Security awareness & training, made playable New: public join codes

Every employee is a target. Make every one a defender.

Aqoon turns security and compliance training into games your team actually plays: phishing spotting, puzzles, policy games and secure coding, with leaderboards and audit-ready evidence.

Free for up to 25 people · no card needed
SPOT THE PHISH+50 XP
From: pay@paysatck.co
Your transfer failed. Verify now or lose access today.
Tap an answer to try it
WORD PUZZLE2 / 6 found · PHISH · CONSENT
POLICY GAMESharing a customer list on your personal WhatsApp?
AllowedNot allowed ✓
NDPA · Acceptable use
SECURE CODINGapi.py
1uid = req.args["id"]2q = "SELECT * FROM txns WHERE id=" + uid3return db.run(q)
Bug found on line 2 · SQL injection
TEAM LEADERBOARD
1Payments4,120
2Support3,860
3You’re here3,000
MAPPED TONDPAGDPRISO 27001PCI DSSCBNOWASP
FRAMEWORKS COVERED
Built for the standards that require staff awareness training.

Each mission maps to the training clause auditors ask about, so playing counts as evidence.

  • Nigeria
    NDPA / NDPR
    Staff privacy awareness via the DPO
  • EU
    GDPR
    Art. 39(1)(b) · staff training
  • Global
    ISO/IEC 27001
    Annex A 6.3 · awareness & training
  • Payments
    PCI DSS v4.0
    Req. 12.6 · security awareness
  • Nigeria
    CBN Cybersecurity
    Awareness & training programme
  • US / Global
    SOC 2
    CC1.4 · CC2.2 · competence
  • Global
    NIST CSF 2.0
    PR.AT · awareness & training
  • Global
    CIS Controls v8
    Control 14 · security awareness
  • EU finance
    DORA
    Art. 13(6) · ICT security training
  • EU
    NIS2
    Art. 20(2) · management training
BY FRAMEWORK

Games mapped to every framework that matters.

Every game in the library is tagged to the framework it trains for, so a challenge you build doubles as compliance evidence.

Nigeria

NDPA & NDPR

Lawful bases, data subject rights, DPIAs and what the NDPC expects when things go wrong.

  1. 1Consent or not?
  2. 2Rights request rush
  3. 3Boss: The cross-border transfer
EU

GDPR

The seven principles, controller vs processor, records of processing and the 72-hour clock.

  1. 1Principle match-up
  2. 2Controller or processor?
  3. 3Boss: The 72-hour clock
Global

ISO/IEC 27001

How the ISMS works day to day: Annex A controls, risk treatment and your part in the audit.

  1. 1Control card sort
  2. 2Risk register builder
  3. 3Boss: Survive the auditor
Payments

PCI DSS

Cardholder data, scope, segmentation and the everyday habits that keep payments in compliance.

  1. 1In scope or out?
  2. 2Mask the PAN
  3. 3Boss: The skimmer
Nigeria

CBN Cybersecurity

What the Central Bank's risk-based framework asks of a fintech: governance, resilience and reporting.

  1. 1Who owns what?
  2. 2Incident report relay
  3. 3Boss: Outage at month-end
Engineers

Secure coding

OWASP Top 10 in the languages your team ships. Find the bug, patch it, beat the clock.

  1. 1Injection station
  2. 2Broken access control
  3. 3Boss: The payments API
GAME LIBRARY

Learn by playing, not by clicking “Next”.

Six categories of games. Admins mix them into challenges, or add their own quizzes, puzzles and scenarios.

Case Files & Simulations

Everyone

Investigate incidents and run team breach drills like the 72-Hour Clock.

Policy Games

Everyone

Allowed or not allowed? Real situations tied to your own policies and the NDPA.

Quizzes

GRC · Ops

Ready-made quizzes for every framework, or write your own in the content builder.

Word Puzzles

Leaders · GRC

Word searches, crosswords and jumbles that make security terms stick.

Spot the Phish

Everyone

Real or fake? Flag the tells in emails, SMS and payment requests before you click.

Secure Coding

Engineers

Find and fix vulnerable code in the languages your team ships, then watch the exploit fail.

SECURE CODE ARENAFor engineers

Find the bug before an attacker does.

Hands-on challenges in the languages your team ships, built around the OWASP Top 10 and the code paths that move money. Earn XP for every vulnerability found, fixed or exploited.

  • Python
  • JavaScript / TypeScript
  • Java
  • Go
  • Kotlin
  • Terraform (AWS)
Counts as developer secure-coding training for PCI DSS Req. 6.2.2 and ISO/IEC 27001 A 8.28, mapped to CWE for your reports.
transactions_api.py
Bugs found 0 / 2+100 XP
Tap the lines you think are vulnerable.Hint: this endpoint returns a customer's payment history. Two lines let an attacker read someone else's.
Beginner

Find it

Spot the vulnerable lines in real-looking code from our own stack.

Intermediate

Fix it

Patch the code in the browser editor. Hidden tests check the exploit fails and features still work.

Advanced

Exploit it

Sandboxed capture-the-flag labs. Break a practice payments API to understand what attackers see.

Team

Review duel

Two engineers, one pull request. First to leave the right security comment wins the round.

ENGINEER RANKS
  1. Rookie
  2. Defender
  3. Bug Hunter
  4. Security Champion
  5. Red Team
Champions review PRs and host bug bashes.
FEATURED SIMULATION

The breach happened. The clock is running.

Teams play the first 72 hours of a data breach together: engineering contains it, legal assesses risk, leadership signs off the notification. Every decision is scored against what the NDPA and GDPR actually require.

  • Multiplayer
  • Role-based decisions
  • Tabletop-exercise evidence
Incident #BR-041747:12:09
  1. Contain: rotate exposed keysEngineering
  2. Assess: whose data, how sensitive?GRC
  3. Decide: notify the regulator?Your move
  4. Communicate: tell affected customersLeadership
HOW IT WORKS

Sign up. Invite. Play.

  1. 1

    Create your workspace

    Sign up and you become the admin of your organization's workspace.

  2. 2

    Invite your team

    Add colleagues one by one by email, or upload a CSV to invite everyone at once.

  3. 3

    Launch a challenge

    Pick games from any category or your own content. Each challenge has its own leaderboard, and results roll up into audit-ready reports.

FOR GRC & SECURITY TEAMS

Stop chasing completions. Start exporting evidence.

See who has played what, where the knowledge gaps are, and which controls your training covers, then hand auditors a report instead of a spreadsheet.

  • Training mapped to ISO 27001, PCI DSS and NDPA clauses
  • Automatic reminders for unfinished missions
  • Weak-spot heatmap by team and topic
  • One-click evidence export (PDF / CSV)
Compliance overview
Sample data · Cybersecurity Awareness Month Challenge
Completion68%
Avg. score81%
Not started14
COMPLETION BY FRAMEWORK
NDPA / NDPR82%
GDPR74%
ISO/IEC 2700161%
PCI DSS48%
Secure coding66%
BADGES

Collect them all. Bragging rights included.

  • Privacy Guardian
  • Breach Buster
  • Control Freak
  • Card Keeper
  • Phish Whisperer
  • Bug Hunter

Ready to beat the auditor
at their own game?

Create your workspace, invite your team and launch your first challenge.