PARTNERS

Embed, resell, or white-label AI security — OEM, scanner, MSSP, consulting, and reseller tracks are open now

aisecurity.llc · site index

Site Map

Complete index of every page — 1,416 routes across 20 sections. Titles, descriptions, keywords, and source file paths extracted at build time.

1,416Total routes
1,204Sitemap-indexed
1,099With description
624With keywords
320With file path
20Sections

Core

1 page

Platform entry points

Workbench

1 page

SecEng instruments and delivery tools

Services

114 pages

Map, Attack, Defend, Evidence, and packaged service instruments

Attack
Test realistic AI abuse paths across prompts, retrieval, tools, agents, tenants, and model behavior.
/attack
Defend
Turn AI security findings into controls, guardrails, evals, approval gates, telemetry, and release criteria.
/defend
Evidence
Package AI security work into buyer-ready evidence, governance artifacts, claim-readiness labels, and control mappings.
/evidence
Map
Identify AI systems, trust boundaries, workflows, vendors, data flows, agents, tools, and launch risks.
/map
Services
Expert-led AI security services organized around Map, Attack, Defend, and Evidence.
/services
SecEng AI Security Program Jumpstart — Service
Expert-led service route for SecEng AI Security Program Jumpstart.
/services/seceng-program-jumpstart
Agentic Workflow Abuse Review
An adversarial review of AI agents, tools, automations, permissions, approvals, workflows, rollback paths, and action boundaries. It tests the action layer…
ai securityserviceagentic-workflow-abuse-review
/services/agentic-workflow-abuse-review
Agentic Workflow Security & Hardening
A hardening engagement for AI agents and workflows: permission design, tool policies, approval gates, scoped credentials, logging, rollback, exception…
ai securityserviceagentic-workflow-security-hardening
/services/agentic-workflow-security-hardening
AI Governance & Security Program Build
A program-building engagement that turns AI security from scattered policy into operating model, ownership, controls, evidence, workflows, and governance…
ai securityserviceai-governance-security-program-build
/services/ai-governance-security-program-build
AI Guardrails & Evals Review
A review and improvement plan for guardrails, evals, refusal behavior, fallbacks, test coverage, monitoring, regression cases, and release criteria.
ai securityserviceai-guardrails-evals-review
/services/ai-guardrails-evals-review
AI Launch Security Review
A 5–10 business day pre-release security review for AI features, copilots, RAG systems, agents, and AI workflows. Find the launch-blocking AI security risks…
ai securityserviceai-launch-security-review
/services/ai-launch-security-review
AI Product Security Assessment
The deeper 2–4 week assessment for AI-enabled products — typically the follow-on to an AI Launch Security Review, or when a system needs full architecture…
ai securityserviceai-product-security-assessment
/services/ai-product-security-assessment
AI Red Team & Adversarial Testing
A focused adversarial engagement testing prompt injection, indirect instruction attacks, RAG exposure, tool abuse, tenant leakage, policy bypasses, unsafe…
ai securityserviceai-red-team-adversarial-testing
/services/ai-red-team-adversarial-testing
AI Security Program Baseline
A fast diagnostic of product, engineering, governance, evidence, and AI-security maturity. It gives leaders a lower-friction first artifact and a prioritized…
ai securityserviceai-security-maturity-benchmark
/services/ai-security-maturity-benchmark
AI Security Sales Enablement
A workshop-first evidence sprint for AI-enabled products, designed to help sales, SE, product, legal, and security teams answer enterprise AI-security…
ai securityserviceai-security-sales-enablement
/services/ai-security-sales-enablement
SecEng Enterprise AI Security Buildout — Service
Expert-led service route for SecEng Enterprise AI Security Buildout.
/services/seceng-enterprise-buildout
Agentic Workflow Abuse Review — Discovery
Consulting discovery and intake for agentic workflow abuse review.
consultingdiscoveryagentic-workflow-abuse-reviewai security
/consulting/discovery/agentic-workflow-abuse-review
Agentic Workflow Security Hardening — Discovery
Consulting discovery and intake for agentic workflow security hardening.
consultingdiscoveryagentic-workflow-security-hardeningai security
/consulting/discovery/agentic-workflow-security-hardening
Ai Governance Security Program Build — Discovery
Consulting discovery and intake for ai governance security program build.
consultingdiscoveryai-governance-security-program-buildai security
/consulting/discovery/ai-governance-security-program-build
Ai Guardrails Evals Review — Discovery
Consulting discovery and intake for ai guardrails evals review.
consultingdiscoveryai-guardrails-evals-reviewai security
/consulting/discovery/ai-guardrails-evals-review
Ai Launch Security Review — Discovery
Consulting discovery and intake for ai launch security review.
consultingdiscoveryai-launch-security-reviewai security
/consulting/discovery/ai-launch-security-review
Ai Product Security Assessment — Discovery
Consulting discovery and intake for ai product security assessment.
consultingdiscoveryai-product-security-assessmentai security
/consulting/discovery/ai-product-security-assessment
Ai Red Team Adversarial Testing — Discovery
Consulting discovery and intake for ai red team adversarial testing.
consultingdiscoveryai-red-team-adversarial-testingai security
/consulting/discovery/ai-red-team-adversarial-testing
Ai Security — Discovery
Consulting discovery and intake for ai security.
consultingdiscoveryai-securityai security
/consulting/discovery/ai-security
Ai Security Maturity Benchmark — Discovery
Consulting discovery and intake for ai security maturity benchmark.
consultingdiscoveryai-security-maturity-benchmarkai security
/consulting/discovery/ai-security-maturity-benchmark
Ai Security Sales Enablement — Discovery
Consulting discovery and intake for ai security sales enablement.
consultingdiscoveryai-security-sales-enablementai security
/consulting/discovery/ai-security-sales-enablement
AI Security Speed Run Integration
Tauri desktop learning tool for rapidly onboarding engineers onto AI security fundamentals, control frameworks, and threat models.
desktoptaurirun_exercisestrack_progress
/defend/integrations/aisecurity-speed-run
AIPSA Handbook Integration
Tauri desktop app providing offline access to the AI Product Security Assurance (AIPSA) handbook, frameworks, and checklists.
desktoptauribrowse_handbookexport_markdown
/defend/integrations/aipsa-handbook
AIPSA Training — Moodle XML Quiz Integration
Moodle XML quiz import with all 132 AIPSA maturity assessment questions, organized by domain with fractional scoring.
lmsmoodleimport_question_bankfractional_grading
/defend/integrations/moodle
AIPSA Training — SCORM 1.2 Package Integration
SCORM 1.2 package delivering the AIPSA Field Guide and maturity self-assessment to any SCORM-compatible LMS.
lmsscormdeliver_field_guiderun_maturity_assessment
/defend/integrations/lms-scorm
Career Frameworks App Integration
Tauri desktop app for browsing AI security career ladders, competency maps, and role expectations for security engineering orgs.
desktoptauribrowse_frameworksexport_markdown
/defend/integrations/career-frameworks
Enterprise Readiness Security Operations — Discovery
Consulting discovery and intake for enterprise readiness security operations.
consultingdiscoveryenterprise-readiness-security-operationsai security
/consulting/discovery/enterprise-readiness-security-operations
Product Security Architecture — Discovery
Consulting discovery and intake for product security architecture.
consultingdiscoveryproduct-security-architectureai security
/consulting/discovery/product-security-architecture
SecEng Evidence Connector for Burp Suite Integration
Burp Suite extension using the Montoya API to capture HTTP traffic and send findings to the SecEng sidecar.
security_toolburp_suitecapture_trafficreport_finding
/defend/integrations/burp-evidence-connector
SecEng Evidence Connector for Metasploit Integration
Metasploit auxiliary modules for discovering and fingerprinting AI infrastructure and services.
security_toolmetasploitdiscover_servicereport_finding
/defend/integrations/metasploit-evidence-connector
SecEng Evidence Connector for OWASP ZAP Integration
ZAP add-on providing a passive scan rule to detect AI traffic and integrate with the SecEng sidecar.
security_toolowasp_zapcapture_trafficreport_finding
/defend/integrations/zap-evidence-connector
SecEng Program Blueprint for Jira Integration
Jira-targeted SecEng program blueprint exporter with native issue types, epics, components, and story templates.
devopsjiraexport_jsonexport_markdown
/defend/integrations/jira-program-blueprint
SecEng Program CLI Integration
Command-line tool for listing, exporting, and analyzing SecEng program blueprints across all target platforms.
clilist_blueprintsexport_jsonexport_markdown
/defend/integrations/seceng-program-cli
SecEng Program Dashboard Integration
React dashboard for visualizing SecEng program blueprint coverage, progress, and evidence across workstreams.
cliwebview_blueprintstrack_progress
/defend/integrations/seceng-program-dashboard
SecEng Program Importer Integration
CLI tool for importing SecEng program blueprints into project management platforms from JSON export files.
cliimport_jsondry_runexport_json
/defend/integrations/seceng-program-importer
SecEng Trust Scanner Automation Webhook Integration
Generic webhook server and API adapter for routing trust scanner scans from Zapier, Make, n8n, and custom automation pipelines.
ciautomationscan_textscan_file
/defend/integrations/automation-trust-scanner
SecEng Trust Scanner CI Integration
GitHub Actions-compatible CLI and action for scanning repository files, PRs, and docs for trust language risks in CI/CD pipelines.
cigithub_actionsscan_textscan_file
/defend/integrations/trust-scanner-ci
SecEng Trust Scanner for Azure DevOps Integration
Azure DevOps extension scaffold for scanning work items, wiki pages, pull requests, and pipeline evidence.
devopsazure_devopsscan_textscan_selection
/defend/integrations/azure-devops-trust-scanner
SecEng Trust Scanner for Discord Integration
Discord bot and slash commands for scanning community, support, and product-security language.
collaborationdiscordscan_textscan_message
/defend/integrations/discord-trust-scanner
SecEng Trust Scanner for Eclipse Integration
Eclipse plugin scaffold for regulated enterprise teams scanning AI-related source, docs, and policies.
developereclipsescan_textscan_selection
/defend/integrations/eclipse-trust-scanner
SecEng Trust Scanner for Figma Integration
Figma plugin for scanning text layers, frame annotations, component descriptions, and AI-generated copy for trust and governance language.
designfigmascan_textscan_selection
/defend/integrations/figma-trust-scanner
SecEng Trust Scanner for Gmail Integration
Google Apps Script add-on for scanning email drafts, threads, and pasted text for AI security and trust language risks.
productivitygmailscan_textscan_selection
/defend/integrations/gmail-trust-scanner
SecEng Trust Scanner for Google Chat Integration
Google Chat app for scanning pasted messages and AI/security claims from Google Workspace conversations.
collaborationgoogle_chatscan_textscan_message
/defend/integrations/google-chat-trust-scanner
SecEng Trust Scanner for Google Docs Integration
Google Apps Script add-on for scanning Docs content, selected text, and pasted policy or vendor language for trust risks.
productivitygoogle_docsscan_textscan_selection
/defend/integrations/google-docs-trust-scanner
SecEng Trust Scanner for Google Sheets Integration
Google Apps Script add-on for bulk-scanning cell content, vendor responses, AI audit worksheets, and questionnaire answers.
productivitygoogle_sheetsscan_textscan_selection
/defend/integrations/sheets-trust-scanner
SecEng Trust Scanner for HubSpot Integration
CRM card and workflow webhook for scanning sales/security claims and customer-facing AI language.
crmhubspotscan_textscan_record
/defend/integrations/hubspot-trust-scanner
SecEng Trust Scanner for Intercom Integration
Intercom app card and webhook for scanning customer support messages, AI bot replies, and security-related conversation text.
crmintercomscan_textscan_message
/defend/integrations/intercom-trust-scanner
SecEng Trust Scanner for JetBrains Integration
JetBrains plugin scaffold for scanning prompts, policies, markdown, config, and AI security claims in IDE projects.
developerjetbrainsscan_textscan_selection
