Human risk management you can prove — for the industry, region and auditors you actually answer to.
Chinron reduces your team's human risk — and hands you the audit- and insurance-ready evidence that you did. Security awareness training and phishing built for your region and industry, deepfake detection and a continuous human risk score, structured like a compliance program. One platform for organisations of any size and the MSPs who serve them.
Recent CISA KEV entries — the kind of live feeds Chinron filters to your industry.
Whether you run a business or serve dozens of them
Chinron is built for direct organisations and the managed service providers who deliver security to their whole client base.
Train your people on their real risk
Industry-mapped content, cadenced training paths, a human risk score for every user, and audit-ready reporting — with your data provisioned in your region.
See how organisations use ChinronRun human risk management across every client
One dashboard for your whole portfolio. White-label branding, fully isolated reporting, portfolio-wide risk analytics, and revenue economics built for resale.
See how MSPs use ChinronHuman risk management, built around four ideas
Built for your world
Your team doesn't train on American case studies or fictional companies. Courses, phishing simulations and breach scenarios are built around the services, incidents and regulations they actually recognise. Data stays in-region too — but that's the floor, not the point.
Expert-approved, always current
Every course and simulation is reviewed and signed off by an expert before it reaches your team. AI is what keeps that library mapped to your region, your industry, and the latest threats — at a pace no manual process could match.
Reduce and measure human risk
Industry-specific phishing, image-based deepfake detection, and a continuously-updated human risk score for every user — the behaviour legacy tick-box training never measured. It runs on a cadence: set it up once, it keeps running.
Prove it, on demand
Every completion, phishing result and risk score rolls into an audit- and insurance-ready report — mapped to the specific control each framework requires, with a documented due-diligence trail of every reminder sent. Reduce human risk, and prove your organisation did its part.
Every other platform sends your team a module written for somewhere else.
Most security awareness training is built once, in one country, and shipped everywhere. The phishing lures reference services nobody in your office uses. The breach examples are from companies your team has never heard of. The regulatory references are for a different legal system entirely.
Your people complete it because they have to. They don't remember it because it doesn't feel real.
Chinron builds training for the world your team actually works in. If your team is in Australia, they train on Australian threats, Australian services, Australian regulatory events. When you expand to the UK or Canada, those teams get locally contextualised content automatically — not because someone swapped out a template, but because that's how the platform works.
Everything built around how humans actually fail
The most common breach vector isn’t a zero-day — it’s a person making a decision under pressure. Chinron is built around that reality.
Industry-targeted phishing, not recycled spam
Today’s phishing is personalised, sector-specific and indistinguishable from legitimate mail. Chinron’s simulations mirror what your industry actually sees — so your people practise on realistic attacks, then learn the moment they slip.
- Templates built for your sector — financial fraud lures for accounting, patient-portal spoofs for healthcare
- Scheduled, recurring campaigns with real-time open and click tracking
- Fail a sim and you’re automatically assigned a targeted refresher — the loop closes without an admin lifting a finger
- Spot-the-Phish covers the blind spot every phishing program has — execs, floor staff and anyone without an inbox get playable, in-platform phishing training, so your whole workforce is measured, not just the mailbox-holders
Always current. Always expert-approved.
A library your team will actually finish. Every module is built around the threats, services and incidents your region and industry actually face — so training feels real, because it is. And nothing reaches your team until a person has signed off on it.
- Content built for your region and industry — local examples, local incidents, local regulatory context
- Cadenced training paths release the right course to the right department automatically
- Bite-sized modules with 100% completion — every learner who starts, finishes, across all clients on the platform
- Pace monitoring flags course rushing under 60 seconds — completion means engagement, not just a click-through
Train for AI-generated images attackers already use
AI-generated images are being used in impersonation attempts your employees have never been trained to spot. Chinron builds that skill progressively, so recognising a synthetic image becomes second nature.
- A progressive challenge path of real vs AI-generated images
- Teaches the tells — extra fingers, garbled background text, impossible reflections
- Delivered in a cadence so the skill builds over time, not a one-off quiz
Know your highest-risk users before attackers do
The Chinron Human Risk Score gives every active user a number built from what they actually do — not who they are on paper. It’s not a blame tool, it’s a targeting tool: know where to focus attention, reassign training, or increase simulation frequency.
