Logo StartupKit
EN

Training Template Library

Browse Kit's shared library of ready-made decks (SOC 2, GDPR, ISO 27001, HIPAA, plus two evidence checklists) and seed a complete program from one.

Choosing a Template

The library contains four course templates and two checklists. Courses cover SOC 2, GDPR, ISO 27001, and HIPAA topics. Checklists collect device-setting evidence or acknowledgments of company policies.

Choose a template for your training scope, fill in company details, and review the content before publishing. Templates need adaptation; they do not replace a compliance assessment or guarantee an auditor’s acceptance.

Browsing the Library

From the Training dashboard, click Build from template to open the gallery at /training/templates. The library shows one card per framework, each with its name, a short description, the language, and an approximate slide and question count. Click Use this template on the card you want.

Note

The template library is admin-only. The Build from template link and the gallery are visible to Training module admins, the same people who author and publish programs. Participants take the training they are invited to; they do not see the library.

The Four Course Templates

These four follow the same shape: an ordered set of content slides, a multiple-choice knowledge check, and a sign-off attestation. Each is roughly 12–14 slides plus a knowledge check, with company-specific facts written once as {{ variables }} and filled in from your answers.

Framework Deck covers
SOC 2 The all-hands annual security-awareness and business-continuity deck: phishing, credentials, MFA, device security, data handling, remote work, dependency hygiene, AI tools, incident reporting, and continuity.
GDPR Data-protection staff awareness: the core principles, personal vs. special-category data, lawful basis and consent, data-subject rights, minimization and retention, processors and DPAs, international transfers, privacy by design, and breach reporting, including the 72-hour deadline where notification is required.
ISO 27001 Information Security Management System (ISMS) awareness: what the ISMS is and why certification matters, the security policy, everyone’s role, risk treatment, information classification, access control, cryptography, clear desk, operations and supplier security, incident reporting, and business continuity.
HIPAA Workforce training for the Privacy Rule and Security Rule: what counts as PHI and ePHI, the minimum-necessary standard, permitted uses and disclosures, patient rights, safeguards for devices and communications, Business Associate Agreements, breach reporting, and secure disposal.

Tip

Pick the framework named in the audit or certification you’re pursuing. If you’re covering general staff security awareness with no specific regime in mind, SOC 2 is the broadest starting point.

The Two Evidence Checklists

The other two templates collect confirmations. One covers device settings with screenshots; the other records policy acknowledgments. They use checkpoints instead of slides and have no quiz.

Deck Deck covers
Endpoint Hardening The seven device settings an auditor asks a contractor to prove: full-disk encryption, screen lock, automatic OS updates, malware protection, password manager, firewall, and password length. Six take a screenshot; password length is attest-only. macOS, Windows 11, and Linux instructions per checkpoint.
Policy Acknowledgment The 22 policies included in the SOC 2 template as attest-only checkpoints, grouped into conduct, information security, data, resilience, and governance. The signed attestation names every policy, so the signature covers specific documents rather than a blanket claim.

See Evidence Checklists for how they are built, taken, reviewed, and retained.

Language Selection

Template content (slides, quiz, attestation) is authored in English today. Each card in the gallery is resolved to your account’s language automatically: Kit reads your account’s Default Language setting, shows the matching variant when one exists, and otherwise falls back to the English deck. More languages are planned; as localized decks are added, the same account setting will surface them with no change on your side.

The gallery chrome (headings, buttons, counts) is already localized into every language Kit supports, so the page reads naturally even while the deck content itself is English.

From Template to Program

Picking a deck seeds a complete program, then hands you straight to the smart-template Q&A to make it yours:

  1. Choose: On the gallery, click Use this template for the framework you want. Kit creates a program named after your account and seeds the full deck: every slide, the quiz, and the attestation.
  2. Fill in your specifics: You land on the smart-template questions. Answer a short list about your company (name, password manager, incident contact, and so on); each answer fills the {{ variables }} across every slide and the attestation.
  3. Refine: Review and edit slides, tune the knowledge check, and adjust the attestation text.
  4. Publish: Once the program has at least one slide, a configured quiz, and attestation text, publish it and invite participants.

Each seeded program is independent and tenant-scoped: your content stays yours, and choosing a template never touches other programs.

Re-seeding Is Safe

A program remembers which deck it came from. You can return to the smart-template questions at any time, change an answer, and re-seed. Re-seeding is idempotent: each template slide is matched by its key and updated in place, so re-running never creates duplicates and never clobbers slides you added by hand.

Important

Re-seeding refreshes the template’s own slides, quiz, and attestation from the deck it was seeded from. The smart-template form reuses the same framework you originally picked. Re-seeding updates template slides and leaves hand-authored slides untouched. It overwrites edits you made to template-owned slides.

For AI Agents (MCP)

The library is also reachable over Kit’s MCP tools. training_list_templates returns the available decks with their kind and counts for the account’s language, and training_seed_from_template accepts a template parameter, either a course key (soc2, gdpr, iso27001, hipaa) or a checklist key (endpoint_hardening, policy_acknowledgment), so an agent can seed the right deck. Omitting the parameter defaults to SOC 2. training_create_program takes a kind of course or checklist for authoring one from scratch.

Next Steps

Type to search...