/defend/integrations/jetbrains-trust-scanner
SecEng Trust Scanner for Mattermost Integration
Mattermost slash command and bot webhook for self-hosted security teams.
collaborationmattermostscan_textscan_message
/defend/integrations/mattermost-trust-scanner
SecEng Trust Scanner for Microsoft Teams Integration
Personal tab, channel tab, bot, and message extension for scanning AI/security language in Teams.
collaborationmicrosoft_teamsscan_textscan_message
/defend/integrations/teams-trust-scanner
SecEng Trust Scanner for Notion Integration
Notion integration for scanning page content, database properties, and pasted vendor or policy text via the Notion API.
productivitynotionscan_textscan_selection
/defend/integrations/notion-trust-scanner
SecEng Trust Scanner for Outlook Integration
Outlook add-in for scanning email drafts, AI-generated replies, vendor communications, and pasted policy text.
productivitymicrosoft_outlookscan_textscan_selection
/defend/integrations/outlook-trust-scanner
SecEng Trust Scanner for Raycast Integration
Raycast extension with paste-and-scan and clipboard commands for scanning trust language anywhere on macOS.
developerraycastscan_textscan_selection
/defend/integrations/raycast-trust-scanner
SecEng Trust Scanner for Salesforce Integration
Salesforce Lightning component and Apex trigger scaffold for scanning opportunity text, account notes, and AI-generated customer communications.
crmsalesforcescan_textscan_record
/defend/integrations/salesforce-trust-scanner
SecEng Trust Scanner for ServiceNow Integration
ServiceNow app scaffold for AI risk, governance, incidents, exceptions, and evidence workflows.
governanceservicenowscan_textscan_record
/defend/integrations/servicenow-trust-scanner
SecEng Trust Scanner for SharePoint Integration
SharePoint Framework (SPFx) web part for scanning document libraries, wiki pages, and SharePoint list content for governance and AI trust risks.
productivitymicrosoft_sharepointscan_textscan_selection
/defend/integrations/sharepoint-trust-scanner
SecEng Trust Scanner for Slack Integration
Slack App Home, shortcut, modal, slash command, and bot response for scanning trust language.
collaborationslackscan_textscan_message
/defend/integrations/slack-trust-scanner
SecEng Trust Scanner for Telegram Integration
Telegram bot webhook for scanning pasted claims, messages, and community support text.
collaborationtelegramscan_textscan_message
/defend/integrations/telegram-trust-scanner
SecEng Trust Scanner for Wix Integration
Wix app for scanning site copy, AI-generated content, privacy pages, and customer-facing trust claims on Wix-hosted properties.
cmswixscan_textscan_selection
/defend/integrations/wix-trust-scanner
SecEng Trust Scanner for Word Integration
Microsoft Word add-in for scanning document content, track-changes text, vendor agreements, and AI-generated policy drafts.
productivitymicrosoft_wordscan_textscan_selection
/defend/integrations/word-trust-scanner
SecEng Trust Scanner for WordPress Integration
WordPress plugin with Gutenberg block for displaying trust scanner summaries on posts, pages, and AI-generated content.
cmswordpressscan_textscan_selection
/defend/integrations/wordpress-trust-scanner
SecEng Trust Scanner for Zendesk Integration
Ticket sidebar app for scanning support replies, security responses, macros, and AI claims.
service_deskzendeskscan_textscan_ticket
/defend/integrations/zendesk-trust-scanner
Trust Scanner Integrations CLI Integration
CLI for listing, inspecting, and exporting the full trust scanner integrations registry to JSON.
clilist_integrationsshow_integrationexport_json
/defend/integrations/trust-scanner-integrations-cli
Discovery
Scope an AI security review.
/consulting/discovery
Adversarial Range Demo
Fixture-driven mockup of the SecEng Adversarial Range dashboard.
/attack/adversarial-range/demoapp/(public)/attack/adversarial-range/demo/page.tsx
Agent Permission Analyzer
Deterministic security analysis of AI agent tool configurations.
/attack/agent-analyzerapp/(public)/attack/agent-analyzer/page.tsx
AI Governance Operating Model | SecEng Governance
Turn AI governance obligations into named owners, controls, evidence, and decisions engineering teams can execute.
/services/governanceapp/(public)/services/governance/page.tsx
AI Security Attestation
Independent technical AI security review producing a structured attestation document.
/evidence/attestationapp/(public)/evidence/attestation/page.tsx
AI Security Scorecard — Self-Service Baseline, Roadmap…
Baseline your AI security program across 14 domains.
/evidence/scorecardapp/(public)/evidence/scorecard/page.tsx
AIPSA Labs — Hands-On AI Security Scenario Tracks
Red team, blue team, RAG security, agentic, governance, and product security lab tracks.
/evidence/labsapp/(public)/evidence/labs/page.tsx
Atlassian Threat Canvas
Turn AI and product architecture into structured threat models, Jira-ready remediation, and Confluence-ready security design evidence.
/map/atlassian-threat-canvasapp/(public)/map/atlassian-threat-canvas/page.tsx
Attack Path Chaining (APC)
Build validated attack clusters from grounded evidence, then challenge the chain independently before it becomes a defended claim.
/attack/attack-path-chainingapp/(public)/attack/attack-path-chaining/page.tsx
Attack Services
Adversarial AI security services across the MADE Attack lifecycle — red teaming, prompt injection, RAG abuse, agent authority validation, jailbreaks
/services/attackapp/(public)/services/attack/page.tsx
Authority Graph Demo
Fixture-driven mockup of the SecEng Authority Graph dashboard and workflow-analysis bundle.
/attack/authority-graph/demoapp/(public)/attack/authority-graph/demo/page.tsx
Blue Team
/services/blue-teamapp/(public)/services/blue-team/page.tsx
Consulting
/consultingapp/(public)/consulting/page.tsx
Defend Services
Defend AI systems with agent hardening, guardrails, evals, secure SDLC, release gates, logging, rollback, and implementation support.
/services/defendapp/(public)/services/defend/page.tsx
Evidence Graph — Grounded Attack Paths
SecEng Evidence Graph: normalize evidence from savvy-cli, simstudio, and the Adversarial Range into one system/authority graph, discover grounded attack paths…
/attack/authority-graph/evidence-pathsapp/(public)/attack/authority-graph/evidence-paths/page.tsx
Evidence Graph — Real Tool Formats
Grounded attack paths assembled from the actual serialized outputs of savvy-cli, simstudio-whitelabel, and llm-attack-range, joined by cross-tool entity…
/attack/authority-graph/evidence-paths/realapp/(public)/attack/authority-graph/evidence-paths/real/page.tsx
Evidence Services
AI security evidence services across the MADE Evidence lifecycle — decision-ready artifacts, framework crosswalks, control registers
/services/evidenceapp/(public)/services/evidence/page.tsx
Injection Harness
A library of prompt injection attack probes across multiple categories.
/attack/injection-harnessapp/(public)/attack/injection-harness/page.tsx
Map Services
Map AI surfaces, trust boundaries, threat models, maturity, control gaps, and program risk before attack, defense, or evidence work.
/services/mapapp/(public)/services/map/page.tsx
Model Gateway
Route AI work through local CLIs, hosted APIs, and policy-controlled execution paths with evidence capture.
/defend/model-gatewayapp/(public)/defend/model-gateway/page.tsx
Output Safety Tester
Test AI model output for unsafe rendering, injection, link safety, and side-effect risks.
/defend/output-safetyapp/(public)/defend/output-safety/page.tsx
Pen Test & Red Team Readiness Packet
Prepare classic pentests, cloud reviews, and adversarial red team engagements with the scope, authorization, ROE, access plan, evidence handling
/services/pen-test-red-team-readinessapp/(public)/services/pen-test-red-team-readiness/page.tsx
Prompt Reviewer
Deterministic prompt security review and KB/corpus risk scanner.
/attack/prompt-reviewerapp/(public)/attack/prompt-reviewer/page.tsx
Red Team
/services/red-teamapp/(public)/services/red-team/page.tsx
Runtime Proxy Demo
Fixture-driven mockup of the SecEng Runtime Proxy, repository concept, and boundary lens.
/defend/runtime-proxy/demoapp/(public)/defend/runtime-proxy/demo/page.tsx
Sample Report — Acme Assistant Platform SecEng Scorecard
A realistic sample SecEng Scorecard for a B2B SaaS platform using RAG, agents, and enterprise customer data.
/evidence/scorecard/demoapp/(public)/evidence/scorecard/demo/page.tsx
Scorecard Assessment
/evidence/scorecard/assessapp/(public)/evidence/scorecard/assess/page.tsx
SecEng Adversarial Range — AI Red-Team Scenario Harness
Scenario-driven adversarial testing for AI systems — prompt injection, agent abuse, RAG leakage, jailbreaks, tool misuse, and multimodal attack surfaces. Feed…
/attack/adversarial-rangeapp/(public)/attack/adversarial-range/page.tsx
SecEng AI Config Linter | AI Runtime Configuration Security
Scan .env, Docker Compose, Kubernetes, GitHub Actions, and platform configs for AI-specific unsafe defaults, exposed model endpoints
/defend/ai-config-linterapp/(public)/defend/ai-config-linter/page.tsx
SecEng Artifact Analyzer — Authority Signals & Evidence…
Analyze Rust, Go, browser, MCP, and agent artifacts for authority signals, capability exposure, and evidence-quality review outputs.
/attack/artifact-analyzerapp/(public)/attack/artifact-analyzer/page.tsx
SecEng Authority Graph — Agent Authority & Approval-Path…
Discover dangerous authority compositions, then feed them into APC as evidence for multi-step attack-chain analysis.
/attack/authority-graphapp/(public)/attack/authority-graph/page.tsx
SecEng Code Scanner | AI-Native Static Analysis
AI-native static analysis for LLM applications, RAG, agents, MCP, and AI-specific code paths. Available direct and through OEM licensing.
/attack/code-scannerapp/(public)/attack/code-scanner/page.tsx
SecEng Code Scanner Demo
Fixture-driven preview of the SecEng Code Scanner team experience, including attack paths, exports, and validation planning.
/attack/code-scanner/demoapp/(public)/attack/code-scanner/demo/page.tsx
SecEng Evidence Packs — Buyer-Ready AI Security Artifacts
Evidence Packs turn scoped AI security findings, controls, caveats, and retest notes into buyer-ready artifacts for customer review, procurement
/evidence/evidence-packsapp/(public)/evidence/evidence-packs/page.tsx
SecEng Evidence Scorecard Results
/evidence/scorecard/resultsapp/(public)/evidence/scorecard/results/page.tsx
SecEng Model Gateway Demo
Fixture-driven preview of the SecEng Model Gateway policy-routing experience and evidence trail.
/defend/model-gateway/demoapp/(public)/defend/model-gateway/demo/page.tsx
SecEng Program Blueprint Kit
Your complete AI security program — 7 blueprints, 42 tasks, 113 evidence requirements
/defend/blueprintapp/(public)/defend/blueprint/page.tsx
SecEng RAG Demo
Fixture-driven mockup of the SecEng RAG Test Harness.
/attack/rag/demoapp/(public)/attack/rag/demo/page.tsx
SecEng RAG Test Harness — Retrieval & Context Security
Validate retrieval authorization, detect cross-tenant leaks, poisoned content, and indirect prompt injection before they reach the model.
/attack/ragapp/(public)/attack/rag/page.tsx
SecEng Runtime Proxy — MITM Capture, Replay & Runtime…
Capture, replay, and reconstruct AI interactions into audit-ready evidence.
/defend/runtime-proxyapp/(public)/defend/runtime-proxy/page.tsx
SecEng Threat Canvas — AI Threat Modeling & Trust-Boundary…
DFD-style AI threat modeling with trust-boundary mapping, abuse-path planning, and Jira/Confluence export.
/map/threat-canvasapp/(public)/map/threat-canvas/page.tsx
SecEng Trust Scanner — Public AI Trust Signal Scoring
Score every public AI trust signal across six dimensions — legal clarity, governance evidence, security trust, and more.
/map/trust-scannerapp/(public)/map/trust-scanner/page.tsx
Start SecEng Evidence Scorecard
Choose your assessment package and begin the scorecard.
/evidence/scorecard/startapp/(public)/evidence/scorecard/start/page.tsx
Surface Scanner
Discover and inventory AI providers, SDKs, agent frameworks, tools, copilots, and shadow AI signals across snapshots and scans.
/map/surface-scannerapp/(public)/map/surface-scanner/page.tsx
Threat Canvas Demo
Live demo of the SecEng Threat Canvas: DFD canvas, STRIDE risk register, controls, Jira export, and Confluence evidence for an AI Work Item Copilot system.
/map/threat-canvas/demoapp/(public)/map/threat-canvas/demo/page.tsx
Trust Scanner Demo
Live demo of the SecEng Trust Scanner: six-dimension ATG scorecard, artifact presence checklist, and improvement guidance
/map/trust-scanner/demoapp/(public)/map/trust-scanner/demo/page.tsx

