Evidence-led comparison · Reviewed 2026-08-19

GoPhish vs TaiGong, capability by capability.

01 / Method
Documented native capability

What the labels mean.

“Documented native” means the capability appears in the reviewed official GoPhish guide. “Not documented as native” does not mean impossible: extensions, custom code, or external systems may add it. TaiGong states use its versioned public matrix.

GoPhish evidenceOFFICIAL GUIDE

Direct documentation, not competitor shorthand.

The reviewed guide documents SMTP sending profiles, campaign launch and send-by scheduling, results and recipient timelines, API access, optionally signed webhooks, self-hosted operation, and User/Admin roles.

TaiGong evidenceVERSION 1.3.4

Core and licensed are different states.

Core is delivered without a dedicated feature entitlement. Licensed capabilities require the matching plan or private license. Integration-only is not a native simulation-delivery channel.

Review dateSources were reviewed on . Both products can change. Read the current official documentation and validate the exact release before procurement or migration.
02 / Feature-by-feature
Facts · Boundary · Source

Both cover the campaign fundamentals.

TaiGong’s differentiation begins after the basic email workflow: versioned human-risk operations, licensed channels, training, automation, advanced analytics, and managed SaaS.

CapabilityGoPhish official guideTaiGong Drill 1.3.4Evidence
SMTP email campaigns Documented native
Sending Profiles configure the SMTP relay, authentication, sender, headers, and certificate behavior used by campaigns.
Core
Native SMTP campaigns with targets, groups, templates, landing pages, tracking, and evidence.
GoPhish Sending Profiles ↗
TaiGong delivery matrix →
Templates, landing pages, and recipient groups Documented native
Campaign configuration uses an email template, landing page, URL, sending profile, and one or more groups.
Core
Equivalent campaign resources are part of the Community email baseline.
GoPhish Campaigns ↗
TaiGong availability →
Scheduled launch and send-by pacing Documented native
Launch Date schedules the start; Send Emails By spreads delivery evenly through a deadline.
Core
Launch date and send-by date are shipped campaign fields with scheduled and distributed email delivery.
GoPhish scheduling ↗
TaiGong matrix →
Campaign results, event timeline, and recipient detail Documented native
Results include status, raw events, recipient timelines, opens, clicks, submissions, and user-agent-derived device detail.
Core
Campaign funnel, results, sent/opened/clicked/submitted/reported events, recipient timelines, comparison, retraining, and evidence.
GoPhish results ↗
TaiGong operations matrix →
CSV and campaign reporting Documented native
The UI exports campaign results and raw events as CSV; the guide also points to API-based and community reporting.
Core
Base campaign evidence and supported exports are delivered. Licensed Advanced analytics and PDF reports require entitlement.
GoPhish reports ↗
TaiGong reporting boundary →
REST API Documented native
The official API exposes campaigns, results, summaries, templates, pages, groups, sending profiles, users, and settings through API-key authentication.
Core
API tokens and platform APIs support campaign and resource integration. Feature entitlements still apply to gated operations.
GoPhish Campaign API ↗
TaiGong API documentation →
Event webhooks and signatures Documented native
Webhooks push campaign events and can be signed with an HMAC-SHA256 secret in the X-Gophish-Signature header.
Integration-only
Outbound TaiGong event webhooks support HMAC signing. A webhook connection does not add a simulation-delivery channel.
GoPhish Webhooks ↗
TaiGong governance matrix →
User roles and governed access Documented native
GoPhish documents global User and Admin roles; accounts own separate campaigns and resources.
Core
Tenant-aware request handling and API tokens. Licensed Resource-level RBAC and searchable/exportable audit console.
GoPhish User Management ↗
TaiGong governance matrix →
Self-hosted deployment Documented native
The official guide describes operating the local Gophish server and its configuration.
Core
Private single-node deployment is shipped with SQLite as the default database; packaged-server and Docker paths are documented.
GoPhish operation guide ↗
TaiGong self-hosted →
Managed multi-tenant SaaS Not documented as native
The reviewed official guide documents the self-operated product, not an official managed multi-tenant service.
Core deployment mode
Shipped SaaS mode with tenant-aware request handling, API tokens, MySQL, and Docker Compose deployment assets.
Current GoPhish guide ↗
TaiGong deployment matrix →
Human-risk management Not documented as native
The reviewed guide documents campaign statistics and reporting, but not a native human-risk scoring and follow-up operating model.
Core
Base campaign evidence and risk signals. Licensed High-risk users, trends, geography, department exposure, rankings, threat context, and advanced reports.
GoPhish reporting guide ↗
TaiGong human risk →
Security-awareness courses and training batches Not documented as native
No native course, batch, assessment, and completion workflow was found in the reviewed official guide.
Licensed
Awareness courses, batches, assessments, completion views, and built-in scenarios require the awareness/scenarios entitlement.
GoPhish documentation index ↗
TaiGong operations matrix →
Multi-stage orchestration and event automation Not documented as native
The reviewed guide documents campaign launch scheduling, but not native cross-stage orchestration, event rules, or execution history.
Licensed
Campaign stages, automation rules, scheduled triggers, executions, and event-driven actions require the automation entitlement.
GoPhish campaign scheduling ↗
TaiGong automation boundary →
SMS and enterprise-messaging simulation delivery Not documented as native
The reviewed official workflow is centered on SMTP email campaigns. No native SMS or enterprise-IM delivery provider is documented.
Licensed
SMS: Aliyun, Tencent Cloud, and Twilio. DingTalk: robot webhook and App direct messaging. Feishu China: robot and App delivery. WeCom: group robot webhook only.
GoPhish Campaigns ↗
TaiGong channel matrix →
Slack and Microsoft Teams delivery Not documented as native
Generic signed webhooks are documented; native Slack or Teams phishing-simulation delivery is not.
Slack: Integration-only
Outbound event formatting only; no Slack simulation delivery. Teams: Unsupported No provider or Teams-specific event adapter in 1.3.4.
GoPhish Webhooks ↗
TaiGong channel matrix →
AI assistance and autonomous agents Not documented as native
No AI content, insight, or autonomous-agent workflow was found in the reviewed official guide.
Licensed assistance
Email, SMS, IM, and insight generation require an external model provider and key. Autonomous Agent: Unsupported No autonomous planning or agent runtime is shipped in 1.3.4.
GoPhish documentation index ↗
TaiGong AI/MCP matrix →
03 / How to read the result
Shared fundamentals · Different scope

The difference is not “campaigns versus no campaigns.”

Both products document the essential email-campaign workflow. The practical decision is whether the program also needs native human-risk operations, licensed training, multi-stage automation, additional delivery providers, managed SaaS, or TaiGong’s governance model.

GoPhish may fit when

The email campaign is the product boundary.

The official guide documents a capable self-hosted email workflow with scheduling, results, timeline detail, CSV, API, signed webhooks, and User/Admin roles.

  • SMTP email is sufficient
  • Risk and training live elsewhere
  • Custom integrations are acceptable
  • Your team operates the deployment
Read current GoPhish docs ↗
TaiGong may fit when

The workflow continues after campaign results.

TaiGong connects core campaign evidence to a versioned platform model, then adds human-risk operations and licensed channels, analytics, awareness, automation, RBAC, auditing, and advanced controls.

  • SaaS or self-hosted is required
  • Follow-up must be risk-based
  • Licensed modules should stay explicit
  • Advanced capability needs governance
Compare your workflow
Evidence-led evaluation

Compare one representative workflow.

Bring the campaign, data boundary, integrations, reporting, and follow-up requirements your team uses today.