Why NOUSEC
NOUSEC is a human risk management platform that measures and reduces social engineering risk across multiple attack channels and unifies the result into a single 0–100 Human Risk Score. What separates it from other security awareness platforms is that every claim it makes has a published mechanism underneath it: completion is verified server-side against watched seconds, per-module effectiveness is reported as a correlation to real phishing click rate, and every component of the risk score is visible to the person being scored.
Six claims, six mechanisms
On the left, what every platform says. On the right, the thing underneath ours that you can check.
“Employees complete their training.”
Completion is a server-side coverage gate, not a progress bar
A video is complete at ≥ 90% unique-second watch coverage, computed server-side. Accrual pauses when the browser tab is hidden. Scrub to the end and walk away and coverage is near zero — no completion, no certificate.
“Our training works.”
A correlation against real click rate — hidden below n = 10
For each module we compute a Pearson correlation between completing that module and real phishing-simulation click rate, and display it only at n ≥ 10. Below the threshold you see nothing, because a number we cannot stand behind is worse than a blank.
n = 34
r = −0.41
n = 6
Not shown yet
“We give personalised feedback.”
Every wrong answer names the observable signal
Feedback points at the thing on screen that gave the attack away — not at a habit of mind.
Ours
“Domain ‘microsft-team.com’ is misspelled — real Microsoft uses microsoft.com”
The generic version
“Be careful of suspicious links.”
“We score human risk.”
One score, 0–100, with a mandatory component breakdown
The Human Risk Score reads identically on every surface and never appears without its components — no black box. Reporting a suspicious message is additive: an employee who raises their hand improves their own score. And exposure is not blame — a user whose credentials appeared in a third-party breach did not choose to be there.
“We simulate phishing.”
Eight channels. Most platforms test one or two.
Attackers do not restrict themselves to the inbox, so neither does the simulation surface.
“We teach deepfake awareness.”
The hardest audio pair in the deepfake training module teaches that you cannot tell by ear
The defence taught is process, not perception: verify through a known, pre-verified number. A module that promised to train your ear would sell better. It would also be wrong, and honest pedagogy is itself the differentiator.
Taught
Verify through a known, pre-verified number.
Not taught
Trust your ear to spot the fake.
One thing that does not exist anywhere else
An escape room one employee can play alone, at 11pm, in a browser tab
We ship gamification too — points, badges and leaderboards. What nobody else ships is the format underneath them: one competitor runs live team-based sessions that need a calendar, a facilitator and everyone in the same hour. Nobody ships a game an individual can simply play, on their own time.
The differentiator is the format, not the fun: asynchronous, single-player, browser-based, delivered as SCORM into the LMS you already run.
See it in the demo3 variants
3 variants
3 variants
3 variants
4 puzzles
22 min
Mission mode
28 min
Practice mode
Built for where you actually operate
Evidence, residency, language and billing that match the jurisdiction you are audited in.
Compliance evidence mapped per tenant
Seven frameworks: KVKK, ISO/IEC 27001, NIS2, BDDK, SOC 2, GDPR, ISO/IEC 27701 — and which of them you have to satisfy depends on the sector you report in.
Certificates carry a public verification page
An auditor can check a certificate without asking you for a screenshot.
Audit log exportable to SIEM
CSV, NDJSON or JSON.
Policy acknowledgement re-gates on version change
Acknowledgement history is preserved, not overwritten.
Billing in your local currency
The major US platforms bill in USD only.
GDPR native, EU data residency in Frankfurt
No endpoint agents.
Thirty languages, localised rather than translated
Character names, company names and cultural context change per language — not just the strings. Voice-over coverage is not equal across all thirty.
Ask any vendor these seven questions.
Every row is a mechanism you can verify in a live demo, next to what the market typically offers instead.
| Mechanism | NOUSEC | General market |
|---|---|---|
| Server-side watch-coverage gate | ≥ 90% unique-second coverage, computed server-side; accrual pauses while the tab is hidden | Completion is typically claimed by the browser and accepted by the LMS |
| Per-module correlation to click rate, with an n-threshold | Pearson r per module, shown only at n ≥ 10 | Completion rates and click rates reported separately, never linked per module |
| Async single-player escape room | 4 puzzles, SCORM, playable alone, no scheduling — alongside points, badges and leaderboards | Points, badges and leaderboards only; no playable solo game |
| Score component breakdown visible to the employee | Mandatory breakdown, identical on every surface | Risk scores are typically admin-facing and unexplained to the person scored |
| Reporting a suspicious message improves your own score | Additive by design — raising your hand lowers your risk | Reporting is tracked but typically does not improve the reporter's standing |
| Forensic per-answer feedback | Every wrong answer names the observable signal — “microsft-team.com is misspelled” | Generic guidance — “be careful with suspicious links” |
| Billing in your local currency | Invoiced in your own currency | USD billing from the major US platforms |
General-market and vendor characterizations are based on public vendor documentation, reviewed August 2026. Where no equivalent is described, the cell says so.
Questions
The six a CISO asks in the first call.
Sources
Everything above, with its receipts
The same on-page pattern used on the training pages. It exists because no competitor publishes one.