Solutions

10 pages

End-to-end AI security program briefs

Solutions
Pain-led routes for AI code risk, shadow AI, SDLC gaps, deal blockers, agent blast radius, RAG leakage, and governance buildouts.
/solutions
Agent Blast Radius Is Unknown
Agents can read, write, browse, call tools, trigger workflows, and move data.
Agentic Workflow Security & HardeningCTOCISO
/solutions/agent-blast-radius-is-unknown
AI Bugs Hide in New Paths
Traditional scanners miss prompt injection, unsafe output handling, retrieval abuse, model misuse, and agent tool paths.
AI Red Team & Adversarial TestingProduct SecurityRed Team
/solutions/ai-bugs-hide-in-new-paths
AI Code Risk Is Spreading
Developers are generating code faster than security can review it.
AI Product Security AssessmentCISOProduct Security
/solutions/ai-code-risk-is-spreading
AI Sales Needs Proof
Sales engineers need sharper AI security language, evidence, and objection handling.
AI Security Sales EnablementSales EngineeringCustomer Success
/solutions/ai-sales-needs-proof
AI SDLC Is Missing
Normal AppSec does not cover prompts, RAG, agents, evals, model behavior, or AI release gates.
AI Governance & Security Program BuildCISOCTO
/solutions/ai-sdlc-is-missing
AI Security Roles Are Undefined
Teams know they need AI security, but they cannot define the work, roles, skills, or hiring profile.
AI Governance & Security Program BuildCISOCTO
/solutions/ai-security-roles-are-undefined
Enterprise Deal Is Blocked
A buyer, procurement team, or security reviewer is asking AI security questions the team cannot answer cleanly.
AI Security Sales EnablementSales EngineeringCustomer Trust
/solutions/enterprise-deal-is-blocked
RAG Access Can Leak
Retrieval can expose the wrong chunks, wrong tenants, poisoned context, stale sources, or sensitive data.
AI Product Security AssessmentProduct SecurityAppSec
/solutions/rag-access-can-leak
Shadow AI Has No Owner
AI tools, extensions, copilots, CLIs, and workflows are spreading without visibility.
AI Security Maturity BenchmarkCISOSecurity Program Lead
/solutions/shadow-ai-has-no-owner

