Security awareness with a defensible record

Security training that survives inspection.

Continuous security awareness for any organization that has to prove its people were trained. Twelve core modules, monthly reinforcement, and a training record built to be inspected — so when an auditor, an assessor or a customer says show me your evidence, it takes ninety seconds, not two weeks.

Regulated? Add the pack your framework names: 21 CFR Part 11 · HIPAA · GLBA · PCI DSS · NIST 800-171 · ISO 27001

Training record · export preview ◼ Verified
Person
M. Okafor · Accounts Payable Specialist
Module
A.1 — Phishing, Spear Phishing & Social Engineering
Version
2.4.0 (effective 2026-06-01)
Completed
2026-08-14 09:41:07 CDT
Assessment
94% · threshold 80% · 1 attempt
Signature
Electronic · meaning: completed and understood
Record ID
TS-8841-A1-0714
Audit trail · 4 entries · no modifications Retention: per records policy

Illustrative export. Every completion produces one of these.

The problem

The annual video is not a program.

Most security awareness training exists to be completed, not to change behavior. Once a year, everybody clicks through forty minutes of stock footage, and the organization goes eleven months without another word about it — while the phishing gets better every quarter.

Then someone asks for proof. A customer security questionnaire, a SOC 2 auditor, a HIPAA risk analysis, a cyber-insurance renewal, an FDA inspector. Every one of them wants the same thing: who was trained, on what, when, and can you show it. A completion checkbox in a generic LMS is not an answer.

Annual compliance video

  • One 40-minute sitting, once a year
  • Same content for the engineer, the receptionist and the CFO
  • Generic curriculum with a compliance module bolted on
  • Nothing about the provision your assessor actually cites
  • Evidence is a spreadsheet export someone reformats under pressure
  • Content ages for twelve months while threats don't

Trained State

  • Annual course establishes the baseline, assessed and signed
  • Monthly units of three to five minutes keep it current
  • Role variants so people learn what applies to their job
  • Add-on packs cover the regulation your framework names, by section
  • Inspection packet exports attributable, timestamped records on demand
  • Event-driven units ship within 48 hours of a real incident

Who it's for

Anyone who gets asked for proof.

Companies proving it to customers

Security and compliance leads answering questionnaires and SOC 2 or ISO 27001 auditors, who need training evidence that does not have to be assembled by hand.

Healthcare & covered entities

Providers, plans and business associates whose risk analysis and workforce training are the first two things a HIPAA reviewer asks about.

Clinical research

Sites, CROs, sponsors and trial vendors who get audited by sponsors and inspected by regulators. There is a page for you.

Finance, payments & government contractors

Organizations whose regulator or contract names a training requirement by section, and whose assessor will check for it.

Pilot program

Start with the core. Add the pack.

We're onboarding a small number of design partners. Clinical research organizations get the Clinical & GxP pack now; if your sector's pack is on the roadmap, a design partner is how it gets built. You get the program first, we get your audit findings and your people's honest opinion of the content. Fair trade.

Developed with a clinical research design partner · STACSTRAT LLC