Security and privacy training on autopilot. Audit-ready every day.

Juno assigns the right security and privacy training to each person automatically, tracks every certification before it expires, and keeps the auditor's evidence ready before anyone asks.

Example data

CellebriteGlobal-eWalkMeeToroJFrogGongCintJobber

The audit is in six weeks. Who is still missing?

Chasing training, expired certificates and evidence by hand takes weeks your team does not have.

How it works

1Trigger & Signal

  • Your HRISA joiner, a new role
  • The certification calendarAn expiry
  • Your GRC or audit trackerA control

2Knowledge Design

Your LLM + Juno MCP

  • Scopes who each control binds
  • Three depths from one rule
You sign the scope off

3Delivery & Adoption

4Measure

who is current, whose credential expires next

The evidence request, answered before it lands

Our ISO 27001 audit is in six weeks. Make sure everyone a control binds is current, and show me who is not.

Claude

Example data

Your phishing platform keeps its job.

Exposure

Give every population what its exposure owes

A simulation finds who clicked. A framework names who is exposed.

Example data

  • Criteria, not clicks

    Role, position, department, location, group and employment type decide who a rule binds.

  • Three depths, one rule

    A module, a scenario drill or a three-minute update, matched to each population.

  • Dry run first

    See how many people the rule reaches before anything goes out.

  • On the framework's clock

    The same rule re-assigns the training on the recurring schedule you set.

Credentials

Nothing expires quietly

Example data

  • Your own certifications

    You create them, decide what earns them and set how long they stay valid.

  • Reminders on your timings

    7 days before the due date, 1 day before, and 2 days after.

  • Credentials earned elsewhere

    Cloud, CISM and DPO certificates upload in bulk to the same roster.

  • What lapses, and when

    Issue date, expiry date, authority and number, on every certification held.

Six weeks to the audit, on the calendar

  1. Week 1

    Scope signed off

    Security owner

  2. Week 2

    Assignments out by depth

    64Engineers with production access41Support with customer data380Everyone else
  3. Week 3

    2 credentials renewed

    • Cloud certification
    • CISM
  4. Week 4

    Retention check

    EngineersSupport
  5. Week 5

    97 % current

    11 named people behind
  6. Week 6

    Auditor's sample

    • The saved view, exported

Example data

Retention

Ask it again in a situation they will actually meet

Example data

  • Three weeks later

    The check returns weeks after the session, as its own step.

  • Two real scenarios

    Open questions that ask what the person would actually do.

  • Who grades it

    A validator, the agent, or the agent with a person confirming.

  • Minutes that happened

    After ten minutes without input the clock stops, so idle time never counts.

The record

Have the record before the request arrives

Example data

  • The auditor's own fields

    Person, role, course, version, assignment, due and completion dates, score and attempts.

  • One framework at a time

    Filter the records to one framework's label and save the view.

  • Proof type

    Each row names what closed it: a certificate or a signature.

  • Sent the same morning

    The saved view exports to a file, so the questionnaire goes out that day.

See the Compliance Training Catalog

Try it

  • Roll out a new policy with proof of completion

    A short course, a 5-question check and an acknowledgment, with a clear list of who's done.

    Your AI asks you

    The policy document, who must complete it, the deadline, acknowledgment or quiz

    The prompt

    I want to roll out a new policy in Juno Journey with proof that everyone who needs to has read and understood it. Use the Juno Journey connector for anything in Juno. If it isn’t connected, stop and tell me how to add it (https://docs.junojourney.com/mcp/overview). Before you build anything, ask me: 1. The policy document (upload it, or tell me where it lives) 2. Who must complete it (departments, locations, roles) 3. The deadline 4. Acknowledgment, a quiz, or both Ask these in one message, then wait for my answers. If the document lives in a tool outside Juno, check it’s connected in this chat; if not, I’ll upload it. Stick to what the policy says; don’t add rules. Search Juno for older versions of this policy training and update rather than duplicate. Then plan a short course (what changed, what it means for you, examples), a 5-question check with a pass mark, and an acknowledgment step. Show me that outline, the audience and the due date first, then build as drafts. Don’t publish, assign or notify anyone until I explicitly approve.

  • A completion heatmap by team and topic

    Teams down the side, topics across the top, so the gaps show up before the deadline does.

    Your AI asks you

    Which groups and topics, which courses count, what "done" means, the date range

    The prompt

    I want a completion heatmap: groups down the side, topics across the top, and each cell showing how far along that group is. Use the Juno Journey connector for anything in Juno. If it isn’t connected, stop and tell me how to add it (https://docs.junojourney.com/mcp/overview). Before you build anything, ask me: 1. Which groups (departments, roles, locations) 2. Which topics, and which courses count for each 3. What “done” means (completed, passed, above a score) 4. The date range Ask these in one message, then wait for my answers. Pull everything you can from Juno; if you can’t read completions here (analytics may be off for our account), I’ll upload an export from Juno. If a grouping lives outside Juno (e.g. an HR system, if we use one), check it’s connected in this chat; if not, I’ll upload a CSV. Never guess anyone’s group. Confirm definitions with me, then build an interactive artifact: the heatmap with counts per cell, a click-through to the people in each cell, and the three weakest spots with suggested next steps. State definitions, show sample sizes, and grey out cells too small to judge. Don’t assign or notify anyone.

