Skip to main content
Home Products SecureMinds AI

Security Training Where You Own Every Record.

31 courses, 34 skills assessments, phishing simulation, and compliance tracking. Deploy on your infrastructure or let SinonTech host it for you. Either way, you own 100% of every training record, assessment score, and simulation result. We never access, mine, or sell your data. Fully customisable per organisation.

7 deployment options: bare metal, Docker, Kubernetes, cloud VMs (AWS, Azure, GCP), virtualised environments (VMware, Hyper-V, Proxmox), air-gapped, or SinonTech-hosted. You own every training record, assessment score, and phishing simulation result, regardless of where the software runs.

Coming Soon

This product is currently in development. Contact us to register your interest.

By the Numbers

31

Training Courses

Interactive modules covering phishing, social engineering, data protection, incident response, compliance, and more. Video, quizzes, and case studies included.

60+

Skills Assessments

Measure competency across 8 security domains. Identify knowledge gaps before they become incident reports. Track improvement over time.

8

Security Categories

From phishing awareness to remote work security. Each category maps to recognised frameworks including NIST, ISO 27001, and NIS2 (coming soon).

4

Database Options

PostgreSQL, MySQL, MSSQL, or Elasticsearch. Use your existing database infrastructure. No proprietary storage layer required.

6

Deployment Modes

Bare metal, Docker, Kubernetes, cloud VMs (AWS/Azure/GCP), virtual environments (VMware/Hyper-V/Proxmox), or air-gapped offline bundles. Deploy where your security policy demands.

Core Capabilities

SecureMinds AI is built for organisations that treat security awareness as an operational requirement, not a checkbox exercise. Every feature is designed to measure, improve, and demonstrate workforce security posture — entirely on your infrastructure.

Training Course Library

31 courses spanning Phishing, Social Engineering, Password Security, Data Protection, Malware Awareness, Incident Response, Compliance, and Remote Work Security. Each course combines interactive content, video walkthroughs, quizzes, and real-world case studies drawn from published breach reports.

Courses are structured in progressive difficulty levels (Foundations, Intermediate, and Advanced), so a new hire and a senior engineer receive appropriately challenging material. All content is bundled with the installation; no external CDN or content delivery dependency.

31 Courses8 CategoriesVideo + Quizzes

Skills Assessment Centre

Over 60 assessments distributed across 8 security domains, each designed to surface genuine comprehension rather than rote memorisation. Assessments include scenario-based questions, simulated decision trees, and timed practical exercises.

Identify gaps before they become incidents. Establish per-department baselines, set target scores, and track improvement quarter over quarter. Export assessment data to your existing HR or GRC tooling via the REST API.

60+ AssessmentsScenario-BasedREST API

Learning Path Designer

Build structured learning paths with templates, prerequisites, and role-based assignments. Onboard new starters with security fundamentals, then branch into role-specific tracks — engineering, finance, executive, HR, or operations.

Define prerequisite chains so employees must pass foundational assessments before accessing advanced material. Clone and customise built-in path templates or create entirely bespoke sequences tailored to your organisation's threat landscape.

Role-BasedPrerequisitesTemplates

Awareness Campaign Management

Run targeted awareness campaigns tied to real threat intelligence. When a new phishing technique trends in your sector, launch a focused micro-campaign within hours — not weeks. Segment audiences by department, location, risk score, or previous assessment results.

Track engagement metrics that matter: completion rates, time-to-complete, quiz scores, and behavioural change indicators. Measure whether campaigns actually shift behaviour, not just whether employees clicked "Next".

Threat IntelSegmentationAnalytics

Phishing Simulation & Analytics

Deploy realistic phishing campaigns using customisable templates that mirror current threat actor techniques. Track click rates, credential submission rates, and (critically) report rates. A healthy security culture is measured by how many employees report suspicious emails, not just how many avoid clicking.

Closed-loop remediation: when an employee fails a phishing simulation, they are automatically enrolled in targeted training. No manual intervention, no spreadsheet tracking, no gap between detection and remediation.

