Skip to main content

Every exercise is indexed by name, CWE, OWASP, MITRE ATT&CK, CIS, NIST CSF, GDPR and EU AI Act reference.

Try

Cloud LMS

Run training on our Cloud LMS

Skip the integration project. Deliver, assign, and track security awareness training on our hosted platform, with the analytics, access controls, and audit-ready reporting an enterprise rollout needs. Run it in a US or EU region, in a dedicated private cloud, or on-premises. Prefer your own LMS? Export everything as SCORM instead.

Cloud LMS overview: a course catalog and learning paths on the left, a completion and risk dashboard in the center, and access controls for SSO, SCIM, and roles on the right

Connected platforms

From sign-up to a trained, audited workforce

Four steps, with the busywork of an enterprise rollout handled for you.

01

Bring your people in

Provision users with SAML single sign-on and SCIM, or import by CSV. Teams and roles map from your identity provider, and people who leave are removed automatically.

02

Assign the right training

Build role-based learning paths and campaigns, then assign them to users or teams with deadlines. Set annual programs to recur on their own, so compliance training renews itself.

03

Let it run

Automated reminders nudge people before a deadline, in email or in Slack, Teams, and Webex, and escalate to a manager when someone keeps missing it. Employees train in their own language across seven locales.

04

Prove it

Watch completion and quiz performance on live dashboards, then export per-person attestations and roster reports tagged to the framework you report against.

Deliver and manage every program

Assign from our library or bring your own content, and let the recurring work run itself.

Learning path editor showing an Engineering secure-coding track with numbered exercise steps, completion badges, a Start action on the next step, and locked downstream steps that depend on their prerequisites

A catalog plus your own content

Assign from the interactive exercise catalogue across security awareness, privacy and compliance, and AI security, and upload your own SCORM packages, PDFs, slides, and videos into the same library.

Role-based learning paths

Sequence exercises with prerequisites and assign by team or role, so developers get application security while finance focuses on business email compromise and wire fraud.

Campaigns and annual recurrence

Schedule campaigns, auto-enroll by team or filter, and set learning paths to recur each year with grace periods, so your annual training renews without anyone rebuilding it.

Simulate the attack, then assign the fix

Simulations run from the same console as the training, so the behavior and the remediation never live in two systems.

Phishing campaign configuration form showing template selection, delivery scheduling with jitter, and recipient targeting

Email, SMS, and voice

Send phishing simulations through Microsoft 365 Graph or Google Workspace, smishing over SMS, and voice lures, so the test matches the channel the attacker would actually use.

A template library you control

Clone and author templates, sender personas, landing pages, and attachments, then hold new ones in a review queue until someone signs off. Recipient domains are verified before anything sends.

Reporting turns into training

A report button in Outlook and Gmail lets people flag a suspicious message, and anyone who falls for a lure is enrolled in the remediation module that answers it, without an administrator assigning it by hand.

An experience people actually finish

A game layer that earns completion, certificates worth keeping, and training in each person’s own language.

Achievements dashboard showing unlocked badges across Common, Rare, Epic, and Legendary rarity tiers, learning-streak awards, and a Certificates category, with counts for achievements unlocked, total achievements, and completion rate

Badges, achievements, and streaks

Earn badges from Common to Legendary, unlock achievements, and build learning streaks. The game layer is what turns a compliance chore into something people come back to.

Certificates that verify themselves

Every completion issues a downloadable PDF certificate with a public verification link anyone can check, and expiry reminders prompt a renewal before it lapses.

Train in their own language

Content is delivered in English, Ukrainian, Dutch, Italian, German, French, and Spanish out of the box, with more on request, so global teams learn in the language they work in.

See exactly who needs attention

Live dashboards for the program manager, plus the nudges that keep training moving on their own.

Tenant analytics dashboard with an overall usage trend chart over the last 30 days, a popular-courses leaderboard ranked by time spent, and an aggregate course-completion donut

Live analytics dashboards

Completion rollups, quiz scores, the hardest questions, engagement trends, and the people falling behind, broken down per user and per team.

