Why NOUSECEvery vendor makes the same claim.

The difference is whether there is a mechanism underneath it you can inspect. Ours are published: a server-side watch-coverage gate, a per-module correlation to real phishing click rate that hides itself below ten data points, and a risk score whose components are visible to the person being scored.

GDPR native · EU data residency (Frankfurt) · No endpoint agents
Three claims, three exposed mechanismsPER-MODULE CORRELATIONr = −0.41 · n = 34hidden below n = 10Reduces phishingclicks.WATCH COVERAGE≥ 90%≥ 90% unique-second coveragecomputed server-sideProves trainingcompletion.SCORE COMPONENTSC1C2C3C4C5one score · 0–100published methodology · 5 sourcesScores humanrisk.
Three claims, three exposed mechanismsPER-MODULE CORRELATIONr = −0.41 · n = 34hidden below n = 10Reduces phishing clicks.WATCH COVERAGE≥ 90%≥ 90% unique-second coveragecomputed server-sideProves training completion.SCORE COMPONENTSC1C2C3C4C5one score · 0–100published methodology · 5 sourcesScores human risk.

Why NOUSEC

NOUSEC is a human risk management platform that measures and reduces social engineering risk across multiple attack channels and unifies the result into a single 0–100 Human Risk Score. What separates it from other security awareness platforms is that every claim it makes has a published mechanism underneath it: completion is verified server-side against watched seconds, per-module effectiveness is reported as a correlation to real phishing click rate, and every component of the risk score is visible to the person being scored.

Six claims, six mechanisms

On the left, what every platform says. On the right, the thing underneath ours that you can check.

01

“Employees complete their training.”

Completion is a server-side coverage gate, not a progress bar

A video is complete at ≥ 90% unique-second watch coverage, computed server-side. Accrual pauses when the browser tab is hidden. Scrub to the end and walk away and coverage is near zero — no completion, no certificate.

≥ 90% unique-secondtab hidden → pausedforged request → 403
02

“Our training works.”

A correlation against real click rate — hidden below n = 10

For each module we compute a Pearson correlation between completing that module and real phishing-simulation click rate, and display it only at n ≥ 10. Below the threshold you see nothing, because a number we cannot stand behind is worse than a blank.

n = 34

r = −0.41

n = 6

Not shown yet

03

“We give personalised feedback.”

Every wrong answer names the observable signal

Feedback points at the thing on screen that gave the attack away — not at a habit of mind.

Ours

“Domain ‘microsft-team.com’ is misspelled — real Microsoft uses microsoft.com”

The generic version

“Be careful of suspicious links.”

04

“We score human risk.”

One score, 0–100, with a mandatory component breakdown

The Human Risk Score reads identically on every surface and never appears without its components — no black box. Reporting a suspicious message is additive: an employee who raises their hand improves their own score. And exposure is not blame — a user whose credentials appeared in a third-party breach did not choose to be there.

0–100component breakdown requiredreporting is additive
05

“We simulate phishing.”

Eight channels. Most platforms test one or two.

Attackers do not restrict themselves to the inbox, so neither does the simulation surface.

Email
SMS
WhatsApp
QR code
USB drop
Callback
Voice (vishing)
Deepfake video
06

“We teach deepfake awareness.”

The hardest audio pair in the deepfake training module teaches that you cannot tell by ear

The defence taught is process, not perception: verify through a known, pre-verified number. A module that promised to train your ear would sell better. It would also be wrong, and honest pedagogy is itself the differentiator.

Taught

Verify through a known, pre-verified number.

Not taught

Trust your ear to spot the fake.

One thing that does not exist anywhere else

An escape room one employee can play alone, at 11pm, in a browser tab

We ship gamification too — points, badges and leaderboards. What nobody else ships is the format underneath them: one competitor runs live team-based sessions that need a calendar, a facilitator and everyone in the same hour. Nobody ships a game an individual can simply play, on their own time.

The differentiator is the format, not the fun: asynchronous, single-player, browser-based, delivered as SCORM into the LMS you already run.

See it in the demo
1

3 variants

2

3 variants

3

3 variants

4

3 variants

4 puzzles

22 min

Mission mode

28 min

Practice mode

AsynchronousSingle-playerBrowser-basedSCORMPoints · badges · leaderboards

Built for where you actually operate

Evidence, residency, language and billing that match the jurisdiction you are audited in.

