Prove your team is security-trained — in one afternoon
Cyber-insurance questionnaires. ISO 27001. SOC 2. GDPR. NIS2. Client security reviews. PasswordCare gives you the evidence.
How it works
Invite your team
Add team members by email. They receive an invitation and create their account in under a minute.
They complete the training
Six modules covering passwords, 2FA, phishing, payments, social engineering, and device security. About 2 hours, at their own pace.
Export your report
Generate an attestation report documenting who completed what, mapped to the frameworks your auditors and insurers ask about.
What the report evidences
The attestation report maps your team's training completion to the awareness-training requirements in these frameworks:
| Framework | Control / Article |
|---|---|
| ISO 27001 | A.6.3 |
| SOC 2 | CC1.4 / CC2.2 |
| GDPR | Art. 32 / Art. 39 |
| PCI DSS | 12.6 |
| NIS2 | Art. 20(2) |
| KVKK | Art. 12 |
The report evidences completion of security awareness training relevant to these requirements. It does not claim or imply certification, accreditation, or compliance with any framework.
Two plans, one platform
Awareness
- Training modules (6 modules, 31 steps)
- Final exam with certificate
- Admin dashboard with progress tracking
- Email reminders
- Courses available in multiple languages
Compliance
- Everything in Awareness
- Attestation reports (PDF)
- Audit trail (append-only)
- Policy acknowledgment with timestamps
- Annual training cycles
- Framework mapping
Simple, transparent pricing
Annual billing. Invoice payment. 5-seat minimum.
Awareness
per user / year
- Training modules (6 modules, 31 steps)
- Final exam with certificate
- Admin dashboard with progress tracking
- Email reminders
- Courses available in multiple languages
Compliance
per user / year
- Everything in Awareness
- Attestation reports (PDF)
- Audit trail (append-only)
- Policy acknowledgment with timestamps
- Annual training cycles
- Framework mapping
Frequently asked questions
Does this make us ISO 27001 certified?
No. PasswordCare provides security awareness training and documents its completion. The attestation report evidences that your team has completed the awareness-training control required by frameworks like ISO 27001, SOC 2, and GDPR — but it does not certify or accredit your organization under any framework.
How long does the training take?
About 2 hours total, split across 6 modules. Employees work at their own pace and can stop and resume at any time.
What languages are available?
English and French. More languages are coming soon.
How is our company's data isolated?
Every organization's data is completely isolated at the database level using row-level security policies. Each organization can only access its own training data, progress records, and policy acknowledgments.
Can we upload our own security policy?
Yes, on the Compliance plan. Admins can create and publish policies, and employees must scroll through and acknowledge them. Acknowledgments are timestamped with IP address and user agent.
What happens at renewal?
On the Compliance plan, admins can start a new annual training cycle. Previous progress is archived (not deleted), reports remain accurate, and employees complete a fresh round of training.