Automated reminders and escalation

Reminders go out before a deadline and escalate to a manager when someone keeps missing it, so you are not chasing completion by hand.

Scheduled reports

Weekly and monthly summaries land in stakeholders’ inboxes on their own, so leadership sees progress without logging in.

Prove it to your auditors

The evidence a SOC 2 or ISO review asks for, exported or synced without a scramble.

Compliance dashboard showing training-evidence completion percentages per framework, with cards for SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, CCPA/CPRA, NIST CSF, CIS Controls v8, ISO 27701, EU AI Act, NIST AI RMF, and NIS2, each showing enrolled, done, and overdue counts

Audit-ready evidence

Export per-person training attestations and tenant-wide roster reports as PDF or CSV, tagged to the framework you report against: SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, NIS2, DORA, the EU AI Act, and more.

Audit log and access reviews

A security event log and quarterly access reviews hand your auditor the trail they ask for, instead of a manual export scramble the week the audit lands.

Evidence that writes itself

Training completions flow automatically into Vanta as control evidence, and every person carries a human risk score, so the record stays current.

Enterprise access and administration

The identity, role, and branding controls procurement and security will ask about.

User-management console with license utilization tiles and tabs for Users, Pending Invites, Teams, Roles, and SCORM Users, alongside a roster filterable by role and team and showing each person’s role, team, manager, and enabled status

SSO, MFA, and SCIM

SAML 2.0 single sign-on with any compliant identity provider such as Entra ID, Okta, or Google Workspace, enforceable MFA by authenticator app or email code, and SCIM 2.0 provisioning that adds and removes people as your directory changes.

Roles, teams, and permissions

Group people into teams by department, location, or risk, give managers visibility into their own reports, and use custom roles with fine-grained permissions to keep sensitive data restricted.

Your brand, your domain

Put the platform on your own domain with your logo and a verified sending domain, and lock access to approved IP ranges for users on your network or VPN.

Host it where your data has to live

Our cloud in the US or EU, a dedicated private cloud, or an install on your own infrastructure. Same platform, same content, your choice of perimeter.

Three deployment options side by side: a shared cloud region marked US or EU, a dedicated private cloud in its own account, and an on-premises install inside a customer network

Multi-tenant cloud, US or EU

Pick a US (N. Virginia) or EU (Frankfurt) region at sign-up. Your tenant’s database, uploads, reports, and backups stay in that region, so a GDPR, NIS2, or DORA review gets a one-line answer on where the data lives.

Dedicated private cloud

A single-tenant environment in its own AWS account, in the region you choose, with a dedicated database, object storage, and encryption keys. You get your own maintenance window and release schedule, and nothing is shared with another customer.

On-premises and air-gapped

The same platform as containers on your Kubernetes or Docker hosts, against your own PostgreSQL, Redis, and S3-compatible storage. Air-gapped networks receive courses, drills, and updates as signed offline bundles, so no learner data ever leaves your network.

Wire it into the stack you already run

A REST API, outbound webhooks, and prebuilt connectors, so training data lands where your team already looks.

Integrations settings page listing connected platforms with their status, alongside tabs for webhooks, chat apps, compliance tools, observability, HRIS, LTI, and API tokens

A REST API with scoped tokens

Pull tenant and per-course analytics, compliance evidence, security events, and phishing results, or push your own risk signals in. Each token is scoped to what it needs, so a reporting job never carries write access.

Webhooks on the events that matter

Subscribe to assignment, three stages of deadline warning, completion, badges awarded, and both phishing failures and phishing reports, then route them wherever your team already works.

Connectors, not integration projects

Prebuilt connections to Vanta, Drata, Datadog, New Relic, Splunk, and PagerDuty, chat delivery through Slack, Teams, and Webex, HRIS sync through Merge and HiBob, and LTI 1.3 for course tools.

Cloud LMS vs SCORM into your own LMS

Both run the same content. The question is what the platform keeps once the training is finished.