- Built from four real behavioural signals — phishing response, training engagement, deepfake accuracy, and course pace
- Not a survey. Not a role assumption. Actual observed behaviour, updated continuously
- Tracked over time — watch your organisation’s risk trajectory fall as training lands, and prove the reduction to your board and insurer
- High-risk users surfaced on the dashboard and in every PDF and CSV export
Don’t just reduce human risk — prove you did
The hardest part of a cyber-insurance renewal or an audit isn’t doing the training — it’s proving it happened, and proving you weren’t negligent when someone ignored it. Chinron turns your program’s activity into defensible, control-mapped evidence on demand — so “we run security awareness training” becomes a document you can hand over.
- Every completion, phishing result and risk score rolls into one audit- and insurance-ready report
- Mapped to the specific control each framework asks for — HIPAA §164.308(a)(5), Essential Eight ISM-1546, APRA CPS 234 and more
- Documented due diligence — a timestamped trail of every reminder and escalation, proving your organisation did its part even when an employee didn’t
- Scoped to any reporting period, exportable to PDF and CSV — the evidence your auditor and insurer actually ask for
Train on what’s happening, not last year’s threats
Your threat landscape changes weekly. Chinron pulls live intelligence and filters it to your sector, so training reflects the attacks targeting organisations like yours right now.
- Real-time feeds from CISA KEV, NIST NVD and MITRE ATT&CK
- Filtered to the threats actually relevant to your industry
- Feeds straight into the content your team trains on
Meet your Sentinel
The hardest part of awareness training isn’t the content — it’s getting people to finish it. So every learner gets a Sentinel: a companion that guides them, reacts to how they’re doing, and levels up as their security instincts grow.
- Choose the companion whose personality fits — Tari, Sekai, Faro or Kuda
- It levels through tiers as training and phishing performance improve
- New lore unlocks as your team progresses — a reason to come back
- The engagement layer that finally makes security training stick
Four companions. Pick your guide.
Each learner chooses the personality that motivates them. Same training, very different company.
Calm, grounded and encouraging. Guides your team with steady confidence and genuine warmth.
Sharp, analytical and tactical. Cuts straight to the threat with precision and a knowing smirk.
Energetic, expressive and relentlessly positive. Turns every lesson into a win.
Clever, irreverent and unpredictable. Keeps security training from ever feeling like a chore.
They grow with your team
A Sentinel evolves as security habits build — visible proof of progress your people can see.
We don’t just map to your frameworks — we generate the evidence each one asks for
Every framework maps to a specific security-awareness control, and every report shows your coverage against it — HIPAA §164.308(a)(5), Essential Eight ISM-1546, NIST CSF PR.AT-1 and more. Built with the rigour of a formal compliance program: tracked completions, department-based paths and audit-ready records. Every region launches with its own framework set.
Australia is live with Essential Eight, APRA CPS 234 and the Privacy Act. A UK, US or EU instance launches with its own local set — Cyber Essentials, NCSC, NIST, GDPR and more.
Built for MSPs from day one — not bolted on after
Run human risk management across your entire client portfolio without separate accounts, tools or logins. White-label branding, fully isolated data, portfolio-wide analytics, and a branded, audit-ready evidence report you can hand each client for their auditor or insurer.
White-label branding
Your logo and colours on every client touchpoint — Chinron stays invisible.
Isolated client data
Reports, users, campaigns and risk scores never cross client lines.
Portfolio analytics
Completion, susceptibility and risk across your whole book.
Resale economics
Wholesale pricing that improves with portfolio scale.
We hold ourselves to the standards we train your team on
Field-level encryption
Credentials, authentication secrets and API keys are encrypted with AES-256-GCM. Passwords are hashed, never stored in recoverable form.
Organisation-level isolation
Every record is scoped to your organisation. Users, training data, phishing results and risk scores never cross organisation boundaries.
Anomaly detection
Impossible travel, new-country access, unrecognised devices and brute-force attempts are detected and flagged in real time.
Your data is never sold
We do not sell, share, or use your employee training data to train third-party AI models. Ever.
Start reducing — and proving — your human risk
Spin up a free trial in your region in minutes — or book a walkthrough tailored to your industry.