NEW

Start with the pressure: sales, launch, abuse, agents, data, or guardrails

AI Product Security Assessment

Assessment vocabulary for AI security evidence work.

AIPSA is the assessment vocabulary and benchmark domain model used inside the AI Security Scorecard, Field Guide, and Evidence-phase evidence work.

Credential levels

Four practitioner tiers.

7079 score

Associate

Demonstrates foundational knowledge across AI Product Security domains.

Recommended for: Practitioners getting started

View certification →

8089 score

Practitioner

Proficient understanding of AI Product Security and practical application.

Recommended for: Security engineers, analysts, builders

View certification →

9094 score

Advanced

Advanced knowledge and ability to design, assess, and improve AI security controls.

Recommended for: Security leads, senior engineers, architects

View certification →

95100 score

Distinguished

Expert-level mastery across domains and leadership in AI Product Security.

Recommended for: Leaders, advisors, consultants, researchers

View certification →

Assessment domains

14 domains across 6 groups.

Inventory & Architecture

InventoryArchitecture & Trust BoundariesModel & Provider Risk

What AI systems exist, how they're connected, who controls them, and where the trust boundaries are.

Explore evidence instruments →

Adversarial Testing

Threat ModelingPrompt InjectionEvaluation & Regression Testing

Whether adversarial inputs, manipulation, and prompt injection are modeled, tested, and measured over time.

Explore evidence instruments →

RAG & Data Authorization

RAG AuthorizationData Exposure & PrivacyAI Supply Chain

Whether retrieval systems enforce proper authorization, and whether data exposure is controlled end to end.

Explore evidence instruments →

Agentic Permissions

Agentic PermissionsTool AuthorizationWorkflow Boundaries

Whether agentic systems are constrained to the actions they need, with proper guardrails on tool use.

Explore evidence instruments →

Detection & Incident Response

Logging & TelemetryDetection EngineeringIncident Response

Whether AI systems produce actionable telemetry, and whether teams can detect and respond to AI-specific incidents.

Explore evidence instruments →

Governance Evidence

Governance EvidenceCustomer TrustSecure AI SDLC

Whether AI security is documented, auditable, and integrated into delivery — not just asserted.

Explore evidence instruments →

AIPSA verification records confirm completion of a scoped assessment, lab path, or evidence review where issued. They do not certify that any product, organization, or system is free of vulnerabilities.