via the Message Filter extension; on Android employees report into the same Workforce-mode dashboard via Share Sheet, in-app, and screenshot upload (filter parity on Android tracks platform APIs). The pilot lands cleanly across a 25–100-user MDM-pushed deployment in a single week.

How is the pilot fee credited toward a subscription?

100% of the pilot fee is credited toward your first year of an annual SmishAlert subscription if you move forward after the executive readout. Subscription pricing is scoped during the readout — typical deployments are $4.99–$7.99 per user per month annual. The $1,500 monthly minimum ensures dedicated analyst support, threat intelligence, and executive reporting for every account.

Who is SmishAlert built for?

Security leaders at 200–2,500-employee organizations in healthcare, financial services, professional services, and HR/payroll — verticals where impersonation, payroll fraud, and credential harvesting cost real money and where the buyer needs a defensible number for the board.

Start measuring

See the platform on your own workforce.

A 30-minute scoping call. A 30-day pilot. A report your CEO will read.

Or take the 2-minute self-evaluation — no email required.