Academy

314 pages

Courses, labs, journal, and certification

AI Security Academy Courses
Role-based AI security training, private cohorts, print editions, and enterprise delivery.
/academy/courses
AI Model Gateways and Secure Platforms
A technical enterprise course for platform, DevOps, SRE, cloud security, AI infrastructure, and security architecture teams building model gateways, provider…
/academy/courses/model-gateways-and-secure-ai-platform-engineering
AI Product Management for Secure AI Features
A role-based enterprise course for product managers, PMO leaders, technical program managers, founders, and AI product leads who need to turn AI risk into…
/academy/courses/ai-product-management-for-secure-ai-features
AI Red Teaming for Product Teams
A defensive enterprise course for QA, DevOps, SecOps, product security, and AI platform teams that need repeatable AI abuse-case testing, evidence capture…
/academy/courses/ai-red-teaming-for-product-teams
AI Security for Sales Engineers
A role-based enterprise course for sales engineers, solutions consultants, account executives, founders, customer success teams, and product marketers who…
/academy/courses/ai-security-for-sales-engineers
Hiring AI-Savvy Talent Without Unicorn Hunting
A practical course for recruiters, hiring managers, and talent leaders who need to define AI-era roles, separate real must-haves from team capability gaps…
/academy/courses/hiring-ai-savvy-talent-without-unicorn-hunting
Secure Coding with GenAI
A hands-on enterprise course for developers, AppSec teams, and platform engineers learning how to use AI coding tools safely through secure prompts, shared…
/academy/courses/secure-coding-with-genai
AI Security Engineer — Career Dossier
Secures AI-enabled applications, RAG systems, agents, model supply chains, eval pipelines, and governance evidence loops.
AI Securitycross cuttingai securitycareer
/academy/reference/career-explorer/roles/ai-security-engineer
Job Navigator
Assess your career against the live AI security job market with role intelligence, hiring signals, and job description analysis.
/academy/job-navigator
'Unleashing Potential and Passion: The Impact of Aligned…
Ever wondered why some people seem effortlessly drawn towards their work, invigorated by their day-to-day tasks, while others struggle to...
/academy/journal/unleashing-potential-and-passion-the-impact-of-aligned-work-interests
'Unleashing Sales Potential: Tailored Workshops for Sales…
By incorporating scientific research and advanced technologies, tailored workshops represent the future of sales team development.
/academy/journal/unleashing-sales-potential-tailored-workshops-for-sales-teams
'Values-Driven Culture: The Interplay of Personal and…
In an ever-evolving world, an organization's ability to scale and adapt hinges on the alignment of personal values within its teams....
/academy/journal/values-driven-culture-the-interplay-of-personal-and-enterprise-values
'Worker Engagement: The 8.8 Trillion-Dollar Problem'
The High Cost of Low Engagement Welcome to our exploration of one of the most pressing issues in the contemporary workspace: worker...
/academy/journal/worker-engagement-the-88-trillion-dollar-problem
10 Benefits of Engaging in Meaningful Work
Meaningful work is a critical driver of professional longevity and psychological well-being. This article outlines the systemic benefits of aligning…
/academy/journal/10-benefits-of-having-meaningful-work
10 Reasons Cybersecurity Recruiting Is Challenging
Cybersecurity recruiting is complex due to misaligned role definitions and evolving skill requirements. This article analyzes common recruitment hurdles…
/academy/journal/10-reasons-cyber-security-recruiting-is-so-hard
AI Data Governance for Security Engineers: Classifying…
AI data governance must classify prompts, outputs, embeddings, and training data. Security engineers need rules for provider use, retention, access, and…
/academy/journal/ai-data-governance-prompts-outputs-embeddings-training-data
AI Evals as Security Tests: Building Regression Suites for…
Security evals should test prompt injection, indirect injection, data leakage, RAG access, unsafe output, excessive agency, over-reliance, and cost abuse.…
/academy/journal/ai-evals-as-security-tests-regression-suites
AI Logging and Telemetry: What to Capture Without Creating…
AI systems need logs because you cannot rebuild what happened from vibes. Security teams need to know what prompt was used, what docs were found, what the…
/academy/journal/ai-logging-telemetry-capture-without-privacy-disaster
ATS Systems Overview
An Applicant Tracking System (ATS) is a sophisticated software application designed to manage the full recruitment and hiring process, acting as a critical…
/academy/journal/ats-systems-overview
Beyond Instincts: The Science of Entrepreneurial Success
Entrepreneurial success requires more than intuition; it demands a structured, science-based approach to assessing fit and organizational culture through an…
/academy/journal/beyond-instincts-the-science-of-entrepreneurial-success
Building a Dream Team: Psychometrics in Startup Assembly
Effective startup team assembly requires structured psychometric assessment to ensure role-fit and cultural alignment. This article examines the application…
/academy/journal/building-a-dream-team-how-to-use-psychometrics-to-assemble-your-startup-squad
Building an AI Red Team Lab: Tools, Datasets, Harnesses…
An AI red team lab should provide a controlled, authorized, reproducible environment for testing LLM applications, RAG systems, AI agents, model endpoints…
/academy/journal/building-an-ai-red-team-lab-tools-datasets-harnesses-reporting
Claim-Readiness for AI Security: Marketing Pages, Trust…
Claim-readiness means AI security, privacy, governance, benchmark, sponsorship, and trust-center claims are mapped to reviewable evidence, scoped carefully…
/academy/journal/claim-readiness-for-ai-security-marketing-trust-pages-and-sales-claims
Cloud Security for AI Workloads: GPUs, Secrets, Buckets…
Cloud security for AI workloads requires inventorying AI assets, protecting model endpoints, securing GPU and notebook environments, managing secrets, locking…
/academy/journal/cloud-security-for-ai-workloads-gpus-secrets-buckets-model-endpoints
Cognitive Architecture and Talent Engineering: Leveraging…
An architectural analysis of cognitive processing models in the enterprise, exploring how cognitive diversity enhances adversarial resilience and…
/academy/journal/the-power-of-cognitive-styles-in-job-selection-and-career-success
Compliance for AI Security Engineers: Mapping OWASP, NIST…
AI security compliance should translate frameworks into concrete engineering controls and governance evidence. OWASP helps with LLM application risks, NIST AI…
/academy/journal/compliance-for-ai-security-engineers-owasp-nist-iso-soc2-csa
Conscientiousness vs. Openness: Career and Workplace Impacts
A comparative analysis of conscientiousness and openness to experience, and their distinct roles in career progression and organizational adaptability.
/academy/journal/conscientiousness-vs-openness-career-and-workplace-impacts
Conscientiousness, IQ, and Workplace Performance
An analysis of the correlation between conscientiousness, cognitive ability (IQ), and professional performance within modern organizational structures.
/academy/journal/conscientiousness-iq-and-success-in-the-workplace
De-Risking Recruitment: A Strategic Approach for Scale-Ups
Rapid scaling introduces significant recruitment risks. This article outlines a data-driven approach to de-risking talent acquisition through standardized…
/academy/journal/de-risking-recruitment-a-strategic-approach-for-fast-growing-scale-ups
Enhancing Team Dynamics with Science and AI
Transforming team dynamics requires a purpose-driven approach. This article explores how advanced psychometrics and AI insights can cultivate high-performance…
/academy/journal/create-great-places-to-work-with-science-and-ai
From Jailbreaks to Business Impact: How to Write AI…
AI security findings should connect tested behavior to business impact through scope, preconditions, evidence, reproducibility, affected assets, control…
/academy/journal/from-jailbreaks-to-business-impact-writing-ai-security-findings
Future Trends in Recruitment: The Intersection of People…
The recruitment landscape is evolving toward data-driven, technology-integrated models. This article explores how people, process, and technology converge in…
/academy/journal/future-trends-in-recruiting-the-intersection-of-people-process-and-technology
Harnessing Ethical Alignment: Moral Foundations in Life…
Ethical alignment is fundamental to organizational culture and professional success. This article explores moral foundations and their role in creating…
/academy/journal/harnessing-ethical-alignment-moral-foundations-in-life-and-work
Harnessing the Power of Cybersecurity Certifications: A…
In the contemporary landscape of systemic digital risk, cybersecurity certifications serve as more than personal milestones; they are critical artifacts of…
/academy/journal/harnessing-the-power-of-cybersecurity-certifications-a-guide-for-professionals-at-all-levels
Harnessing the Power of Whole-Brain Thinking for Workplace…
Cognitive diversity is not merely a cultural ideal but a functional requirement for managing the complexity of stochastic systems and ensuring organizational…
/academy/journal/harnessing-the-power-of-whole-brain-thinking-for-workplace-innovation