Phishing SimClosed-LoopAuto-Enrol

Policy Acknowledgment Workflow

Distribute security policies, acceptable use agreements, and compliance documents through a structured acknowledgment workflow. Employees review, acknowledge, and sign. Every step is tracked with timestamps, IP addresses, and user-agent metadata.

Generate audit-ready reports showing exactly who acknowledged which policy, when, and from where. Configurable reminder schedules ensure no acknowledgment falls through the cracks. Full revision history for every policy version.

Audit-ReadyCompliancee-Signature

From Assessment to Compliance, on Your Terms

SecureMinds AI follows a closed-loop methodology: assess where your organisation stands, assign targeted training, deliver it, test retention through simulation, measure the results, and generate the compliance evidence your auditors require. Every step runs on your infrastructure.

01

Assess

Baseline your workforce with skills assessments across 8 security domains. Identify which departments, roles, or individuals have knowledge gaps. Generate a risk-prioritised view of your human attack surface before assigning a single course.

02

Assign

Use assessment results to assign learning paths automatically. Role-based rules ensure developers receive secure coding content while finance staff receive invoice fraud training. Manual overrides available for targeted interventions after incidents.

03

Train

Employees work through assigned courses at their own pace or within administrator-defined deadlines. Interactive content adapts to comprehension — additional explanations surface when quiz answers indicate misunderstanding. Progress is tracked in real time.

04

Simulate

Deploy phishing simulations calibrated to each employee's training level. Newly trained employees receive moderate-difficulty simulations; advanced users face sophisticated, multi-stage scenarios. Simulation difficulty scales with demonstrated competency.

05

Measure

Aggregate results across assessments, course completions, simulation outcomes, and policy acknowledgments. Dashboard views show organisation-wide trends, department comparisons, and individual progress. Identify whether training is actually changing behaviour.

06

Report

Generate compliance-ready reports for ISO 27001 Annex A.7.2.2, SOC2 CC1.4, and GDPR Article 39 (NIS2 Article 20 coming soon). Export as PDF, CSV, or JSON. Schedule automated report delivery to compliance officers, HR, and executive leadership.

Multi-Database Support

PostgreSQL, MySQL, MSSQL, or Elasticsearch. SecureMinds AI adapts to your existing database infrastructure — you do not need to provision a new database server. Connection parameters are configured at install time; the application handles schema creation and migrations automatically. Your existing backup procedures, replication topology, and access controls remain unchanged.

Your Brand. Your Courses. Your Standards.

SecureMinds AI is not a locked-down appliance. It is a platform designed to be shaped to your organisation's specific requirements. Every element (from the login screen to the completion certificate) is configurable.

Custom Branding

Apply your organisation's logo, colour scheme, and typography to the training portal. Employees see your brand, not ours. White-label the entire experience so it integrates naturally with your internal tooling.

Proprietary Course Authoring

Add your own courses alongside the built-in library. Upload internal training materials, policy walkthroughs, or sector-specific content. Use the course builder to create interactive modules with quizzes, embedded video, and downloadable resources.

Role-Based Learning Paths

Customise learning paths per department, role, team, or individual. A security analyst and a marketing coordinator have different threat exposures — their training should reflect that. Map paths to your organisational structure via LDAP/AD group sync or manual assignment.

Branded Certificates & Badges

Issue completion certificates bearing your organisation's branding and authorised signatory. Digital badges can be configured per course or per learning path. Certificate templates are fully editable: adjust layout, fields, and validation QR codes.

Custom Assessments

Author bespoke assessment questions and scoring rubrics. Supplement the 60+ built-in assessments with questions specific to your technology stack, internal procedures, or regulatory obligations. Configurable pass thresholds, retry limits, and time constraints.

Per-Organisation Phishing Templates

Create phishing simulation templates that reflect the threats your organisation actually faces. Clone real phishing emails received by your SOC, sanitise them, and deploy them as simulation exercises. Internal branding, spoofed sender domains, and realistic landing pages — all controlled by you.

