Mandatory training, sorted and certified
TrainIA trains and certifies your team in cybersecurity and quality, and automatically generates the evidence every audit requires, with no spreadsheets or manual tracking.
Value for the organisation and for its professionals
A single system to roll out training, measure progress and evidence compliance.
Demonstrable compliance
Each employee generates a verifiable record of the content completed and the mark obtained, and receives a certificate issued by Zerolynx as an independent third party. The evidence the auditor asks for is documented automatically.
Immediate roll-out
Register your organisation and your learners to begin training without delay. Each organisation has a manager who administers its own learners under its supervision.
Control and visibility
A dashboard with the percentage of progress, passes, marks and certificates by organisation and by course. Certificates can be downloaded individually or in batches.
Clear, effective content
Visual, concise material, designed so that any professional can complete it without difficulty, with a final assessment they can retake until they pass.
Multi-organisation architecture
Suitable for corporate groups and for service providers. Each client organisation manages its learners independently, with its own space and its own reports.
Low investment
From €1 per learner a month. Training and certifying your whole workforce costs a fraction of a single security incident.
All your training control in one place
From the administration dashboard to the learner experience: narrated content, assessment, progress and certificates, with the evidence ready for audit.
Training is a regulatory requirement
The main security and quality frameworks require organisations to train and raise the awareness of their people. TrainIA meets that requirement and provides the corresponding evidence.
National Security Framework (ENS)
RD 311/2022, Annex II [mp.per.3] and [mp.per.4]The personnel protection framework requires the awareness [mp.per.3] and training [mp.per.4] of employees in security matters. The ENS course is already available.
ISO/IEC 27001:2022
Clauses 7.2 and 7.3, control A.6.3It requires evidence of the competence (7.2) and awareness (7.3) of personnel, together with control A.6.3, 'Information security awareness, education and training'.
NIS2 Directive (EU 2022/2555)
Articles 20.2 and 21.2.gIt requires the training of management bodies (Article 20.2) and cyber hygiene practices and staff training (Article 21.2.g).
ISO 22301, ISO 9001 and ISO 42001
Clauses 7.2 and 7.3 (competence and awareness)ISO management systems share the requirement to ensure the competence and awareness of personnel. A single system covers them all.
Subsidised training (FUNDAE)
RD 694/2017, e-learning requirementsWe build TrainIA following the e-learning requirements of Spanish RD 694/2017, so that your company can fund training with its FUNDAE credit. Please note that FUNDAE does not approve or certify platforms: communicating the groups and managing the credit are the responsibility of your company or its consultancy.
GDPR and LOPDGDD
Regulation (EU) 2016/679, Article 39.1.bThe tasks of the Data Protection Officer include the awareness and training of staff involved in the processing of personal data. Privacy training provides evidence of that diligence.
Courses in cybersecurity and quality
They all share the same structure: visual content, a 15-question final assessment and a certificate. Each course also includes a teaching script, narrated by voice, that explains every slide just as a trainer would in the classroom. This way the learner does not merely read the material but understands and absorbs it, following a coherent thread from start to finish. The catalogue grows continually.
Awareness
11 courses- Awareness for Senior Management
- CEO Fraud and Business Email Compromise
- Cybersecurity awareness
- Deepfakes and AI fraud
- Information Classification and Handling
- Mobile device security and BYOD
- Passwords, MFA and Password Managers
- Phishing and Social Engineering
- Ransomware: prevention and response
- Secure Email, Web Browsing and Social Media
- Security in the Workplace and Remote Working
Standards
14 courses- CIS Controls
- Implementing and Auditing ISO 27001, Level 2
- ISO/IEC 20000-1
- ISO/IEC 27001
- ISO/IEC 27001 Internal auditor
- ISO/IEC 27002: Security Controls
- ISO/IEC 27005: Risk Management
- ISO 9001
- ISO 19011: Auditing management systems
- ISO 22301
- National Security Framework (ENS)
- NIST Cybersecurity Framework 2.0
- Risk Management (ISO 31000)
- SOC 2: trust for service organisations
Privacy & data
7 courses- Data breaches and the 72-hour notification
- Data Governance
- Data Protection (GDPR and LOPDGDD)
- Data protection impact assessments (DPIA)
- GDPR Level 2 for the Data Protection Officer: practical cases
- ISO/IEC 27017 and 27018 (Cloud security and privacy)
- ISO/IEC 27701 (Privacy information management, PIMS)
Regulation & compliance
13 courses- Anti-bribery with ISO 37001