How AI is Revolutionizing Career Matching: A Focus on…
AI-driven talent intelligence is transforming the recruitment landscape by bridging the skills validation gap and decoding the complex role-language evidence…
/academy/journal/how-ai-is-revolutionizing-career-matching-a-focus-on-cybersecurity-data-science-and-technology
How Thinking Styles Matter at Work: Cognitive Archetypes…
Understanding the interplay of cognitive archetypes is essential for building resilient security teams capable of governing the non-linear risks of the AI era.
/academy/journal/how-thinking-styles-matter-at-work
How to Read the State of AI Security Engineering Report…
A serious annual report is not only a collection of findings. It is also a contract with the reader about how those findings should be interpreted. The more…
/academy/journal/state-of-ai-security-engineering-annual-report-methodology
Human-in-the-Loop Is Not a Security Control Unless You…
Human-in-the-loop is only a security control when the approval is timely, informed, auditable, placed before meaningful action, and backed by authority to…
/academy/journal/human-in-the-loop-is-not-a-security-control-unless-designed
In Search of the 'Soft Skill': Defining Behavioral Control…
Soft skills are not 'fluff'; they are the critical behavioral artifacts of organizational resilience and the primary mechanisms for bridging the…
/academy/journal/in-search-of-the-soft-skill-beyond-the-technical-defining-the-vague
Job Satisfaction: Personal Development and Meaningful Work…
An analysis of the multifaceted constructs of job satisfaction within the context of high-stakes AI Security Engineering and organizational resilience.
/academy/journal/job-satisfaction-personal-development-and-meaningful-work-outweigh-salary-and-leadership
Job Search Motivations: The Pursuit of Purpose Over…
An examination of shifting job search motivations among Millennials and Gen Z, and the strategic imperative for organizations to align role purpose with the…
/academy/journal/job-search-motivations-the-pursuit-of-purpose-over-paycheck
Least Privilege for AI Agents: Designing Permissions for…
AI agents need least privilege at the tool, API, browser, filesystem, credential, tenant, and action level. Safe design requires tool classification…
/academy/journal/least-privilege-for-ai-agents-tools-apis-browsers-filesystems
Leveraging Purpose-Driven AI for High-Growth SaaS…
How high-growth SaaS organizations can utilize advanced AI to align talent with mission-critical security and governance objectives in a non-deterministic…
/academy/journal/leveraging-purpose-driven-ai-for-high-growth-saas-recruitment
LLMOps Security: CI/CD, Secrets, Eval Gates, Model…
LLMOps security requires CI/CD controls for prompts, tools, model configuration, provider routing, evals, secrets, registries, deployment promotion…
/academy/journal/llmops-security-cicd-secrets-eval-gates-model-registry
Mastering Emotional Intelligence: The Unseen Force in…
Emotional intelligence (EI) is a critical determinant of career success. This article explores the Law and Wong model and strategies for cultivating EI in…
/academy/journal/mastering-emotional-intelligence-the-unseen-force-in-career-success
Mastering Psychometric Workshops: A Strategic Framework…
Leveraging psychometric science and AI-driven insights to build resilient, secure-by-design startup teams capable of governing stochastic systems.
/academy/journal/mastering-psychometric-workshops-a-guide-for-accelerators-and-incubators
Meaningful Work in the Age of AI: The Engine of…
In the rapidly evolving domain of AI Security Engineering, meaningful work is not a luxury—it is a functional prerequisite for the vigilance and adversarial…
/academy/journal/the-importance-of-meaningful-work-a-key-to-job-satisfaction
Measuring Entrepreneurship with the A-SAILORS Framework…
A comprehensive analysis of the A-SAILORS anagram as a metaphor for entrepreneurial resilience and the strategic imperative of control evidence in…
/academy/journal/measuring-entrepreneurship-with-the-a-sailors-anagram
Navigating the Recruitment Maze: Reaching Qualified Talent…
In the increasingly stochastic landscape of high-growth SaaS and cybersecurity, the ability to reach validated talent and survive the competition is a matter…
/academy/journal/navigating-the-recruitment-maze-reaching-qualified-talent-and-winning-the-competition
Neuroticism in the Workplace and Entrepreneurship
A deep dive into the stochastic nature of emotional stability, exploring how neuroticism acts as a critical variable in organizational resilience and…
/academy/journal/neuroticism-in-the-workplace-and-entrepreneurship
New Hire Orientation: Setting the Stage for Long-Term…
In the era of autonomous systems, onboarding is no longer just administrative; it is a critical alignment of the human stochastic engine with the…
/academy/journal/new-hire-orientation-setting-the-stage-for-long-term-success
Notebook Security for ML and AI Teams: Jupyter, Colab…
Notebook security for AI and ML teams requires access control, secret management, data minimization, execution isolation, output review, dependency scanning…
/academy/journal/notebook-security-jupyter-colab-databricks-hidden-execution-risk
Outsourced vs. Internal Recruiters: Who Wins in Tech and…
An architectural analysis of recruitment models in high-stakes technical domains, comparing vertical integration with distributed talent intelligence.
/academy/journal/outsourced-vs-internal-recruiters-who-wins-in-tech-and-cyber
Private Benchmarks for AI Security: Skills, Operating…
Private AI security benchmarks can help organizations compare skills, operating models, control coverage, evidence maturity, and role expectations against…
/academy/journal/private-benchmarks-for-ai-security-skills-operating-models-and-controls
Project Manager vs. Product Manager: Navigating the…
In high-stakes AI and security engineering environments, the distinction between Project and Product management is not merely semantic—it is a critical…
/academy/journal/project-manager-vs-product-manager-whats-the-difference
Psychological Safety as a Control Signal: Happiness as…
An analysis of psychological safety and professional engagement as high-fidelity telemetry points for organizational resilience and the governance of…
/academy/journal/psychological-safety-as-a-control-signal
Psychometric Role-Language Evidence Is Not Diagnosis…
Psychometric role-language analysis can help interpret AI security job descriptions, role expectations, team archetypes, and skills demand when used as…
/academy/journal/psychometric-role-language-evidence-not-diagnosis
Public Hiring Signals: How AI Security Job Descriptions…
Public AI security job descriptions can reveal directional market demand, role architecture, skills convergence, framework adoption, and emerging operating…
/academy/journal/public-hiring-signals-ai-security-job-descriptions-market-intelligence
Purpose as a Catalyst for Organizational Resilience…
In the high-stakes domain of AI Security Engineering, purpose-driven alignment is not a luxury—it is a foundational component of a secure-by-design culture.
/academy/journal/purpose-means-more-than-salary
RAG Data Leakage: How Private Documents Escape Through…
RAG data leakage happens when retrieval, embeddings, metadata, prompt context, generated answers, logs, or deletion workflows expose information outside…
/academy/journal/rag-data-leakage-private-documents-retrieval-embeddings-context
Recruiting and Retention Strategy: Person-Fit, Role-Fit…
In the modern AI Security landscape, the concept of 'fit' has evolved from a HR metric to a critical organizational control. Understanding the nuances of…
/academy/journal/recruiting-and-retention-strategy-person-fit-role-fit-and-job-fit
Remote Work as the New Normal: Leveraging Psychometrics…
In the decentralized era of AI Security Engineering, the home office has become a critical node in the organizational resilience network. Leveraging…
/academy/journal/remote-work-as-the-new-normal-leveraging-psychometrics-for-success
Resilience in Stochastic Operations: The Future of…
An analysis of decentralized governance, AI-human coordination, and the engineering of organizational resilience in the post-geographic AI Security…
/academy/journal/resilience-in-stochastic-operations
Role Architecture and the Big Five: Calibrating…
In the high-stakes domain of AI Security Engineering, personality is more than a preference—it is a critical calibration tool for orchestrating human…
/academy/journal/the-importance-of-personality-in-career-matching
Scaling Up Fast? Beware of Governance Debt in the Tech…
In the race to dominate the AI landscape, 'hustle' is often prioritized over 'control.' However, rushing the recruitment process for critical AI Security…
/academy/journal/scaling-up-fast-beware-of-too-much-hustle-in-the-tech-recruiting-process
Secrets Management for AI Apps: API Keys, Model Providers…
AI applications need disciplined secrets management across model provider keys, vector stores, tool credentials, OAuth tokens, browser sessions, cloud keys…
/academy/journal/secrets-management-for-ai-apps-api-keys-tool-credentials-delegated-access
Secure AI Product Design: How Product Decisions Create or…
AI product decisions can create or reduce security risk by controlling autonomy, data visibility, uncertainty, approval design, reversibility, source…
/academy/journal/secure-ai-product-design-product-decisions-create-reduce-risk
Securing Open-Source Models: What to Check Before Running…
