Compare

You're evaluating Dune Security and Moxso. Here's where each one wins.

Dune Security has built a credible product for US enterprise security teams who want User Adaptive Risk Management. The Sequoia-backed team has assembled a Fortune 1,000 customer base and a CISO advisory board with serious names. We respect what they've built. Moxso operates differently. We are the European architecture for Human Risk Intelligence. Built in Copenhagen, EU sovereign by architecture, NIS2 21(2)(f) and DORA pre-mapped at the calculation level. Our customer base is European banking, public-sector critical infrastructure, retail at scale, and high-growth fintech.

This page is the honest comparison.

Where Dune fits

A strong choice for the US enterprise security team.

Dune is built for the US enterprise CISO operating under SOC 2, HIPAA, and the US regulatory framework. The integration depth across IAM, SEG, EDR, and DLP is real. The OpenAI-grade attack simulation engine produces high-quality phishing content. For a US-headquartered, US-hosted enterprise running on Microsoft or Google identity, with primary regulatory exposure in the US, Dune is a defensible choice.

You're a Dune buyer if:

  • Your operating environment is US-regulatory primary
  • Your buying committee values Sequoia and American venture brand association
  • Your data residency requirements are US or US-permissible
  • Your audit framework is SOC 2 Type II and US compliance regimes
  • Your buying committee values the named CISO advisory board as a primary credibility signal

If those describe you, Dune is doing what it was built to do.

Where Moxso operates differently

Different geography. Different category. Different architecture.

EU sovereign by architecture, not just hosted in Europe. Hosted on Scaleway. Sub-processors disclosed publicly. No US-based primary data processing. NIS2 21(2)(f) and DORA pre-mapped at the calculation level. For European buyers, banks under DORA scope, critical infrastructure under NIS2, regulated industries under sectoral frameworks, this is procurement-grade architectural difference.

The Risk Framework, not just a risk score. Dune produces a User Risk Score. Moxso produces a Resilience Score backed by sixteen explicit risk categories, including HUAI (Human Use of AI) and AAI (Agentic AI), the two no other vendor has built, aligned with MITRE ATT&CK and NIST. Methodology versioned and published. The auditor reads the framework before the call.

Three signals connected, not just behavior and integrations. Dune integrates with IAM, SEG, EDR, DLP. Strong stack ingest. Moxso reads behavior, live OSINT classified by industry and region, and organizational weight at the individual. Connected signals, not just integrated feeds. The difference: Moxso reads what's happening to your sector right now and routes the next intervention to the exposed users on capture. Dune scores what your stack tells it after the fact.

The Signal Bus, framed as architecture not feature. Both vendors integrate with security stacks. Moxso frames the integration as the human layer becoming a connected layer of the security stack, the SOC's view of human risk in the same operational surface as everything else. Behavior becomes context the SOC can act on, not a parallel dashboard.

Adaptive Human Security as category, not as feature. Dune's category is User Adaptive Risk Management, a feature-shaped category claim. Moxso's category is Adaptive Human Security, a security-architecture-shaped category claim. The framing matters because it determines what the buyer is comparing against. Dune competes against SAT vendors with better integrations. Moxso competes against the architectural assumption that the human layer is a parallel program rather than a connected one.

The decision matrix

When Dune. When Moxso.

Choose Dune if you're a US enterprise with primary US regulatory exposure, a Microsoft or Google identity environment, and a buying committee that prioritizes the Sequoia/CISO-advisory-board credibility model.

Choose Moxso if any of these is true:

  • You're a European organization under NIS2, DORA, or any sectoral framework that demands EU-sovereign data architecture
  • Your auditor is asking how you produce evidence at the calculation level, not just at the dashboard level
  • You're a multi-country European business and your program is duplicating effort across regions
  • Your SOC needs human risk signal in the same operational view as everything else
  • You're seeing AI-driven attacks (deepfake, agentic, voice impersonation) and you want a vendor with explicit risk categories for them
  • Your buying committee includes a GRC lead, a DPO, or a procurement officer who will reject US-hosted human-risk tooling on data residency grounds
A note on geography

Decided by data residency and primary jurisdiction.

Dune is a strong choice for US enterprise. Moxso is a strong choice for European enterprise. Where the buying committee is split, a European subsidiary of a US parent, or a US subsidiary of a European parent, the deciding factor is usually data residency and regulatory primary jurisdiction. Both vendors are honest enough to say so in the call.

Get started

Twenty minutes. Bring your shortlist.

We will show you the engine running on your actual signal, walk you through the architectural difference between Adaptive Human Security and User Adaptive Risk Management, and price it per seat in the call. No nurture sequence. One working day to a slot.

Get started

See how your team can reduce human risk

Explore how Moxso helps your team identify employee risk, target training and assess progress. Tell us where you want to reduce exposure.

  • Explore how training, simulations and follow-ups address gaps.
  • See how human risk varies across your organization, departments and employees.
  • Review how your goals automatically steer risk reduction.

By submitting this form, you agree to our Privacy Policy. We will be in touch within one working day. No nurture sequence.

ISO 27001 certifiedEnterprise-grade security across all operations.
EU sovereign by architectureData sovereignty compliance built in.