- Anti-money laundering (AML)
- Automotive cybersecurity with ISO/SAE 21434
- Criminal compliance and UNE 19601
- DORA (Digital Operational Resilience)
- eIDAS 2 and Electronic Signatures
- Industrial cybersecurity with IEC 62443
- Ley 2/2023 and the Whistleblowing Channel
- NIS2
- PCI DSS: Payment Card Security
- Supplier Security
- The Cyber Resilience Act
- TISAX: Information Security in the Automotive Industry
AI governance
7 courses- AI application security (OWASP LLM Top 10)
- Ethics of artificial intelligence
- European AI Regulation (AI Act)
- ISO/IEC 42001 Level 1: Foundations
- ISO/IEC 42001 Level 2: Implementing the AIMS
- ISO/IEC 42001 Level 3: Advanced auditing and governance
- Safe Use of Generative AI
Offensive security
28 courses- Advanced web exploitation: beyond the OWASP Top 10
- Binary Exploitation Level 2: From Overflow to Shell
- Burp Suite Level 2: from proxy to exploit
- C2 Level 2: modern frameworks and their detection
- Cloud penetration testing
- Cloud Pentest Level 2: AWS and Azure in Practice
- Command and Control and adversary emulation
- Credential attacks and password cracking
- Credential Attacks Level 2: Cracking and Abuse
- Infrastructure Pentesting Level 2: from the first packet to Domain Admin
- Internal infrastructure and corporate network pentesting
- Introduction to binary exploitation (buffer overflow)
- Introduction to ethical hacking and pentest methodology
- Mobile application hacking (Android and iOS)
- Mobile Hacking Level 2: Android and iOS in Practice
- Nmap: network scanning and auditing
- Nmap Level 2: NSE, Evasion and In-Depth Scanning
- OSINT and Reconnaissance
- OSINT Level 2: reconnaissance with tooling
- Pentest Methodology Level 2: From Scope to Report With Real Tools
- Post-exploitation, lateral movement and pivoting
- Post-Exploitation Level 2: From Shell to Domain Control with Real Tools
- Red Team and social engineering
- Red Team Level 2: social engineering and phishing infrastructure
- Web Exploitation Level 2: chaining laboratory
- Web pentesting with Burp Suite
- Wi-Fi security
- WiFi Security Level 2: Attacks in Your Own Lab
Defensive security
16 courses- Active Directory Security and Hardening
- Blue Team fundamentals and defence in depth
- Cloud Security Level 2: practical hardening
- Container and Kubernetes security
- Cybersecurity Incident Management
- Defending Active Directory
- Defensive deception with honeypots and honeytokens
- Detection and Blue Team with MITRE ATT&CK
- Detection engineering with Sigma and YARA
- Endpoint detection and response (EDR and XDR)
- Incident Response and Threat Hunting Level 2
- Proactive threat hunting
- Purple Team: collaboration between offence and defence
- Running a SOC with a SIEM
- Systems hardening
- Threat intelligence
Application security
11 courses- API security with the OWASP API Security Top 10
- Applied cryptography for developers
- Automated security testing: SAST, DAST and SCA
- DevSecOps: security in the development lifecycle
- Secure authentication and authorisation (OAuth 2.0 and OpenID Connect)
- Secure Development Level 2: Hardening Code and Architectures
- Secure software development
- Secure source code review
- Security verification with OWASP ASVS
- Software supply chain security and secrets management
- Threat Modeling
Digital forensics
8 courses- Cloud forensics
- Computer Forensics and Expert Witness Reporting
- Linux systems forensics
- Malware analysis
- Malware reverse engineering
- Memory forensics
- Network forensics
- Windows systems forensics
And many more courses
These are just the first. We keep expanding the catalogue with new cybersecurity, compliance and quality courses, all at the same price.
TrainIA is by Zerolynx
TrainIA is not a third-party tool: it is Zerolynx's own product, from a company specialising in cybersecurity. The platform being ours means it evolves continually, that support is provided by the people who build it and that the courses are written by a team that lives security, compliance and quality every day. The result is rigorous, up-to-date content aligned with the reality of organisations.
From sign-up to certificate in three steps
Register your team
Create your organisation and add your learners, or delegate this task to each organisation's manager. The process takes minutes.
Training and assessment
Each learner completes the course at their own pace and passes the final assessment, with unlimited attempts and a pass mark of 5 out of 10.
Get the evidence
Download the certificates with mark and date, individually or in batches. Progress and compliance are reflected on the dashboard.
Your whole workforce trained from €1 a month
- All catalogue courses included
- Unlimited certificates issued by Zerolynx
- Compliance dashboard and batch download
- Flexible terms: renew month by month or for the full year
Meet your training requirement this quarter
Train and certify your whole workforce with a complete cybersecurity and quality catalogue, and have your compliance evidence from day one.
Access the platform