Prerequisite course
Security AI Engineering.
- 12 modules
- A lab artifact per module
- Completion record only
- Not a certification
Read this first
Course completion is not certification. Finishing this course produces a completion record with its own identifier and its own expiry, clearly marked as not being SA-APEX. Certification comes from the independent performance exam, and plenty of people who complete the course will not pass it.
Anyone presenting a course completion as a certification is misrepresenting it, and we will say so publicly if asked.
Scope
What this course does not teach.
- Excluded:Penetration testing.
- Excluded:Red teaming.
- Excluded:Programming fundamentals.
- Excluded:Vulnerability scanning.
- Excluded:How to copy prompts.
You are expected to arrive able to run the engagement. What most experienced testers have not done is build the governed system around a model — the classification, the gateway, the isolation, the evidence chain and the audit trail that make AI use defensible on a real client.
That is the entire subject of this course.
Learning outcomes
What you will be able to do afterwards.
- Included:Classify engagement data and choose an allowed AI deployment from sensitivity, contract, geography, retention and provider terms.
- Included:Build a model gateway that enforces provider allowlists, redaction, tenancy, retention, logging, budgets and an emergency shutdown.
- Included:Design agents with narrow roles, least-privilege tools, explicit inputs and outputs, and bounded execution.
- Included:Create retrieval and context pipelines that preserve provenance and cannot contaminate one client with another.
- Included:Use AI for hypothesis generation, code navigation, test creation, payload mutation, exploit assistance and reporting while keeping a human accountable for the result.
- Included:Measure precision, recall proxies, validation yield, duplicate rate, evidence sufficiency and critical-coverage gaps.
- Included:Detect hallucinations, prompt injection, poisoned context, tool misuse and confident-but-unproven findings.
- Included:Build evidence-linked reports and run completeness reviews that do not simply ask the same model whether it was right.
Curriculum
Twelve modules. Each one ends with something you built.
| # | Module | Scope | Required lab artifact |
|---|---|---|---|
| 1 | AI systems for offensive engineers | Tokens, context, inference, embeddings, retrieval, agents, tools, deterministic code, model limits, threat model. | Architecture comparison and failure analysis. |
| 2 | Client-data classification | Public, internal, confidential, restricted, regulated, secrets, exploit artifacts and prohibited data. | Engagement data-handling plan. |
| 3 | Private model patterns | Local inference, dedicated deployments, contractual APIs, zero-retention modes, regional controls, air-gapped options. | Deployment decision record with threat model. |
| 4 | Secure model gateway | Authentication, authorization, policy, tokenization, DLP, redaction, tenant keys, logging, rate and budget limits, kill switch. | Working gateway policy and leakage tests. |
| 5 | Context and retrieval engineering | Chunking, source integrity, isolation, provenance, freshness, injection resistance, selective disclosure. | Client-isolated retrieval pipeline. |
| 6 | Agent and tool design | Role decomposition, least agency, tool schemas, safe defaults, sandboxing, scope enforcement, concurrency. | Two specialized agents with controlled tools. |
| 7 | AI-assisted code audit | Trust-boundary mapping, data flow, state transitions, authorization, business logic, unsafe composition, variant analysis. | Novel defect hypothesis and trace package. |
| 8 | Exploit engineering with AI | Harness generation, mutation, debugging, differential testing, safe proof construction, human code review. | Candidate-explained proof of concept and negative controls. |
| 9 | False-positive engineering | Evidence gates, independent reproduction, counterexamples, consensus limits, deterministic validators, confidence calibration. | Evaluation set and precision report. |
| 10 | Coverage and criticality | Attack-surface inventory, test obligation graph, uncovered paths, stop rules, critical miss review. | Coverage ledger and residual-risk statement. |
| 11 | AI-assisted reporting | Evidence-to-finding pipeline, templates, citations, severity, remediation, executive translation, fact locking. | Generated report with a validation manifest. |
| 12 | Operations and incident response | Monitoring, prompt and tool audit, leakage response, revocation, evidence retention, model version change control. | AI security incident tabletop. |
Labs are assessed for safe architecture, reproducibility, data handling, code quality, evidence quality and candid treatment of limitations. An artifact that hides what did not work scores worse than one that names it.
After the course
The course is step three of eight.
Completion feeds the practice range, which produces readiness evidence, which is what schedules an exam. There is no route from “finished the modules” straight to a credential, and the platform will not create one.
Course pricing is not set. It will be published — like every other price on this site — once delivery cost, eligibility review and support are known. See the open decision log.