SaaS · in development

Short videos, organised by subject. Questions after each one. That is what we are building.

Two questions decide whether awareness training is worth buying: what do my staff actually have to do, and what can I put in front of an auditor. The answers are short. Here is what ours will do. Staff will work through short videos, grouped into subjects, each one about a risk they will actually meet. After each, they will answer questions that show whether it landed. Every completion will be recorded against a person, a subject and a date. There is no pricing on this page because there is nothing yet to buy — the waitlist below is how you hear when there is.

What we are building

Watch, answer, record

STEP 1

Watch

Short videos, grouped into subjects and taken one at a time — what a risk looks like, and what to do about it. The subjects are not ours to invent. The Human Resources Security Policy in every MeerLock pack sets the floor at §5.4.1: acceptable use, information classification and handling, protection of cardholder data where it applies, phishing and social engineering, reporting an incident, authentication practices, and secure remote working. The policy says at minimum, so seven is the floor and not the ceiling. We are building the delivery, not the subject list.

STEP 2

Answer

Questions after each video, there to check the knowledge landed. That is not a nice-to-have: §5.4.4 of the same policy requires understanding to be assessed within the session. Attendance is not assessment, and a pass should mean somebody understood the thing rather than clicked to the end of it.

STEP 3

Record

Who completed which subjects, and when — a person, a subject and a date. Awareness is a control an auditor tests by asking for records, and a control you cannot evidence is a control you do not have.

Scope, plainly

Videos and questions are the product

The product is short videos and knowledge-check questions. It does not include simulated phishing: that is not something MeerLock offers.

Your pack does require it: the HR Security Policy calls for simulated phishing exercises at least quarterly (§5.4.7), and the Training & Acknowledgment Register carries a second sheet for logging those campaigns — run from whatever platform you choose.

Already in the packs

The evidence half is already built

Awareness is not a gap in the policy packs. The ISMS Toolkit in every bundle includes the Training & Acknowledgment Register, headed in the file itself with Human Resources Security Policy §5.4 and the two requirements it answers: PCI DSS 12.6 and SOC 2 CC1.4. Its columns are the questions an assessor asks, in order — initial training completed, initial acknowledgment signed, last annual refresh, last annual acknowledgment, role-based modules and their dates.

Today those dates are typed in by hand, from whatever you used to deliver the training. What is in development is the thing that fills them in.

One line we will not blur: a finished video is not a signed acknowledgment. The register keeps them in separate columns, and so will we.

Why a meerkat

Pups are taught, and then checked

Meerkat pups do not work it out alone. Adults bring them prey to practise on, stay to watch what happens, and step in when it goes wrong. The lesson is delivered on purpose, it is repeated, and somebody is there to see whether it took.

That is the part of the metaphor this product keeps. What matters is not the prey. It is that the teaching was deliberate and that somebody checked. Videos, subject by subject, then questions. The alertness you want from your staff is taught, not hired for.

Be first into the nursery

The waitlist is the honest version of a launch date: we write to you when the training product launches, and in that email we ask which subjects your staff need beyond the seven the policy already requires. No price, because there is nothing yet to sell. No date, because we will not name one we cannot hold. What MeerLock offers is the policy packs and the consulting (online purchase and consulting engagements open soon) — everything else on this page is a description of work in progress, not a commitment. Meanwhile the Training & Acknowledgment Register in our ISMS Toolkit already covers the compliance side of awareness (PCI DSS 12.6, SOC 2 CC1.4).

We use your email only to tell you when it launches. Privacy notice.