Configurable Compliance Frameworks

Map training requirements to the compliance frameworks that govern your organisation. Built-in mappings for ISO 27001, SOC2, GDPR, PCI-DSS, HIPAA, and NIST (NIS2 coming soon). Add custom framework definitions with your own control references, evidence requirements, and audit schedules. Generate framework-specific reports showing training coverage against each control.

Course Catalogue

31 courses organised across 8 security categories. Each course includes instructor-led video, interactive scenarios, knowledge checks, and a final assessment. Content is reviewed and updated with each release to reflect the current threat landscape.

Phishing Awareness

5 courses

Email phishing fundamentals, spear phishing recognition, business email compromise (BEC), vishing and smishing, and advanced phishing indicator analysis. Covers both detection techniques and correct reporting procedures.

Social Engineering

4 courses

Pretexting, tailgating, quid pro quo, and multi-channel social engineering attacks. Case studies from documented breaches where social engineering was the initial access vector.

Password Security

3 courses

Password hygiene, credential management tools, multi-factor authentication adoption, and passkey/FIDO2 fundamentals. Includes practical exercises using password strength estimators and breach databases.

Data Protection

4 courses

Data classification, handling PII, secure file sharing, and data loss prevention awareness. Aligned with GDPR data protection principles and ISO 27001 Annex A.8 asset management controls.

Malware & Ransomware

4 courses

Malware delivery mechanisms, ransomware response procedures, removable media risks, and browser-based threats. Practical scenarios covering what to do (and what not to do) when a suspected infection occurs.

Incident Response

3 courses

Incident recognition, escalation procedures, and post-incident review participation. Designed for non-technical staff who need to understand their role within the organisation's incident response plan.

Compliance & Regulations

5 courses

GDPR awareness, PCI-DSS for non-technical roles, HIPAA basics, and general regulatory landscape (NIS2 obligations coming soon). Each course is mapped to specific articles and controls to demonstrate audit compliance.

Remote Work Security

3 courses

Secure home network configuration, VPN usage and split-tunnel risks, public Wi-Fi awareness, and physical security for remote workers. Updated for hybrid work environments where the network perimeter is the employee's device.

Deployment Options

SecureMinds AI deploys where your security policy requires it: on physical servers, in virtual machines, across cloud providers, inside containers, or on air-gapped networks. Every deployment mode includes the full feature set — there is no "enterprise-only" tier locked behind a different installer.

Bare Metal

Node.js · Nginx · PostgreSQL / MySQL / MSSQL / ES · systemd

Traditional installation directly on your Linux server. The install script configures the Node.js backend, sets up your chosen database, provisions Nginx as a reverse proxy with TLS, and registers systemd services for process management. Suitable for single-server deployments or when you need direct filesystem access to training content.

sudo ./install.sh --db postgresql --domain training.internal.example.com

Docker

Docker Compose · Nginx · Volume Mounts · Health Checks

Single-command deployment using Docker Compose. All services (application, database, reverse proxy) are containerised with persistent volumes for data and configuration. Health checks, restart policies, and resource limits are pre-configured. Ideal for environments already running containerised workloads.

sudo ./install-docker.sh --domain training.internal.example.com

Kubernetes

Helm Chart · Ingress · PVC · HPA · ConfigMap

Production-grade Helm chart for enterprise Kubernetes clusters. Horizontal pod autoscaling, persistent volume claims, configurable ingress, and network policies included. Supports external database connections, custom storage classes, and node affinity rules. Tested on EKS, AKS, GKE, and on-premise clusters.

helm install secureminds-ai ./helm/secureminds-ai \
  --set global.domain=training.internal.example.com \
  --set database.type=postgresql

Air-Gap Coming Soon

Offline Bundle · Pre-Packaged Dependencies · No Internet Required

Complete offline installation bundle for classified, restricted, or disconnected environments. All dependencies (Node.js runtime, npm packages, database binaries, Nginx, and training content) are pre-packaged. Transfer via USB, optical media, or secure file transfer. No internet connectivity required at any point during installation or operation.

