Name it, set a due date, pick the audience.
Employee training platform
Train your people.
Keep the proof.
Roll out any training your company needs — security, onboarding, policies, role-specific skills — to everyone, and watch completion land in real time. Every completion leaves proof behind, which is what turns the same programme into compliance evidence when someone asks.
Reviewed by a person · No card, no auto-renew
ISO 27001 · SOC 2 · HIPAA · PCI DSS · GDPR
How a campaign runs
One flow, from decision to evidence.
Pick what people need to do — take a training path, or read and formally acknowledge a policy — choose who it applies to, and let it run. Completion arrives as it happens.
Slides then a scored quiz.
certificateRead to the end, then sign.
e-signatureEveryone is invited by email. Reminders escalate on their own.
Live progress, then a pack you can hand over.
- 01Build a campaign
Name it, set a due date, pick the audience.
- 02 · Option AA training path
Slides then a scored quiz, ending in a certificate.
- 02 · Option BA policy document
Read to the end, then sign — recorded as an e-signature.
- 03Assign to your people
Everyone is invited by email. Reminders escalate on their own.
- 04Evidence
Live progress, then a pack you can hand over.
What it does
Everything a compliance training programme needs.
Campaigns that repeat
Assign annually or every N months. Expiry, reassignment and escalating reminders run without anyone remembering.
Policies, properly signed
Upload a PDF or DOCX. People must reach the end before they can acknowledge. Publish a new version and everyone re-signs.
Certificates that verify
Issued automatically on completion, with an ID anyone can check publicly — no login, no account, no phone call.
Framework coverage
Tag any course to the controls it satisfies, then read coverage per control — covered, partial, or a gap you need to close.
The part that matters
Records that hold up when someone checks.
A completion report is only worth what its integrity is worth. Every record here is signed, and tampering is detectable rather than deniable.
- Tamper-evident audit log Every action is HMAC-chained to the one before it. Editing or deleting a row breaks the chain and the console names the row where it broke.
- Signatures over the whole record Name, course, score, dates and issuer are all inside the signature. Change any one of them in the database and public verification stops saying "valid".
- An evidence pack, not a screenshot One click exports members, assignments, certificates, acknowledgements, activity and framework coverage as CSVs, with the audit seal in the README.
- GDPR built in, not bolted on Export or erase one person's record. Erasure can keep signed certificates as Article 17(3) evidence while scrubbing the identity around them.
- Awarded to
- Priya Sharma
- Training completed
- Phishing Awareness
- Issued by
- Acme Security Ltd
- Valid until
- 2027-03-14
- Certificate ID
- UNC-7K3F-9T2Q
An example of what a verifier sees at /verify — the holder's name, the course and the issuer, and nothing else about them. Scores are deliberately not published.
- #1482certificate.issue4d5cea52
- #1481attempt.finish2b30b74d
- #1480campaign.assign70640fec
- #1479policy.acknowledgec600da61
Each entry is chained to the one above it. Recomputing the chain is how the console proves no row was edited, added or removed after the fact.
Compliance mapping
Answer "which control does this cover?" in one place.
Courses carry the control codes they satisfy. Coverage is then computed from what your people have actually completed — not from what was assigned.
Training library
Ready to assign on day one.
Maintained by us and already tagged to the frameworks above. Build your own courses alongside them whenever you need something specific to your business.
AI & Emerging Tech
AI Security Awareness
Using AI assistants at work without leaking data, being misled, or approving something you did not read.
Data Protection
Data Protection & Privacy
What counts as personal data, how to handle it, and what to do the moment it goes astray.
Human Risk
Social Engineering
How attackers use trust, urgency and authority to get what they want — and the one habit that stops them.
Identity & Access
Password & Authentication Security
Strong passphrases, password managers and the second factor — the habits that stop account takeover.
Incident Response
Incident Reporting
What to report, how to report it well, and why speaking up early is what keeps small problems small.
Phishing Defense
Phishing Awareness Training
Spot and stop phishing: email, chat, SMS and voice — and what to do when you slip.
Policy & Conduct
Acceptable Use
Where the line sits on work devices, accounts, software and data — including the day you leave.
Remote & Hybrid Work
Remote Working Security Training
Stay secure outside the office: networks, devices, data and habits for working from anywhere.
Secure Development
Developer Secure Coding Training
The vulnerability classes behind most breaches — and the code patterns that prevent them.
Security Awareness
Annual Security Awareness Training
The yearly baseline: threats, passwords, devices, data handling and incident reporting.
Getting started
Three steps, and a person at the first one.
We don't open the platform to whoever fills in a form. Every request is read by a person before access is issued.
Tell us about your team
Company, roughly how many people, and what you want to roll out. Takes a minute.
We send you a key
Tied to your company email domain, with a seat count and an end date on it. We turn these around as quickly as we can.
Invite your people
Set up your account, invite the team one by one or by CSV, and launch your first campaign.
Questions
Straight answers.
What is Uncrypt?
Uncrypt is an employee training platform. Companies assign courses or policy documents to their staff as campaigns and track completion in real time. Because every completion is recorded and signed, the same programme also produces the evidence an auditor asks for.
How do employees prove they completed training?
Every completion issues a certificate automatically, carrying a unique ID in the form UNC-XXXX-XXXX. Anyone can check that ID at https://uncrypt.net/verify without an account, and the page confirms whether the record is genuine, expired or revoked.
Which compliance frameworks does Uncrypt map to?
Courses can be tagged against 34 training-relevant controls across 5 frameworks: ISO 27001, SOC 2, HIPAA, PCI DSS and GDPR. Coverage is then calculated from what employees have actually completed, not from what was assigned to them.
Can Uncrypt handle policy acknowledgements as well as courses?
Yes. A campaign can assign a policy document instead of a training path. Employees must read to the end before they can acknowledge it, the acknowledgement is recorded as an electronic signature bound to the document hash, and publishing a new version requires everyone to sign again.
How does Uncrypt prevent training records from being altered?
Every recorded action is chained to the one before it with an HMAC, so editing or deleting a row breaks the chain and is detected. Certificate signatures cover the holder name, course, score, dates and issuer, so an altered record stops verifying.
Is there a free trial?
Yes. Requests are reviewed by a person rather than granted automatically, and access is issued as a demo key tied to your company email domain with a set number of seats and an end date. No payment details are required and there is nothing to cancel.
Run it on your own team first.
A real campaign with your people and your courses — not a sandbox full of sample data. Tell us what you need and we'll set it up.