Open-source models require a production intake process covering provenance, license review, file formats, remote code, unsafe serialization, dependencies…
/academy/journal/securing-open-source-models-production-checklist
Security Monitoring for AI Agents: How to Detect Dangerous…
Security monitoring for AI agents requires tool-call telemetry, action-sequence detection, approval-state tracking, memory monitoring, credential visibility…
/academy/journal/security-monitoring-for-ai-agents-dangerous-tool-use
Skills Get the Job, but Character Keeps It: Proactive…
In the high-stakes domain of AI Security Engineering, technical proficiency is a baseline requirement, but proactive personality traits are the true drivers…
/academy/journal/skills-get-the-job-but-character-keeps-it-about-proactive-personality-in-the-workplace
Training
AI security training, skill tests, and certification-ready exercises.
/training
The Agentic Anarchy Problem: Why AI Agents Break…
AI agents break traditional IAM because they act across user intent, application authority, and tool permissions. A secure agent program requires explicit…
/academy/journal/agentic-anarchy-why-ai-agents-break-traditional-iam
The Agreeableness Paradox in AI Security: Balancing…
In the evolving landscape of AI Security Engineering, the personality trait of agreeableness presents a complex paradox—essential for team cohesion yet…
/academy/journal/the-impact-of-agreeableness-in-the-workplace
The AI Security Buyer’s Guide: How to Evaluate Vendors for…
AI security buyers should judge vendors by the job to be done: filtering, testing, evals, access, logs, leaks, rules, and proof. Choosing a vendor should…
/academy/journal/ai-security-buyers-guide-llm-firewalls-guardrails-evals-monitoring
The AI Security Engineer Career Map: Skills, Tools…
The AI Security Engineer career path combines AppSec, cloud security, MLOps, LLM application security, secure RAG, agent security, red teaming, detection…
/academy/journal/ai-security-engineer-career-map-skills-tools-frameworks
The AI Security Operating Model: Who Owns What Across…
A credible AI security operating model assigns ownership across AppSec, product security, AI platform engineering, MLOps, data governance, privacy, legal…
/academy/journal/ai-security-operating-model-who-owns-what
The Art of Nurturing Talent: Why Overqualification Risks…
In the pursuit of top-tier talent for AI Security Engineering, over-hiring for seniority can inadvertently lead to the 'Unicorn Index' trap, increasing…
/academy/journal/the-art-of-nurturing-talent-why-overqualification-leads-to-employee-turnover
The Career Impact of Extraversion and Introversion: A Deep…
In the evolving landscape of AI Security Engineering, the interplay between extraversion and introversion defines the efficacy of risk communication and the…
/academy/journal/the-career-impact-of-extraversion-and-introversion-a-deep-dive
The Dawn of a New Era: Distributed Governance in the Age…
The transition to hybrid work models is more than an operational shift; it is a fundamental reconfiguration of the security perimeter and the governance of…
/academy/journal/the-dawn-of-a-new-era-navigating-the-future-of-hybrid-work
The Demand for AI Security Engineering: Bridging the…
As the digital landscape transitions toward the governance of stochastic systems, the cybersecurity talent shortage is evolving into a critical 'Skills…
/academy/journal/the-demand-for-cybersecurity-skills-and-talent-shortage-the-role-of-ai-and-data-science
The Empathetic Leader: Overcoming Output-Bias in…
A critical analysis of leadership promotion models, arguing for a transition from meritocratic output-fixation to empathy-centric governance to ensure…
/academy/journal/the-empathetic-leader-challenging-the-notion-of-promotion-based-on-hard-work
The Entropy of Talent Acquisition: Addressing Systemic…
An architectural analysis of the structural inefficiencies, information asymmetries, and algorithmic biases inherent in contemporary hiring processes…
/academy/journal/the-problems-with-job-search-and-recruiting-today
The Evolution of Hiring Marketplaces: From Lead Gen to…
An analysis of the structural shift in talent acquisition through the lens of hiring marketplaces like Vettery, Hired, and Wellfound, emphasizing the move…
/academy/journal/the-evolution-of-hiring-marketplaces-spotlight-on-vettery-hired-and-wellfound
The Future of AI Security Engineering: From AppSec to…
The future of AI Security Engineering is a platform discipline that extends AppSec into LLM applications, creates AgentSec for autonomous workflows, builds…
/academy/journal/future-of-ai-security-engineering-appsec-agentsec-autonomous-socs
The Future of Corporate Retreats: A Psychometric Approach
Corporate retreats are strategic interventions for aligning team performance. This article outlines how to leverage psychometrics to ensure retreat activities…
/academy/journal/harnessing-psychometrics-in-the-future-of-corporate-retreats
The Future of Jobs 2023: Navigating the Skills Revolution…
An executive deep-dive into the World Economic Forum's 2023 report, analyzing the structural displacement of labor, the rise of the augmented worker, and the…
/academy/journal/the-future-of-jobs-an-in-depth-analysis-of-the-world-economic-forums-2023-report
The Future of Team Building: Integrating AI and…
A deep-dive into the convergence of AI-driven analytics and psychometric science, exploring how data-rich team building optimizes organizational resilience…
/academy/journal/the-future-of-team-building-integrating-ai-and-psychometrics
The Governance of Technical Talent: Architecture, Purpose…
An architectural analysis of the NICE Framework as a foundation for cybersecurity workforce development, exploring its evolution into the domain of AI…
/academy/journal/the-purpose-driven-cybersecurity-career-the-nice-framework
The Passive Reservoir: Architectural Advantages of…
An analysis of recruitment telemetry and the strategic role of outsourced partners in navigating the passive talent market for high-stakes technical roles.
/academy/journal/the-power-of-passive-why-outsourced-recruiters-excel-in-engaging-passive-candidates-in-tech
The Science of Evidence-Based Career Matching
Effective career matching requires the integration of cognitive, behavioral, and moral telemetry. This article details our evidence-based approach to…
/academy/journal/the-science-behind-career-matching-at-hirepurposeai
The Security Architect’s Toolchain: Evaluating…
A technical overview of the AI Security Engineer's toolchain, focused on language-level security, the governance of stochastic systems, and the generation of…
/academy/journal/the-security-architects-toolchain
The Theories of Personality, Cognition, Interests, and…
Personality Personality is a complex pattern of traits, including thoughts, emotions, and behaviors, that shape individuals' unique ways...
/academy/journal/the-theories-of-personality-cognition-interests-and-morality
Threat Modeling LLM Applications: Data Flows, Trust…
LLM threat modeling should map assets, actors, data flows, trust boundaries, prompt assembly, retrieved content, model providers, tool calls, memory, outputs…
/academy/journal/threat-modeling-llm-applications-data-flows-trust-boundaries-tools
Thriving in the Era of Continuous Learning and Upskilling
Stay Ahead or Get Left Behind: Embracing Continuous Growth In the modern world, the pace of change is accelerating, driven by...
/academy/journal/thriving-in-the-era-of-continuous-learning-and-upskilling
Top 10 Corporate Values Identified from 8000 Company HR…
The world of business is as diverse as it is complex, filled with a myriad of companies, each possessing a unique set of values,...
/academy/journal/top-10-corporate-values-identified-from-8000-company-hr-portals
Top 10 Reasons Why a Career in Cyber Security is Worth…
Cybersecurity is one of the most in-demand fields in today's digital age. With the increasing reliance on technology and the internet,...
/academy/journal/top-10-reasons-why-a-career-in-cyber-security-is-worth-pursuing
Understanding Your Work Interests for a Fulfilling Career
The Importance of Aligning Interests with Career Choices Choosing a career path is a significant decision that can influence your overall...
/academy/journal/understanding-your-work-interests-for-a-fulfilling-career
Unlock the Power of Personality for Professional Success
Welcome to the intricate world of human behavior, a subject that has captivated the attention of philosophers, scientists, and everyday...
/academy/journal/unlock-the-power-of-personality-for-professional-success
Unmasking the Power of Evaluation, Assessment, and…
In the complex world of human resources, candidate assessment and pre-hire screening have become essential tools for organizations...
/academy/journal/unmasking-the-power-of-evaluation-assessment-and-screening-in-the-modern-workplace
Values Alignment in AI Security Engineering: Bridging…
In the high-stakes domain of AI Security Engineering, the alignment of personal and corporate values serves as the ultimate control mechanism for managing the…
/academy/journal/the-importance-of-aligning-personal-and-company-values
Vector Database Security: Access Control, Tenant…
Vector database security requires the same seriousness as other production data infrastructure, with additional attention to embeddings, metadata filtering…
/academy/journal/vector-database-security-access-control-tenant-isolation-poisoning-logging
Why Company Morals Matter