Compliance evidence mapped per tenant

Seven frameworks: KVKK, ISO/IEC 27001, NIS2, BDDK, SOC 2, GDPR, ISO/IEC 27701 — and which of them you have to satisfy depends on the sector you report in.

Certificates carry a public verification page

An auditor can check a certificate without asking you for a screenshot.

Audit log exportable to SIEM

CSV, NDJSON or JSON.

Policy acknowledgement re-gates on version change

Acknowledgement history is preserved, not overwritten.

Billing in your local currency

The major US platforms bill in USD only.

GDPR native, EU data residency in Frankfurt

No endpoint agents.

Thirty languages, localised rather than translated

Character names, company names and cultural context change per language — not just the strings. Voice-over coverage is not equal across all thirty.

EnglishSpanishFrenchGermanPortugueseArabic (RTL)ChineseJapaneseTurkish+21 more

Ask any vendor these seven questions.

Every row is a mechanism you can verify in a live demo, next to what the market typically offers instead.

Seven mechanisms compared: NOUSEC against what the general market typically offers
MechanismNOUSECGeneral market
Server-side watch-coverage gate≥ 90% unique-second coverage, computed server-side; accrual pauses while the tab is hiddenCompletion is typically claimed by the browser and accepted by the LMS
Per-module correlation to click rate, with an n-thresholdPearson r per module, shown only at n ≥ 10Completion rates and click rates reported separately, never linked per module
Async single-player escape room4 puzzles, SCORM, playable alone, no scheduling — alongside points, badges and leaderboardsPoints, badges and leaderboards only; no playable solo game
Score component breakdown visible to the employeeMandatory breakdown, identical on every surfaceRisk scores are typically admin-facing and unexplained to the person scored
Reporting a suspicious message improves your own scoreAdditive by design — raising your hand lowers your riskReporting is tracked but typically does not improve the reporter's standing
Forensic per-answer feedbackEvery wrong answer names the observable signal — “microsft-team.com is misspelled”Generic guidance — “be careful with suspicious links”
Billing in your local currencyInvoiced in your own currencyUSD billing from the major US platforms

General-market and vendor characterizations are based on public vendor documentation, reviewed August 2026. Where no equivalent is described, the cell says so.

Questions

The six a CISO asks in the first call.

How is NOUSEC different from KnowBe4 or Proofpoint?

We do not compete on catalogue size or gamification. Every claim we publish has a mechanism underneath it that you can inspect: a server-side completion gate, a correlation to real click rate with a sample threshold, and a risk score whose components are visible to the person being scored.

What does “completion is verified server-side” actually mean?

A video counts as complete at ≥ 90% unique-second watch coverage, computed on our servers rather than reported by the browser. Accrual pauses when the tab is hidden, and a forged completion request returns 403.

Can we see how the Human Risk Score is calculated?

Yes. The methodology is published, and the score never renders without its component breakdown — on the admin console and on the employee's own view alike.

Does gamification make employees resent the programme?

Format matters more than points. Reporting a suspicious message improves an employee's own score, exposure from a third-party breach is not counted as blame, and the escape room is something an individual plays alone rather than a public leaderboard.

Do we need to install anything on employee devices?

No. There are no endpoint agents. The phishing report add-in is an optional mail client add-in, not an agent.

Where is our data stored?

EU data residency in Frankfurt, GDPR native, with tenant-level data export and erasure available.

Sources

Everything above, with its receipts

The same on-page pattern used on the training pages. It exists because no competitor publishes one.

Title
Publisher
Year
Used for
Ho et al., large-scale phishing study (UC San Diego Health)
IEEE S&P
2025
Effectiveness of embedded phishing training
Reinheimer et al., anti-phishing training retention study
USENIX SOUPS
2020
Retention intervals for awareness training
Phishing by Industry Benchmarking Report
KnowBe4
2026
Phish-prone baseline and post-training rate
Data Breach Investigations Report
Verizon
2026
Human-element share of breaches

Bring the claims you were given. We will show you the mechanism.

A live demo against your own scenario, not a slide deck.

GDPR native · EU data residency (Frankfurt) · No endpoint agents