Comparison

Pavlov vs GoPhish

In short: GoPhish is free, open-source, and self-hosted — total control, but you run and maintain everything. Pavlov is managed, white-label simulation delivered by API for trainers, MSPs, and platforms who want GoPhish-style own-brand delivery without operating the infrastructure. Choose GoPhish if you want to self-host; choose Pavlov if you want simulations as a branded service you don't have to run.

What is GoPhish?

GoPhish is the most widely used free, open-source phishing framework, distributed under the MIT license as a single binary. It gives you complete control of your phishing infrastructure and data. In exchange, you own everything operationally: deployment, server security, email deliverability, and ongoing maintenance. It has no built-in awareness-training content or vendor support, so it's most popular with red teams and engineers comfortable running their own stack.

What is Pavlov?

Launching Fall 2026 — this describes Pavlov's product approach.

Pavlov is white-label security simulation as a service, delivered by API and MCP. It's built for the people who deliver training — trainers, training providers, MSPs — and for platforms that want to embed simulations under their own brand. The simulation engine runs as managed infrastructure, so there are no servers to maintain, and the experience your audience sees carries your name, not Pavlov's.

Side by side

 GoPhishPavlov
ModelOpen-source, self-hostedManaged white-label API / MCP
Best forTechnical / red teamsTrainers, MSPs, platforms
BrandingYour own (you host it)Your own (white-label, managed)
Infrastructure & upkeepYou run and maintain itManaged for you
Email deliverabilityYour responsibilityHandled by the platform
IntegrationManual / DIYAPI and MCP first
CostFree (plus your time & infra)Pricing at launch
StatusAvailableLaunching Fall 2026

Who should choose which

Choose GoPhish if you have the technical capacity and want to own every layer for free, and you're securing your own organization. Choose Pavlov if you want GoPhish's own-brand delivery without running servers — especially if you deliver simulations to clients or want to build them into your own product by API.

Want GoPhish-style control without the upkeep?

Pavlov is managed, white-label simulation by API. Join the waitlist for the Fall 2026 launch.

Join the waitlist