Skip to content

Start here

How can we help?

Answers for the people doing the training and the people running it. A person reads every message we receive.

Write to us

For anything not answered here.

hello@underwing.co.za

Something claiming to be from us that doesn’t look right? Forward it to security@underwing.co.za.

For your team

You've been invited to Underwing by your organisation. Here's how it works for you.

Is this email really from Underwing?

Our email comes from hello@mail.underwing.co.za and our links go to underwing.co.za. Read the address from the right: the name before .co.za is always exactly underwing, so an address like underwing-security.co.za isn't us. We'll never ask for your password, a one-time code or new banking details. If something claims to be from us and asks for any of those, don't act on it: forward it to security@underwing.co.za.

How to recognise us →

Can I do the training on my phone, or on limited data?

Yes. Lessons are made for phones first, play with captions on, and have a low-data option. A lesson and its quiz take about nine minutes; the rest of the month is a 30-second challenge, a short read and a one-page card.

Who can see my results?

Your manager sees whether you've finished each lesson and where you might need support. They don't see a ranking, and our terms don't allow results to be used in disciplinary action.

What managers can see →

For managers and account owners

Running Underwing for your organisation, or about to.

How do I sign in?

Enter your work email on the sign-in page. We email you a link, and your device confirms it's you with a passkey: your fingerprint, face or screen-lock PIN. After the first time, you can sign in with the passkey alone. There's no password to forget or to steal.

Sign in →

Adding or removing people

Add or remove people from your dashboard at any time, or upload your team list. People who leave stop receiving lessons straight away. If your team grows past your plan's size, we'll suggest the next plan before anything changes.

Our lesson emails are going to spam

Ask whoever looks after your email to allowlist our sending domain, mail.underwing.co.za. It's signed (DKIM and SPF), so they can trust it safely. It takes a few minutes, and we'll send them a one-page guide. Nothing needs to be installed.

Reports and proof of training

You get a report at the start of every month. Certificates and an evidence export for auditors, boards and insurers are in your dashboard whenever you need them.

Billing, invoices and cancelling

Card payments are handled by Paystack; we never see or store your card number. Invoices are emailed and kept in your dashboard. Monthly plans cancel at any time and stop at the end of the month you've paid for. Paying by invoice and EFT is available for organisations over 100 people.

Pricing →

Have Underwing's banking details changed?

No. Our banking details will never change by email. If you receive a message saying they have, don't pay: it isn't from us. Forward it to security@underwing.co.za.

Security, privacy and data

For your IT, risk and compliance people.

Report a security vulnerability

Found a weakness in Underwing? Tell us privately and we'll work with you to fix it. Please don't test against other customers' data.

Our disclosure policy →

Access, correct or delete personal information

Under POPIA you can ask what we hold about you, and ask us to correct or delete it. Write to privacy@underwing.co.za. If you're on a team, your organisation is the responsible party and we'll work with them.

Privacy policy →

Where is our data stored?

In South Africa, in Amazon Web Services' Cape Town region. Our emails are delivered by Resend, in Ireland. We keep only what the training needs: names, work emails and results.

Trust centre →

If something has already happened

Acting in the first hour matters more than anything else. These are the first steps, whoever you are. Underwing is training, not an incident-response service, so for help beyond this, start with your bank and your IT provider.

  1. 01

    Money paid or banking details shared

    Call your bank's fraud line now, on the number on your card or the bank's own website, not one from a message. The sooner they know, the more they can do.

  2. 02

    A password or sign-in code shared

    Change that password from a device you trust, sign out of other sessions, and tell whoever looks after your IT.

  3. 03

    An attachment opened or a program installed

    Disconnect the device from Wi-Fi and the network, and call your IT person before you do anything else.

  4. 04

    Then

    Report it at your nearest police station and keep the messages as evidence. Tell your team what happened: the next attempt usually follows the first.

Looking for something else? Read the questions people ask before they start, visit the trust centre, or report a vulnerability through our disclosure policy.