  • Find training that's out of date

    Claude checks your courses against your source of truth and lists what to fix first.

    Your AI asks you

    Where your source of truth lives, which topics matter most, what counts as a recent change

    The prompt

    I want to find training in Juno Journey that no longer matches how things actually work today. Use the Juno Journey connector for anything in Juno. If it isn’t connected, stop and tell me how to add it (https://docs.junojourney.com/mcp/overview). Before you build anything, ask me: 1. Where our source of truth lives (product docs, release notes, policies) 2. Which topics or courses matter most 3. How recent a change must be to count Ask these in one message, then wait for my answers. Check that source is connected in this chat; if not, I’ll connect it or upload the documents. Only flag drift you can show evidence for. Read the relevant Juno courses, quizzes and journeys, compare each claim to the source, and give me a table: course, what it says, what the source says now, severity, suggested fix. This is a review, not an edit: change nothing yet. Offer to draft updated versions of the top items; after I approve, save them as drafts and don’t publish until I say so.

Every prompt

“Automated course assignments, reminders, and escalation flows based on role, legal mandates, and business needs.”

Trained thousands on key topics including compliance (5,200), information security (4,885), financial monitoring (~5,400) and personal safety (5,981).

Raiffeisen Bank case studySeptember 2025
“Running our compliance season with Juno was smooth, structured, and highly effective. Everything from automated assignments and reminders to manager visibility and real-time dashboards was planned in advance and executed flawlessly. We achieved over 90% completion across the company, and the process felt completely under control from start to finish.”
Marion D.People Experience Partner, Efficy
“Individual records should identify the employee or immutable user ID, department or role, assigned course, policy version, assignment date, due date, completion date, score, attempts, and pass threshold.”
Enterprise Security Awareness Training Audit ChecklistAdaptive Security, August 21, 2026Source

Off your payroll, the same rule still binds.

Back to Compliance

Questions people ask.

What security and privacy training do ISO 27001, SOC 2 and GDPR require?

They ask who is bound by which control, whether those people were trained on it, and whether the evidence is still valid. Your counsel reads the frameworks. Juno selects the people each control binds, keeps their training and certifications current, and holds the per-person record an auditor samples. Course coverage lives on the Compliance Training Catalog.

How do you prove security awareness training to an auditor?

Open the learner records and filter them to the framework: the person, their role, the course, the published version they were given, the assignment, due and completion dates, the score and the attempts. Save that as a view and export it. Certifications held, with their issue and expiry dates, export from the roster the same way.

Do we need a security awareness platform and an LMS?

Often both, because they do different jobs. A security awareness platform runs phishing simulations and scores who clicked, and Juno does neither. Juno carries the obligation set, the certifications that expire and the per-person record, and it plays the awareness platform's SCORM module inside the same assignment. Your phishing platform keeps its job.

How do we track security certifications that expire?

You create your own certifications in Juno, decide what earns them and set how long they stay valid, with reminders before the date. Credentials earned elsewhere, such as a cloud certification, CISM or a DPO qualification, upload in bulk to the same roster with their authority, number and proof file, and the roster reports what expires and when.

How do we assign privacy training only to the people who handle personal data?

Build the assignment rule from who handles the data: department, position, location, group and employment type, in combination. The rule sends the privacy training to that population only, at the depth it owes, and re-assigns it on the schedule you set. A dry run shows how many people it will reach before anything goes out.

Can we run our existing security awareness modules in Juno?

Yes. SCORM 1.2 and 2004, xAPI and cmi5 packages upload and play in Juno, and LTI 1.3 tools run inside it, so the module you already license keeps working. Juno assigns it to the people each control binds, tracks who is current, and keeps its record beside the rest of the obligation set.

A prospect's security questionnaire asks for our training records. How do we answer it?

From the same record you keep for the auditor. Filter the learner records to the controls the questionnaire names, save the view and export it: person, course, version, date and proof type. The question that used to take a week of spreadsheets becomes a file you can send the same morning, before it holds the deal up.

Is it safe to let an AI assign security training and read our HR data?

Juno's MCP works inside the permissions your people already hold in Juno, over OAuth 2.1. Publishing, assigning and notifying wait for an explicit review before anything is confirmed, and drafts stay invisible to learners until they are published. What we hold, each item with its status, is listed on the Trust Center.