Moral Foundations Theory (MFT) is a psychological framework that examines how individuals' moral values guide their judgments, behaviors,...
/academy/journal/why-company-morals-matter
Why External Recruiters Should Integrate with ATS
Direct ATS integration for external recruiters is essential for operational security and talent supply chain integrity. This article details the systemic…
/academy/journal/5-reasons-why-external-recruiters-should-send-leads-directly-to-your-ats
Why Outsource? You gotta know. Cybersecurity and Data…
In the rapidly evolving tech landscape, companies are increasingly recognizing the importance of specialized roles such as cybersecurity...
/academy/journal/why-outsource-you-gotta-know-cybersecurity-and-data-science-niche-roles
AI Governance and vCISO Readiness Diagnostic
A leadership-oriented diagnostic for security leaders, vCISOs, advisors, consultants, and GRC teams translating AI risk into controls, policy, evidence, and…
/training/ai-governance-vciso-readiness
AI Security Engineering Practice Exam
A practice version of the readiness assessment intended for repeat attempts, self-study, and training cohorts. The practice exam emphasizes explanations and…
/training/ai-security-engineering-practice-exam
AI Security Engineering Readiness Assessment
A rigorous, standards-aligned, learning-first assessment covering LLM application security, prompt injection, RAG security, agent security, model supply…
/training/ai-security-engineering-readiness
LLM Application Security Specialist Diagnostic
A focused diagnostic for practitioners building or securing LLM-powered applications, RAG systems, and agentic workflows.
/training/llm-application-security-specialist
AI Governance Lead — Career Dossier
Builds AI governance operating models, evidence programs, policy, risk processes, and accountability mechanisms.
AI Governancecross cuttingai securitycareer
/academy/reference/career-explorer/roles/ai-governance-lead
Ai Impact — Journal
AI security journal articles in the Ai Impact category.
Ai Impactai securityjournal
/academy/journal/category/ai-impact
Ai Integration — Journal
AI security journal articles in the Ai Integration category.
Ai Integrationai securityjournal
/academy/journal/category/ai-integration
AI Security — Journal
AI security journal articles in the AI Security category.
AI Securityai securityjournal
/academy/journal/category/ai-security
Ai Security Engineering — Journal
AI security journal articles in the Ai Security Engineering category.
Ai Security Engineeringai securityjournal
/academy/journal/category/ai-security-engineering
Application Security Engineer — Career Dossier
Secures software applications, code, dependencies, SDLC processes, and developer workflows.
Application Securitysecurely provisionai securitycareer
/academy/reference/career-explorer/roles/application-security-engineer
Ats Systems — Journal
AI security journal articles in the Ats Systems category.
Ats Systemsai securityjournal
/academy/journal/category/ats-systems
Attack — Journal
AI security journal articles in the Attack category.
Attackai securityjournal
/academy/journal/category/attack
Attack — Journal
Journal articles for the Attack security engineering capability.
Attackcapabilitytraining
/academy/journal/capability/attack
Career Development — Journal
AI security journal articles in the Career Development category.
Career Developmentai securityjournal
/academy/journal/category/know-yourself
Career Development — Journal
AI security journal articles in the Career Development category.
Career Developmentai securityjournal
/academy/journal/category/career-development
CISO — Career Dossier
Owns enterprise cybersecurity strategy, risk, governance, board communication, and security operating model.
Security Leadershipoversee governai securitycareer
/academy/reference/career-explorer/roles/ciso
Cloud Security Engineer — Career Dossier
Secures cloud infrastructure, IAM, workloads, CI/CD, containers, and cloud-native architectures.
Cloud Securitysecurely provisionai securitycareer
/academy/reference/career-explorer/roles/cloud-security-engineer
Corporate Culture — Journal
AI security journal articles in the Corporate Culture category.
Corporate Cultureai securityjournal
/academy/journal/category/corporate-culture
Corporate Culture And Leadership — Journal
AI security journal articles in the Corporate Culture And Leadership category.
Corporate Culture And Leadershipai securityjournal
/academy/journal/category/corporate-culture-and-leadership
Culture Security — Journal
AI security journal articles in the Culture Security category.
Culture Securityai securityjournal
/academy/journal/category/culture-security
Cyber Security — Journal
AI security journal articles in the Cyber Security category.
Cyber Securityai securityjournal
/academy/journal/category/cyber-security
Cybersecurity — Journal
AI security journal articles in the Cybersecurity category.
Cybersecurityai securityjournal
/academy/journal/category/cybersecurity
Cybersecurity Strategy — Journal
AI security journal articles in the Cybersecurity Strategy category.
Cybersecurity Strategyai securityjournal
/academy/journal/category/cybersecurity-strategy
Data Security Engineer — Career Dossier
Secures data platforms, access controls, lineage, sensitive data, and data governance systems.
Data Securitysecurely provisionai securitycareer
/academy/reference/career-explorer/roles/data-security-engineer
Defend — Journal
AI security journal articles in the Defend category.
Defendai securityjournal
/academy/journal/category/defend
Defend — Journal
Journal articles for the Defend security engineering capability.
Defendcapabilitytraining
/academy/journal/capability/defend
DevSecOps Engineer — Career Dossier
Builds security automation into pipelines, infrastructure, delivery workflows, and developer platforms.
DevSecOpssecurely provisionai securitycareer
/academy/reference/career-explorer/roles/devsecops-engineer
Digital Forensics Analyst — Career Dossier
Collects, preserves, analyzes, and reports digital evidence.
Digital Forensicsinvestigateai securitycareer
/academy/reference/career-explorer/roles/digital-forensics-analyst
Distributed Governance — Journal
AI security journal articles in the Distributed Governance category.
Distributed Governanceai securityjournal
/academy/journal/category/distributed-governance
Distributed Systems — Journal
AI security journal articles in the Distributed Systems category.
Distributed Systemsai securityjournal
/academy/journal/category/distributed-systems
Economic Governance — Journal
AI security journal articles in the Economic Governance category.
Economic Governanceai securityjournal
/academy/journal/category/economic-governance
Education — Journal
AI security journal articles in the Education category.
Educationai securityjournal
/academy/journal/category/education-paths
Evidence — Journal
AI security journal articles in the Evidence category.
Evidenceai securityjournal
/academy/journal/category/evidence
Evidence — Journal
Journal articles for the Evidence security engineering capability.
Evidencecapabilitytraining
/academy/journal/capability/evidence
Future of Work — Journal
AI security journal articles in the Future of Work category.
Future of Workai securityjournal
/academy/journal/category/future-of-work
Governance — Journal
AI security journal articles in the Governance category.
Governanceai securityjournal
/academy/journal/category/governance
Governance And Resilience — Journal
AI security journal articles in the Governance And Resilience category.
Governance And Resilienceai securityjournal
/academy/journal/category/governance-and-resilience
GRC Analyst — Career Dossier
Supports governance, risk, compliance, controls, audits, evidence, and policy operations.
GRCoversee governai securitycareer
/academy/reference/career-explorer/roles/grc-analyst
Hiring & Talent — Journal
AI security journal articles in the Hiring & Talent category.
Hiring & Talentai securityjournal
/academy/journal/category/hiring-talent
Hiring And Talent — Journal
AI security journal articles in the Hiring And Talent category.
Hiring And Talentai securityjournal
/academy/journal/category/hiring-and-talent
Hiring Strategy — Journal
AI security journal articles in the Hiring Strategy category.
Hiring Strategyai securityjournal
/academy/journal/category/hiring-strategy
Identity Security Engineer — Career Dossier
Secures identity systems, IAM, access controls, privileged access, and authorization models.
Identity Securityoperate maintainai securitycareer
/academy/reference/career-explorer/roles/identity-security-engineer
Incident Responder — Career Dossier
Responds to, contains, investigates, and coordinates recovery from cybersecurity incidents.
Incident Responseprotect defendai securitycareer
/academy/reference/career-explorer/roles/incident-responder
Leadership And Governance — Journal
AI security journal articles in the Leadership And Governance category.
Leadership And Governanceai securityjournal
/academy/journal/category/leadership-and-governance
Malware Analyst — Career Dossier
Analyzes malicious code, behavior, campaigns, indicators, and reverse-engineering evidence.
Malware Analysisanalyzeai securitycareer
/academy/reference/career-explorer/roles/malware-analyst
Map — Journal
AI security journal articles in the Map category.
Mapai securityjournal
/academy/journal/category/map
Map — Journal
Journal articles for the Map security engineering capability.
Mapcapabilitytraining
/academy/journal/capability/map
