Skip to content
Chinron
About

Your people aren’t the weakest link. They just haven’t had a system that treats human risk seriously.

Most security breaches don’t start with a zero-day. They start with a person — clicking the wrong link, opening the wrong attachment, trusting a voice that sounds exactly like their manager.

We built Chinron because the human layer of security has always been treated as an afterthought. Generic tick-box training that nobody finishes. Phishing simulations that aren’t built for your industry. No visibility into who your actual highest-risk people are.

Chinron fixes that. Training built around your team’s actual world — the services they use, the incidents that made their local headlines, the regulatory language they recognise. Industry-specific simulations. Content kept current and signed off by a person before it reaches anyone. Deepfake detection that builds a real skill over time. Course rushing detection that means completion actually means something. A human risk score for every user so you always know where to focus. And — the part most platforms ignore — the audit- and insurance-ready evidence to prove it’s all happening.

We didn’t build this in a vacuum. Chinron was shaped over six months of real, daily use alongside a healthcare practice in one of the most tightly regulated corners of the industry. Their feedback drove the features that now set us apart: deepfake detection, the engagement system, and control-mapped audit-evidence reporting. Built in the field, for the businesses that actually carry the compliance burden.

Our security

We hold ourselves to the standards we train your team on

Field-level encryption

Credentials, authentication secrets and API keys are encrypted with AES-256-GCM. Passwords are hashed, never stored in recoverable form.

Organisation-level isolation

Every record is scoped to your organisation. No query crosses organisation boundaries — your users, training data, phishing results and risk scores are only accessible within your account.

Multi-factor authentication

MFA is available across the platform. TOTP secrets are encrypted at rest.

Access anomaly detection

Login-time anomalies, impossible travel, new-country access, unrecognised devices and brute-force attempts are detected and flagged in real time.

Regional infrastructure

Your data is provisioned in your region, so your employee records stay within the borders your organisation operates in.

Your data is never sold

We do not sell, share, or use your employee training data to train third-party AI models. Ever.

Start training your people on their real risk

Spin up a free trial in your region in minutes — or book a walkthrough tailored to your industry.

Book a demo