# On connected machine:
./package-airgap-bundle.sh --db postgresql

# On air-gapped target:
sudo ./install-airgap.sh --domain training.airgap.local

Cloud VMs

AWS EC2 · Azure VM · GCP Compute · Any IaaS

Deploy on any cloud provider's virtual machines. Use your existing cloud infrastructure without surrendering data to vendor-managed SaaS. You control the instance, the network, and the encryption keys. All installation scripts work identically whether the underlying host is physical or cloud-provisioned.

Virtual Environments

VMware ESXi/vSphere · Hyper-V · Proxmox VE · KVM/QEMU

Full support for all major hypervisors. Deploy SecureMinds AI as a virtual machine alongside your existing virtualised infrastructure. Snapshot, clone, and template using standard hypervisor tooling. No hardware-specific dependencies.

Why Data Ownership Matters for Training

Most security awareness platforms are SaaS. That means your employee data (names, roles, departments, assessment scores, phishing simulation results, behavioural profiles) lives on someone else's infrastructure. With SecureMinds AI, you own 100% of that data whether you self-host or let us host it for you.

Employee Data is PII.

Security training platforms accumulate a detailed profile of every employee: their name, email address, department, job title, manager, assessment scores, courses completed, phishing simulation failures, and behavioural risk indicators.

This is sensitive HR data. It reveals who your weakest links are. It maps your organisational structure. It identifies which departments have security knowledge gaps. In the wrong hands, it is a reconnaissance goldmine.

SecureMinds AI keeps all of this data under your ownership and control — whether it runs on your servers or ours. We never access, read, mine, or share it. Your backup and retention policies apply. No third-party processor. No sub-processor risk assessments.

Training is a Compliance Obligation.

NIS2 Article 20 mandates that management bodies approve and oversee cybersecurity risk-management measures, including regular training. SOC2 CC1.4 requires security awareness communication. ISO 27001 Annex A.7.2.2 demands information security awareness, education, and training. GDPR Article 39 assigns DPO responsibility for staff awareness.

When an auditor requests evidence, you need complete, unmodified training records with full chain of custody. Whether you self-host or use SinonTech-managed hosting, your audit logs, completion records, and assessment results are stored in your database, backed up by your procedures, and accessible without depending on a vendor's export function.

Air-Gapped Environments Need Training Too. Coming Soon

Some organisations (from small research labs to large defence contractors) operate air-gapped networks by policy or regulation. These environments cannot reach external SaaS platforms, yet they have the same (often greater) training requirements.

SecureMinds AI's air-gapped deployment mode delivers the complete platform (all 31 courses, all 34 assessments, phishing simulation, compliance reporting) without any internet connectivity. The offline bundle is transferred via approved media and installed entirely within the isolated network.

Technical Specifications

Backend Node.js (TypeScript)
Frontend React 18 + TypeScript + Vite + Tailwind CSS
Databases PostgreSQL, MySQL, MSSQL, or Elasticsearch
Reverse Proxy Nginx with TLS termination
Process Management systemd (bare metal), Docker Compose, Kubernetes (Helm)
Authentication Local accounts, SAML 2.0, OIDC (LDAP/Active Directory coming soon)
API RESTful JSON API (OpenAPI 3.0 specification coming soon)
Courses 31 built-in + unlimited custom courses
Assessments 60+ built-in + unlimited custom assessments
Compliance Frameworks ISO 27001, SOC2, GDPR, PCI-DSS, HIPAA, NIST + custom (NIS2 coming soon)
Deployment Modes Bare metal, Docker, Kubernetes, Cloud VMs, Virtual Environments, Air-Gapped
Minimum Requirements 2 vCPU, 4 GB RAM, 20 GB storage (single-server)
Supported OS Ubuntu 22.04+, Debian 12+, RHEL 9+, Rocky 9+, AlmaLinux 9+

Train Smarter. Host It Yourself.

SecureMinds AI is in active development. Request access to receive deployment documentation, architecture guides, and priority access to the first release. No commitment, no credit card, no cloud account required.

Contact Us

Get in touch to discuss your requirements.

No credit card. No cloud account. Your employees' data stays on your network.


SecureMinds AI is developed by SinonTech. Self-hosted security tools for organisations that take data sovereignty seriously.