Comparison
Pavlov vs GoPhish
In short: GoPhish is free, open-source, and self-hosted — total control, but you run and maintain everything. Pavlov is managed, white-label simulation delivered by API for trainers, MSPs, and platforms who want GoPhish-style own-brand delivery without operating the infrastructure. Choose GoPhish if you want to self-host; choose Pavlov if you want simulations as a branded service you don't have to run.
What is GoPhish?
GoPhish is the most widely used free, open-source phishing framework, distributed under the MIT license as a single binary. It gives you complete control of your phishing infrastructure and data. In exchange, you own everything operationally: deployment, server security, email deliverability, and ongoing maintenance. It has no built-in awareness-training content or vendor support, so it's most popular with red teams and engineers comfortable running their own stack.
What is Pavlov?
Launching Fall 2026 — this describes Pavlov's product approach.
Pavlov is white-label security simulation as a service, delivered by API and MCP. It's built for the people who deliver training — trainers, training providers, MSPs — and for platforms that want to embed simulations under their own brand. The simulation engine runs as managed infrastructure, so there are no servers to maintain, and the experience your audience sees carries your name, not Pavlov's.
Side by side
| GoPhish | Pavlov | |
|---|---|---|
| Model | Open-source, self-hosted | Managed white-label API / MCP |
| Best for | Technical / red teams | Trainers, MSPs, platforms |
| Branding | Your own (you host it) | Your own (white-label, managed) |
| Infrastructure & upkeep | You run and maintain it | Managed for you |
| Email deliverability | Your responsibility | Handled by the platform |
| Integration | Manual / DIY | API and MCP first |
| Cost | Free (plus your time & infra) | Pricing at launch |
| Status | Available | Launching Fall 2026 |
Who should choose which
Choose GoPhish if you have the technical capacity and want to own every layer for free, and you're securing your own organization. Choose Pavlov if you want GoPhish's own-brand delivery without running servers — especially if you deliver simulations to clients or want to build them into your own product by API.
Want GoPhish-style control without the upkeep?
Pavlov is managed, white-label simulation by API. Join the waitlist for the Fall 2026 launch.
Join the waitlist