Skip to content
Chinron
Human risk management · Provable · Localised

Human risk management you can prove — for the industry, region and auditors you actually answer to.

Chinron reduces your team's human risk — and hands you the audit- and insurance-ready evidence that you did. Security awareness training and phishing built for your region and industry, deepfake detection and a continuous human risk score, structured like a compliance program. One platform for organisations of any size and the MSPs who serve them.

Book a demo
Audit- & insurance-ready evidence Continuous human risk scoring Live threat intelligence Expert-approved content Regional data residency
au.chinron.io
Live · Threat landscape

Recent CISA KEV entries — the kind of live feeds Chinron filters to your industry.

Why Chinron is different

Human risk management, built around four ideas

Built for your world

Your team doesn't train on American case studies or fictional companies. Courses, phishing simulations and breach scenarios are built around the services, incidents and regulations they actually recognise. Data stays in-region too — but that's the floor, not the point.

Expert-approved, always current

Every course and simulation is reviewed and signed off by an expert before it reaches your team. AI is what keeps that library mapped to your region, your industry, and the latest threats — at a pace no manual process could match.

Reduce and measure human risk

Industry-specific phishing, image-based deepfake detection, and a continuously-updated human risk score for every user — the behaviour legacy tick-box training never measured. It runs on a cadence: set it up once, it keeps running.

Prove it, on demand

Every completion, phishing result and risk score rolls into an audit- and insurance-ready report — mapped to the specific control each framework requires, with a documented due-diligence trail of every reminder sent. Reduce human risk, and prove your organisation did its part.

Localised · Industry-specific · Framework-aligned

Every other platform sends your team a module written for somewhere else.

Most security awareness training is built once, in one country, and shipped everywhere. The phishing lures reference services nobody in your office uses. The breach examples are from companies your team has never heard of. The regulatory references are for a different legal system entirely.

Your people complete it because they have to. They don't remember it because it doesn't feel real.

Chinron builds training for the world your team actually works in. If your team is in Australia, they train on Australian threats, Australian services, Australian regulatory events. When you expand to the UK or Canada, those teams get locally contextualised content automatically — not because someone swapped out a template, but because that's how the platform works.

The platform

Everything built around how humans actually fail

The most common breach vector isn’t a zero-day — it’s a person making a decision under pressure. Chinron is built around that reality.

Phishing simulation

Industry-targeted phishing, not recycled spam

Today’s phishing is personalised, sector-specific and indistinguishable from legitimate mail. Chinron’s simulations mirror what your industry actually sees — so your people practise on realistic attacks, then learn the moment they slip.

  • Templates built for your sector — financial fraud lures for accounting, patient-portal spoofs for healthcare
  • Scheduled, recurring campaigns with real-time open and click tracking
  • Fail a sim and you’re automatically assigned a targeted refresher — the loop closes without an admin lifting a finger
  • Spot-the-Phish covers the blind spot every phishing program has — execs, floor staff and anyone without an inbox get playable, in-platform phishing training, so your whole workforce is measured, not just the mailbox-holders
au.chinron.io
Courses & training paths

Always current. Always expert-approved.

A library your team will actually finish. Every module is built around the threats, services and incidents your region and industry actually face — so training feels real, because it is. And nothing reaches your team until a person has signed off on it.

  • Content built for your region and industry — local examples, local incidents, local regulatory context
  • Cadenced training paths release the right course to the right department automatically
  • Bite-sized modules with 100% completion — every learner who starts, finishes, across all clients on the platform
  • Pace monitoring flags course rushing under 60 seconds — completion means engagement, not just a click-through
au.chinron.io
Deepfake detection

Train for AI-generated images attackers already use

AI-generated images are being used in impersonation attempts your employees have never been trained to spot. Chinron builds that skill progressively, so recognising a synthetic image becomes second nature.

  • A progressive challenge path of real vs AI-generated images
  • Teaches the tells — extra fingers, garbled background text, impossible reflections
  • Delivered in a cadence so the skill builds over time, not a one-off quiz
au.chinron.io
Human risk scores

Know your highest-risk users before attackers do

The Chinron Human Risk Score gives every active user a number built from what they actually do — not who they are on paper. It’s not a blame tool, it’s a targeting tool: know where to focus attention, reassign training, or increase simulation frequency.

  • Built from four real behavioural signals — phishing response, training engagement, deepfake accuracy, and course pace
  • Not a survey. Not a role assumption. Actual observed behaviour, updated continuously
  • Tracked over time — watch your organisation’s risk trajectory fall as training lands, and prove the reduction to your board and insurer
  • High-risk users surfaced on the dashboard and in every PDF and CSV export
au.chinron.io
Compliance evidence

Don’t just reduce human risk — prove you did

The hardest part of a cyber-insurance renewal or an audit isn’t doing the training — it’s proving it happened, and proving you weren’t negligent when someone ignored it. Chinron turns your program’s activity into defensible, control-mapped evidence on demand — so “we run security awareness training” becomes a document you can hand over.

