The platform
Block the smish before the tap. Capture everything else.
SmishAlert is built around three jobs: prevent the attack on iOS before anyone taps, capture every attempt we can't block across the other channels, and prove all of it in a record your team can defend in a board review or audit.
A threat blocked upstream is a log entry. A threat that gets through is a ticket. We sell the log entry.
How it works
Prevent · Capture · Prove
iOS prevention is the point of the spear. The other channels are the sensor network that makes the blocking smart — one report anywhere becomes a block everywhere.
Block the smish before the tap.
iOS · managed and BYOD
Inline blocking of unknown-sender messages on iOS, before they reach the tap. The moment an attack is fingerprinted anywhere — any tenant, any device, any channel — it becomes an automatic block on every iPhone in the network.
- On-device filtering of unknown-sender SMS and iMessage via Apple's Message Filtering extension
- Runs on any iPhone — company-managed or personal (BYOD) — with no MDM required to protect the device
- Cross-tenant intelligence: the first phone to see it is the last one that has to
Nothing gets through invisibly.
Android, WhatsApp, iMessage, social DMs
Where we can't block, employees report suspicious messages in a tap. Those reports don't sit in a queue — they're correlated into named campaigns and they feed the fingerprint database that hardens iOS blocking for everyone.
- One-tap reporting across Android, WhatsApp, iMessage, and social DMs
- Fingerprint-grade correlation clusters lookalike reports into named campaigns
- Report-only is the honest boundary — and the network's early-warning system
An audit-grade record of everything.
SIEM · API · executive readout
Every block and every report becomes a defensible record — executive impersonation, payroll and HR fraud, credential harvesting, vendor impersonation — streamed to your SIEM and available over API.
- Board-ready executive reporting on what was blocked and what was captured
- SIEM/SOAR routing and API access for teams that want signal in their stack
- The system of record beneath prevention — governance, not the headline
Every attack one employee reports makes the whole network safer — automatically.
Where the stack stops
Your defenses stop before the phone. The attackers didn't.
Every layer you already own stops at a boundary the attacker walks right past. The message is the last mile — and it's the one nobody else covers.
Privacy & deployment
Runs on any iPhone. Never reads a message.
The iOS filtering layer runs on any iPhone — company-managed or personal (BYOD)— via Apple's Message Filtering extension, with no MDM required to protect the device. Classification runs on-device; only coded fingerprints of unknown-sender messages ever leave the phone. For assessment-grade measurement, SmishAlert runs in Workforce mode on a managed fleet (every unknown SMS / iMessage reviewed, with Android employees reporting into the same dashboard); for individuals and BYOD it runs in Report-Only / Personal mode. The choice is made at deployment and surfaced in the admin console — what procurement reviews is what users experience on day one.
Each mode's data flow is spelled out on the Trust page.
FAQ
Questions security leaders ask
How does SmishAlert block smishing before an employee taps?
On iOS, SmishAlert uses Apple's Message Filtering extension to classify unknown-sender SMS and iMessage on-device and block the known-bad before it reaches the tap. The moment an attack is fingerprinted anywhere in the network, it becomes an automatic block on every enrolled iPhone — so the first target is the last target. It runs on any iPhone, managed or personal (BYOD).
Does SmishAlert work on personal (BYOD) iPhones?
Yes. SmishAlert's iOS filtering runs on any iPhone — company-managed or personal — with no MDM required to protect the device. That's the exact blind spot EDR, MDM, and the secure web gateway can't reach, and the one Verizon's 2026 DBIR calls a 'risky gap in your visibility.' For assessment-grade measurement across a fleet, the pilot runs in Workforce mode on managed devices.
Does SmishAlert read employees' messages?
No. Classification runs on-device, and only coded fingerprints of unknown-sender messages ever leave the phone — never the content, and never a message from a contact. That privacy-first posture is what makes deployment on a personal device feasible, and it's a clean one-up on secure web gateways, which have to decrypt TLS to see anything at all.
How do I measure my workforce's exposure to social engineering?
Book a scoping call and run the SmishAlert 30-day exposure pilot. We deploy our app to 25–100 of your employees, block the known-bad on iOS, capture every attempt we can't block, correlate reports into named campaigns, and end with an executive-grade findings report your CEO and board will read. $2,500 for up to 50 users, credited toward an annual subscription if you move forward.
What's the difference between SmishAlert and a secure email gateway (SEG)?
Your SEG stops at the inbox. SmishAlert blocks the attack on the phone — in SMS, iMessage, and chat — before anyone taps, and keeps an audit-grade record of everything it can't block. We don't replace your email security; we cover the messaging-channel attack surface it was never built to see, which is now where the highest-leverage attacks land first.
What does the SmishAlert 30-day exposure pilot include?
Deployment of the SmishAlert mobile app across 25–100 enrolled users, a reporting portal with classified and correlated message data, a 60-minute executive readout call, a written findings report (branded for your leadership team), and a vertical-specific threat intelligence summary. Pricing is $2,500 for up to 50 users or $5,000 for 51–100 users.
Can SmishAlert deploy across a managed iOS and Android fleet via MDM?
Yes. SmishAlert ships native apps for iOS and Android, both MDM-deployable via Jamf, Addigy, Intune, or any provider that supports iOS Message Filtering extensions and Android Enterprise. On iOS we capture every unknown SMS / iMessage via the Message Filter extension; on Android employees report into the same Workforce-mode dashboard via Share Sheet, in-app, and screenshot upload (filter parity on Android tracks platform APIs). The pilot lands cleanly across a 25–100-user MDM-pushed deployment in a single week.
How is the pilot fee credited toward a subscription?
100% of the pilot fee is credited toward your first year of an annual SmishAlert subscription if you move forward after the executive readout. Subscription pricing is scoped during the readout — typical deployments are $4.99–$7.99 per user per month annual. The $1,500 monthly minimum ensures dedicated analyst support, threat intelligence, and executive reporting for every account.
Who is SmishAlert built for?
Security leaders at 200–2,500-employee organizations in healthcare, financial services, professional services, and HR/payroll — verticals where impersonation, payroll fraud, and credential harvesting cost real money and where the buyer needs a defensible number for the board.
Start measuring
See the platform on your own workforce.
A 30-minute scoping call. A 30-day pilot. A report your CEO will read.
Or take the 2-minute self-evaluation — no email required.