UNCRYPT

Employee training platform

Train your people.
Keep the proof.

Roll out any training your company needs — security, onboarding, policies, role-specific skills — to everyone, and watch completion land in real time. Every completion leaves proof behind, which is what turns the same programme into compliance evidence when someone asks.

Reviewed by a person · No card, no auto-renew

0frameworks mapped
ISO 27001 · SOC 2 · HIPAA · PCI DSS · GDPR
0individual controls each course can be tagged against
0ready-made courses, assignable on day one
SHA-256hash chain over every recorded action

How a campaign runs

One flow, from decision to evidence.

Pick what people need to do — take a training path, or read and formally acknowledge a policy — choose who it applies to, and let it run. Completion arrives as it happens.

  1. 01Build a campaign

    Name it, set a due date, pick the audience.

  2. 02 · Option AA training path

    Slides then a scored quiz, ending in a certificate.

  3. 02 · Option BA policy document

    Read to the end, then sign — recorded as an e-signature.

  4. 03Assign to your people

    Everyone is invited by email. Reminders escalate on their own.

  5. 04Evidence

    Live progress, then a pack you can hand over.

What it does

Everything a compliance training programme needs.

Campaigns that repeat

Assign annually or every N months. Expiry, reassignment and escalating reminders run without anyone remembering.

Policies, properly signed

Upload a PDF or DOCX. People must reach the end before they can acknowledge. Publish a new version and everyone re-signs.

Certificates that verify

Issued automatically on completion, with an ID anyone can check publicly — no login, no account, no phone call.

Framework coverage

Tag any course to the controls it satisfies, then read coverage per control — covered, partial, or a gap you need to close.

The part that matters

Records that hold up when someone checks.

A completion report is only worth what its integrity is worth. Every record here is signed, and tampering is detectable rather than deniable.

  • Tamper-evident audit log Every action is HMAC-chained to the one before it. Editing or deleting a row breaks the chain and the console names the row where it broke.
  • Signatures over the whole record Name, course, score, dates and issuer are all inside the signature. Change any one of them in the database and public verification stops saying "valid".
  • An evidence pack, not a screenshot One click exports members, assignments, certificates, acknowledgements, activity and framework coverage as CSVs, with the audit seal in the README.
  • GDPR built in, not bolted on Export or erase one person's record. Erasure can keep signed certificates as Article 17(3) evidence while scrubbing the identity around them.
Valid certificate
Awarded to
Priya Sharma
Training completed
Phishing Awareness
Issued by
Acme Security Ltd
Valid until
2027-03-14
Certificate ID
UNC-7K3F-9T2Q

An example of what a verifier sees at /verify — the holder's name, the course and the issuer, and nothing else about them. Scores are deliberately not published.

Compliance mapping

Answer "which control does this cover?" in one place.

Courses carry the control codes they satisfy. Coverage is then computed from what your people have actually completed — not from what was assigned.

ISO 27001 8 training-relevant controls
SOC 2 8 training-relevant controls
HIPAA 7 training-relevant controls
PCI DSS 6 training-relevant controls
GDPR 5 training-relevant controls

Training library

Ready to assign on day one.

Maintained by us and already tagged to the frameworks above. Build your own courses alongside them whenever you need something specific to your business.

AI & Emerging Tech

AI Security Awareness

Using AI assistants at work without leaking data, being misled, or approving something you did not read.

Data Protection

Data Protection & Privacy

What counts as personal data, how to handle it, and what to do the moment it goes astray.

Human Risk

Social Engineering

How attackers use trust, urgency and authority to get what they want — and the one habit that stops them.

Identity & Access

Password & Authentication Security

Strong passphrases, password managers and the second factor — the habits that stop account takeover.

Incident Response

Incident Reporting

What to report, how to report it well, and why speaking up early is what keeps small problems small.

Phishing Defense

Phishing Awareness Training

Spot and stop phishing: email, chat, SMS and voice — and what to do when you slip.

Policy & Conduct

Acceptable Use

Where the line sits on work devices, accounts, software and data — including the day you leave.

Remote & Hybrid Work

Remote Working Security Training

Stay secure outside the office: networks, devices, data and habits for working from anywhere.

Secure Development

Developer Secure Coding Training

The vulnerability classes behind most breaches — and the code patterns that prevent them.

Security Awareness

Annual Security Awareness Training

The yearly baseline: threats, passwords, devices, data handling and incident reporting.

Getting started

Three steps, and a person at the first one.

We don't open the platform to whoever fills in a form. Every request is read by a person before access is issued.

STEP 01

Tell us about your team

Company, roughly how many people, and what you want to roll out. Takes a minute.

STEP 02

We send you a key

Tied to your company email domain, with a seat count and an end date on it. We turn these around as quickly as we can.

STEP 03

Invite your people

Set up your account, invite the team one by one or by CSV, and launch your first campaign.

Questions

Straight answers.

What is Uncrypt?

Uncrypt is an employee training platform. Companies assign courses or policy documents to their staff as campaigns and track completion in real time. Because every completion is recorded and signed, the same programme also produces the evidence an auditor asks for.

How do employees prove they completed training?

Every completion issues a certificate automatically, carrying a unique ID in the form UNC-XXXX-XXXX. Anyone can check that ID at https://uncrypt.net/verify without an account, and the page confirms whether the record is genuine, expired or revoked.

Which compliance frameworks does Uncrypt map to?

Courses can be tagged against 34 training-relevant controls across 5 frameworks: ISO 27001, SOC 2, HIPAA, PCI DSS and GDPR. Coverage is then calculated from what employees have actually completed, not from what was assigned to them.

Can Uncrypt handle policy acknowledgements as well as courses?

Yes. A campaign can assign a policy document instead of a training path. Employees must read to the end before they can acknowledge it, the acknowledgement is recorded as an electronic signature bound to the document hash, and publishing a new version requires everyone to sign again.

How does Uncrypt prevent training records from being altered?

Every recorded action is chained to the one before it with an HMAC, so editing or deleting a row breaks the chain and is detected. Certificate signatures cover the holder name, course, score, dates and issuer, so an altered record stops verifying.

Is there a free trial?

Yes. Requests are reviewed by a person rather than granted automatically, and access is issued as a demo key tied to your company email domain with a set number of seats and an end date. No payment details are required and there is nothing to cancel.

Isolated per company. Your people and your records are scoped to your organisation alone, and everything sensitive is encrypted at rest. No other customer can reach any part of your account.

Run it on your own team first.

A real campaign with your people and your courses — not a sandbox full of sample data. Tell us what you need and we'll set it up.