  • Every completion, phishing result and risk score rolls into one audit- and insurance-ready report
  • Mapped to the specific control each framework asks for — HIPAA §164.308(a)(5), Essential Eight ISM-1546, APRA CPS 234 and more
  • Documented due diligence — a timestamped trail of every reminder and escalation, proving your organisation did its part even when an employee didn’t
  • Scoped to any reporting period, exportable to PDF and CSV — the evidence your auditor and insurer actually ask for
au.chinron.io
Live threat intelligence

Train on what’s happening, not last year’s threats

Your threat landscape changes weekly. Chinron pulls live intelligence and filters it to your sector, so training reflects the attacks targeting organisations like yours right now.

  • Real-time feeds from CISA KEV, NIST NVD and MITRE ATT&CK
  • Filtered to the threats actually relevant to your industry
  • Feeds straight into the content your team trains on
au.chinron.io
Tari, the Mentor — a Chinron Sentinel companion
Tari · The Mentor
Engagement

Meet your Sentinel

The hardest part of awareness training isn’t the content — it’s getting people to finish it. So every learner gets a Sentinel: a companion that guides them, reacts to how they’re doing, and levels up as their security instincts grow.

  • Choose the companion whose personality fits — Tari, Sekai, Faro or Kuda
  • It levels through tiers as training and phishing performance improve
  • New lore unlocks as your team progresses — a reason to come back
  • The engagement layer that finally makes security training stick

Four companions. Pick your guide.

Each learner chooses the personality that motivates them. Same training, very different company.

Tari, The Mentor
Tari The Mentor

Calm, grounded and encouraging. Guides your team with steady confidence and genuine warmth.

Sekai, The Strategist
Sekai The Strategist

Sharp, analytical and tactical. Cuts straight to the threat with precision and a knowing smirk.

Faro, The Optimist
Faro The Optimist

Energetic, expressive and relentlessly positive. Turns every lesson into a win.

Kuda, The Wildcard
Kuda The Wildcard

Clever, irreverent and unpredictable. Keeps security training from ever feeling like a chore.

They grow with your team

A Sentinel evolves as security habits build — visible proof of progress your people can see.

Tari at Spark tier
Spark
Day one
Tari at Guardian tier
Guardian
Building the habit
Tari at Vanguard tier
Vanguard
Security second nature
Compliance-calibrated

We don’t just map to your frameworks — we generate the evidence each one asks for

Every framework maps to a specific security-awareness control, and every report shows your coverage against it — HIPAA §164.308(a)(5), Essential Eight ISM-1546, NIST CSF PR.AT-1 and more. Built with the rigour of a formal compliance program: tracked completions, department-based paths and audit-ready records. Every region launches with its own framework set.

ASD Essential Eight
APRA CPS 234
Privacy Act 1988
ISO 27001
NIST CSF
SOC 2
HIPAA
PCI-DSS
GDPR
CMMC
NERC CIP
FERPA

Australia is live with Essential Eight, APRA CPS 234 and the Privacy Act. A UK, US or EU instance launches with its own local set — Cyber Essentials, NCSC, NIST, GDPR and more.

For MSPs

Built for MSPs from day one — not bolted on after

Run human risk management across your entire client portfolio without separate accounts, tools or logins. White-label branding, fully isolated data, portfolio-wide analytics, and a branded, audit-ready evidence report you can hand each client for their auditor or insurer.

White-label branding

Your logo and colours on every client touchpoint — Chinron stays invisible.

Isolated client data

Reports, users, campaigns and risk scores never cross client lines.

Portfolio analytics

Completion, susceptibility and risk across your whole book.

Resale economics

Wholesale pricing that improves with portfolio scale.

Trust

We hold ourselves to the standards we train your team on

Field-level encryption

Credentials, authentication secrets and API keys are encrypted with AES-256-GCM. Passwords are hashed, never stored in recoverable form.

Organisation-level isolation

Every record is scoped to your organisation. Users, training data, phishing results and risk scores never cross organisation boundaries.

Anomaly detection

Impossible travel, new-country access, unrecognised devices and brute-force attempts are detected and flagged in real time.

Your data is never sold

We do not sell, share, or use your employee training data to train third-party AI models. Ever.

Start reducing — and proving — your human risk

Spin up a free trial in your region in minutes — or book a walkthrough tailored to your industry.

Book a demo