RansomLeak Cloud LMS

  • Simulations and training run from one console, so behavior and remediation connect
  • Every person carries a human risk score that updates from what they actually did
  • Reminders escalate to a manager on their own when someone keeps missing a deadline
  • Attestations export already tagged to the framework you report against
  • Completions sync into Vanta and Drata as control evidence

SCORM export into your own LMS

  • Completion and quiz scores land in the reporting stack you already run
  • No risk score: a SCORM package reports status, not susceptibility
  • Reminders and escalation are whatever your existing LMS already does
  • Framework tagging and attestation exports stay your team’s job
  • Simulations run somewhere else, so behavior and training never meet

What is a cloud LMS for security awareness training?

A cloud LMS for security awareness training is a hosted platform that delivers the training, assigns it to the right people, and records who completed it. You run the program on the vendor’s infrastructure instead of importing SCORM packages into a learning management system you host yourself.

The rollout

  • Provision
  • Assign
  • Nudge
  • Prove

The difference from SCORM export is what the platform keeps. Completion status travels with a SCORM package; risk scores, manager escalation, framework-tagged attestations, and phishing results do not, because they are produced by the platform that runs the training.

RansomLeak runs both halves in one console. Phishing and smishing simulations surface real behavior, the catalogue and learning paths assign the training that answers it, SSO and SCIM govern who has access, and the compliance module exports the evidence an auditor asks for, without an integration project of your own.

Frequently asked questions

What is the RansomLeak Cloud LMS?

The Cloud LMS is our hosted platform for delivering, assigning, and tracking security awareness training. It is the alternative to exporting SCORM packages into your own learning management system: instead of running the training elsewhere, you run it on ours.

It includes the catalog, learning paths, campaigns, analytics, access controls, and compliance reporting an enterprise program needs.

Do I have to use your platform, or can I use my own LMS?

Either one. If you already run a learning management system, export RansomLeak training as SCORM packages and deploy them there. If you would rather not, the Cloud LMS gives you the whole program without an integration project.

Both run the same content, so the choice is about where you want completion data to live.

How do users sign in and get provisioned?

Through SAML 2.0 single sign-on with any compliant identity provider, including Microsoft Entra ID, Okta, and Google Workspace. SCIM 2.0 provisioning creates and deactivates accounts automatically as your directory changes, and you can also import users by CSV.

MFA can be enforced organization-wide using an authenticator app or an email code.

Can we put it on our own domain and brand it?

Yes. Run the platform on your own custom domain with your logo, and send notification emails from a verified sending domain of your own. Employees see your brand, not ours.

You can also restrict access to approved IP ranges so only people on your network or VPN can sign in.

Where is our data hosted, and can we choose the EU?

Yes. The Cloud LMS runs in a US (N. Virginia) or EU (Frankfurt) region, and you pick the region when the tenant is created. Your database, uploaded content, reports, and backups stay in that region.

If you need a region of your own or stricter separation, a dedicated single-tenant private cloud is available in the region you choose. The security and compliance page lists what lives where.

Can we run the platform on-premises or in our own private cloud?

Yes. The on-premises edition is the same platform packaged as containers for Kubernetes or Docker. It runs against your own PostgreSQL, Redis, and S3-compatible storage, authenticates through your identity provider, and sends mail through your SMTP relay.

Air-gapped installs receive courses, drills, and platform updates as signed offline bundles. Phishing and smishing simulations work on-premises as long as the environment can reach your mail and SMS gateways.

What languages is the training delivered in?

Content is delivered in seven languages out of the box: English, Ukrainian, Dutch, Italian, German, French, and Spanish. Additional languages are available on request.

The interface and exercises follow the language each person is using, so global teams train in their working language.

Can it produce audit evidence for our compliance frameworks?

Yes. Export per-person training attestations and tenant-wide roster reports, tagged to the framework you report against, across SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, NIS2, and more.

Training completions can also flow automatically into Vanta as control evidence, so the record keeps itself.

See RansomLeak in Action

Try the free exercises or book a demo to see analytics, SCORM export, SSO, and custom content in your environment.