Fensivo is the human risk management platform built for Latin America.
More than 90% of successful cyberattacks begin with a phishing email, yet the budget allocated to protect people is a tiny fraction of the total. Fensivo exists to close that gap: real behavior under real attack.
The cybersecurity industry invests billions every year in technology: firewalls, endpoint detection, Zero Trust architectures. All that investment rests on one premise —that the attacker will try to breach the machine— but the sophisticated attacker knows it's easier to convince a person.
The number changes, the pattern doesn't: most attacks come through the door technology cannot close.
of successful cyberattacks begin with a phishing email
CISA
of breaches involve a human factor, per the 90-5-5 framework, while security investment stays concentrated in the technical layer
Cisco
to be operational, with the first executive report within 48 hours
Fensivo
The problem isn't just how much is invested, it's what's measured. For years, the industry optimized the wrong metric: training completed, click rate. None of those numbers answer the only question that matters: whether that person will fall or not when the real attack arrives.
Fensivo doesn't measure finished courses, it measures real behavior under real attack — and that's the difference between a completion certificate and a defense.
Watches for compromised credentials across 680+ breach databases.
Runs simulations that adapt to each person and their context.
Delivers 3–5 minute microtraining at the exact moment of the error.
Each simulation feeds the next, so the defense becomes more specific over time. Explore the full platform →
Fensivo was born from combining two experiences that seemed unrelated. Its founder, José Vicente Chávez, spent eight years at Rappi designing personalization campaigns for over 350 brands across nine countries. There he learned that a good campaign depends on three things: the right user, the precise moment, and the right message.
Later, as COO of an offensive security firm, he helped grow revenue 9.5× in 18 months through ethical hacking. The team was good at finding technical vulnerabilities, until the data made an uncomfortable truth clear: they were solving a tiny fraction of the problem. Their clients were building impenetrable castles where people opened the doors to anyone who rang the bell.
There was the connection: attackers use exactly the same framework as a good marketing team —extreme personalization, perfect timing, precise targeting— only the goal changes. With artificial intelligence, that framework no longer needs a team of fifty; today three seconds of audio is enough to clone a voice.
Fensivo unites offensive and defensive, because in human risk they are inseparable.
If attack and defense speak the same language, the only way to truly prepare a team is to attack it first, in a controlled environment, so it recognizes the signal when the real attack arrives.
Four principles guide every product decision.
Completing a module doesn't change a response under pressure. Only one of the two matters when the attack arrives.
Microtraining delivered right after a failure is retained far better than the same information weeks later in a scheduled course.
There is no message that fools everyone; there is the one that fools that person in that context. Fensivo's defense is just as specific.
Fensivo doesn't inflate metrics to make the dashboard look good: it reports what changed and what hasn't, because that's the information that truly protects.

Founder & CEO
Eight years at Rappi in monetization and personalization for 350+ brands across nine countries, plus experience as COO in offensive cybersecurity.
LinkedIn
Head of Product & Technology
Technical architect of the platform, responsible for its implementation, deployment, and continuous evolution.
LinkedInFensivo monitors leaked credentials, which is why data handling is part of the service's design, not a footnote. It operates as Data Processor under Colombia's Law 1581 of 2012 and Decree 1377 of 2013.
The contracting organization acts as Data Controller and authorizes the processing of its employees' data through a data processing agreement.
Four safeguards
Open-source intelligence (OSINT) enrichment capabilities are in development and will be activated only after the corresponding legal validation.
Fensivo is Latin America–native. It's not a translated tool: it's built on the region's regulatory context, attack patterns, and risk profiles.
Colombia
Mexico
Central America
We'll show you how Fensivo measures and reduces human risk in your organization.