Exa AI

It’s too easy for people to watch training videos on 2x speed and not even pay attention to it.

Patrick Schork,

Patrick Schork,

Founding Security Engineer

Founding Security Engineer

No headings found on page
Outcome
How Exa AI replaced passive compliance training with realistic, role-based phishing simulation

Exa builds the search engine for AIs: an API that gives LLMs and agents fast, semantic access to the web, used by more than 5,000 companies and 400,000 developers. The company is scaling fast off the back of a $250M Series C, which puts real weight on a deliberately lean security function.

The Challenge

Exa’s security awareness program was built for compliance, not for the threats a high-profile AI company actually faces. Onboarding training was delivered without requiring significant engagement. The company had no active phishing simulation program.

Meanwhile, the threat was already inside the funnel. New hires were receiving social-engineering text messages impersonating coworkers within days of onboarding, the classic “buy prepaid gift cards” play, aimed at the newest and most vulnerable employees.

Exa had evaluated the incumbent vendor and run a basic lure campaign through it. The result was unusable as a baseline: most emails never reached the inbox due to deliverability issues, and the campaign recorded a single click. The team couldn’t tell whether employees were resilient or whether the phish simply never arrived.

What Exa Needed

  • Realistic email and SMS phishing simulations out of the box, with deliverability the team could trust and measure

  • Role-based and access-based targeting, so people get phished based on what they can actually reach rather than blanket sends to the whole company

  • Immediate remediation training triggered the moment an employee fails a simulation

  • Campaigns discreet enough that even executives could be tested without advance warning

  • Strong data security guarantees for simulation data, given the sensitivity of captured replies

  • A program a lean security team could run at company scale on top of SOC 2 and HIPAA workloads

The Solution

Exa evaluated Cimento side by side with KnowBe4 and moved into a POC with the goal of having an internal phishing service live within the quarter.

Onboarding and Identity

Cimento connected to Exa’s Okta directory during the kickoff call. An initial provisioning sync issue was debugged asynchronously through a shared Slack channel, and users and groups were syncing from the source of truth ahead of the first campaign.

Multi-Turn Phishing That Behaves Like a Real Attacker

Instead of single-shot template emails, Cimento’s simulations open a conversation: after the initial lure, an AI agent continues the thread with human-like response delays, working toward credential capture, and ends on configurable triggers. Exa’s first test campaign against sales and engineering surfaced a real-world lesson.

“It’s too easy for people to watch training videos on 2x speed and not even pay attention to it.”

Patrick Schork, Founding Security Engineer at Exa AI

Get Started

See It Live

Explore how modern phishing simulations and real-time human risk insights can strengthen your security posture. Let’s talk.

Get Started

See It Live

Explore how modern phishing simulations and real-time human risk insights can strengthen your security posture. Let’s talk.

Get Started

See It Live

Explore how modern phishing simulations and real-time human risk insights can strengthen your security posture. Let’s talk.

Get Started

See It Live

Explore how modern phishing simulations and real-time human risk insights can strengthen your security posture. Let’s talk.