NDPA & NDPR
Lawful bases, data subject rights, DPIAs and what the NDPC expects when things go wrong.
- 1Consent or not?
- 2Rights request rush
- 3Boss: The cross-border transfer
Aqoon turns security and compliance training into games your team actually plays: phishing spotting, puzzles, policy games and secure coding, with leaderboards and audit-ready evidence.
Free for up to 25 people · no card neededEach mission maps to the training clause auditors ask about, so playing counts as evidence.
Every game in the library is tagged to the framework it trains for, so a challenge you build doubles as compliance evidence.
Lawful bases, data subject rights, DPIAs and what the NDPC expects when things go wrong.
The seven principles, controller vs processor, records of processing and the 72-hour clock.
How the ISMS works day to day: Annex A controls, risk treatment and your part in the audit.
Cardholder data, scope, segmentation and the everyday habits that keep payments in compliance.
What the Central Bank's risk-based framework asks of a fintech: governance, resilience and reporting.
OWASP Top 10 in the languages your team ships. Find the bug, patch it, beat the clock.
Six categories of games. Admins mix them into challenges, or add their own quizzes, puzzles and scenarios.
Investigate incidents and run team breach drills like the 72-Hour Clock.
Allowed or not allowed? Real situations tied to your own policies and the NDPA.
Ready-made quizzes for every framework, or write your own in the content builder.
Word searches, crosswords and jumbles that make security terms stick.
Real or fake? Flag the tells in emails, SMS and payment requests before you click.
Find and fix vulnerable code in the languages your team ships, then watch the exploit fail.
Hands-on challenges in the languages your team ships, built around the OWASP Top 10 and the code paths that move money. Earn XP for every vulnerability found, fixed or exploited.
Spot the vulnerable lines in real-looking code from our own stack.
Patch the code in the browser editor. Hidden tests check the exploit fails and features still work.
Sandboxed capture-the-flag labs. Break a practice payments API to understand what attackers see.
Two engineers, one pull request. First to leave the right security comment wins the round.
Teams play the first 72 hours of a data breach together: engineering contains it, legal assesses risk, leadership signs off the notification. Every decision is scored against what the NDPA and GDPR actually require.
Sign up and you become the admin of your organization's workspace.
Add colleagues one by one by email, or upload a CSV to invite everyone at once.
Pick games from any category or your own content. Each challenge has its own leaderboard, and results roll up into audit-ready reports.
See who has played what, where the knowledge gaps are, and which controls your training covers, then hand auditors a report instead of a spreadsheet.
Create your workspace, invite your team and launch your first challenge.