ML Security Engineer — Career Dossier
Secures machine learning models, training pipelines, data integrity, deployment, and adversarial ML surfaces.
ML Securitycross cuttingai securitycareer
/academy/reference/career-explorer/roles/ml-security-engineer
Model Risk Manager — Career Dossier
Manages model risk governance, validation, monitoring, approvals, controls, and regulatory evidence.
Model Riskoversee governai securitycareer
/academy/reference/career-explorer/roles/model-risk-manager
Operational Risk — Journal
AI security journal articles in the Operational Risk category.
Operational Riskai securityjournal
/academy/journal/category/operational-risk
Organizational Governance — Journal
AI security journal articles in the Organizational Governance category.
Organizational Governanceai securityjournal
/academy/journal/category/organizational-governance
Organizational Resilience — Journal
AI security journal articles in the Organizational Resilience category.
Organizational Resilienceai securityjournal
/academy/journal/category/organizational-resilience
Penetration Tester — Career Dossier
Performs authorized adversarial testing of applications, systems, infrastructure, and environments.
Offensive Securityprotect defendai securitycareer
/academy/reference/career-explorer/roles/penetration-tester
Platform Governance — Journal
AI security journal articles in the Platform Governance category.
Platform Governanceai securityjournal
/academy/journal/category/platform-governance
Privacy Engineer — Career Dossier
Builds privacy-preserving systems, data controls, privacy reviews, and compliance-aware engineering practices.
Privacy Engineeringsecurely provisionai securitycareer
/academy/reference/career-explorer/roles/privacy-engineer
Product Security Engineer — Career Dossier
Secures product architecture, feature delivery, customer assurance, threat modeling, and secure engineering practices.
Product Securitysecurely provisionai securitycareer
/academy/reference/career-explorer/roles/product-security-engineer
Psychological Safety — Journal
AI security journal articles in the Psychological Safety category.
Psychological Safetyai securityjournal
/academy/journal/category/psychological-safety
Psychometrics — Journal
AI security journal articles in the Psychometrics category.
Psychometricsai securityjournal
/academy/journal/category/psychometrics
Recruitment And Talent — Journal
AI security journal articles in the Recruitment And Talent category.
Recruitment And Talentai securityjournal
/academy/journal/category/recruitment-and-talent
Red Team Operator — Career Dossier
Executes adversary emulation and offensive operations to test defensive readiness.
Red Teamprotect defendai securitycareer
/academy/reference/career-explorer/roles/red-team-operator
Security Architect — Career Dossier
Designs security architectures, controls, patterns, and technical risk strategies across systems.
Security Architecturesecurely provisionai securitycareer
/academy/reference/career-explorer/roles/security-architect
Security Architecture — Journal
AI security journal articles in the Security Architecture category.
Security Architectureai securityjournal
/academy/journal/category/security-architecture
Security Awareness Lead — Career Dossier
Builds workforce security education, behavior change, phishing resistance, and awareness programs.
Security Awarenessoversee governai securitycareer
/academy/reference/career-explorer/roles/security-awareness-lead
Security Engineering Manager — Career Dossier
Leads security engineering teams, priorities, roadmaps, execution, and stakeholder alignment.
Security Leadershipoversee governai securitycareer
/academy/reference/career-explorer/roles/security-engineering-manager
Security Operations Analyst — Career Dossier
Monitors, triages, investigates, and responds to security events and alerts.
Security Operationsprotect defendai securitycareer
/academy/reference/career-explorer/roles/security-operations-analyst
Stochastic Governance — Journal
AI security journal articles in the Stochastic Governance category.
Stochastic Governanceai securityjournal
/academy/journal/category/stochastic-governance
Stochastic Resilience — Journal
AI security journal articles in the Stochastic Resilience category.
Stochastic Resilienceai securityjournal
/academy/journal/category/stochastic-resilience
Systemic Resilience — Journal
AI security journal articles in the Systemic Resilience category.
Systemic Resilienceai securityjournal
/academy/journal/category/systemic-resilience
Talent Acquisition — Journal
AI security journal articles in the Talent Acquisition category.
Talent Acquisitionai securityjournal
/academy/journal/category/talent-acquisition
Technical Intelligence — Journal
AI security journal articles in the Technical Intelligence category.
Technical Intelligenceai securityjournal
/academy/journal/category/technical-intelligence
Threat Hunter — Career Dossier
Proactively searches for adversary activity, suspicious behavior, and hidden threats.
Threat Huntingprotect defendai securitycareer
/academy/reference/career-explorer/roles/threat-hunter
Threat Intelligence Analyst — Career Dossier
Analyzes threat actors, campaigns, vulnerabilities, TTPs, and intelligence sources.
Threat Intelligenceanalyzeai securitycareer
/academy/reference/career-explorer/roles/threat-intelligence-analyst
Toolchain Integrity — Journal
AI security journal articles in the Toolchain Integrity category.
Toolchain Integrityai securityjournal
/academy/journal/category/toolchain-integrity
Training & Workshops — Journal
AI security journal articles in the Training & Workshops category.
Training & Workshopsai securityjournal
/academy/journal/category/workshops
Vulnerability Management Analyst — Career Dossier
Identifies, prioritizes, tracks, and coordinates remediation of vulnerabilities.
Vulnerability Managementprotect defendai securitycareer
/academy/reference/career-explorer/roles/vulnerability-management-analyst
Workforce Science — Journal
AI security journal articles in the Workforce Science category.
Workforce Scienceai securityjournal
/academy/journal/category/psychometric-science
Workplace Evolution — Journal
AI security journal articles in the Workplace Evolution category.
Workplace Evolutionai securityjournal
/academy/journal/category/workplace-evolution
Academy Reading Materials
Handbook chapters, Field Guide chapters, and Mythos selections for academy lab prep and reference.
/academy/resourcesapp/(public)/academy/resources/page.tsx
Academy Reference Desk
Framework maps, compliance crosswalks, and reference tools for AI security teams.
/academy/referenceapp/(public)/academy/reference/page.tsx
Agent Permission Lab — Academy Labs
Analyze agent tool configurations for permission scope creep, missing approval gates, and dangerous side effects.
/academy/labs/agent-permissionapp/(public)/academy/labs/agent-permission/page.tsx
AI Control Crosswalk
Framework navigation across OWASP LLM Top 10, NIST AI RMF, MITRE ATLAS, and ISO 42001 with evidence prompts and scorecard bridges.
/academy/reference/crosswalkapp/(public)/academy/reference/crosswalk/page.tsx
AI Governance & Policy Lab
Evaluate a draft AI use policy against a real query corpus.
/academy/labs/governanceapp/(public)/academy/labs/governance/page.tsx
AI Hiring Workshop
A 3–4 hour working session to calibrate the role before you post it, with JD rewrite, interview loop, scorecard, and onboarding path.
/academy/workshops/ai-hiring-workshopapp/(public)/academy/workshops/ai-hiring-workshop/page.tsx
AI Incident Response Lab
Classify an AI incident from SOC event data, evaluate ethical incident drill scenarios, determine scope and containment actions
/academy/labs/incident-responseapp/(public)/academy/labs/incident-response/page.tsx
AI Inventory & System Boundaries Lab
Build a formal AI system inventory from a real MCP server configuration.
/academy/labs/ai-inventoryapp/(public)/academy/labs/ai-inventory/page.tsx
AI Logging & Forensics Lab
Analyze guardrail denial logs and SOC event streams.
/academy/labs/logging-forensicsapp/(public)/academy/labs/logging-forensics/page.tsx
AI Product Threat Modeling Lab
Apply STRIDE to a real MCP server architecture.
/academy/labs/threat-modelingapp/(public)/academy/labs/threat-modeling/page.tsx
AI Security Academy
Role-based AI security training, labs, workshops, and enterprise rollout options.
/academyapp/(public)/academy/page.tsx
AI Security Internships
Research-driven AI security internships building practical tools, framework mapping, red-team learning, and governance evidence work.
/academy/internshipsapp/(public)/academy/internships/page.tsx
AI Security Labs
Hands-on AI security labs for prompt injection, output safety, agent permissions, RAG, data leakage, supply chain, governance, and incident response.
/academy/labsapp/(public)/academy/labs/page.tsx
AI Security Workshops
Productized AI security workshops for program planning, architecture review, red team jumpstarts, blue team jumpstarts, and governance claim-readiness.
/academy/workshopsapp/(public)/academy/workshops/page.tsx
AI Supply Chain Security Lab
Analyze a malicious PR with a hidden instruction, a terraform state file leaking secrets, and a supply chain poisoning attack pack.
/academy/labs/supply-chainapp/(public)/academy/labs/supply-chain/page.tsx
AI Vendor Risk & Procurement Lab
Evaluate an AI model provider's trust center, DPA, and security questionnaire for procurement readiness.
/academy/labs/vendor-risk-procurementapp/(public)/academy/labs/vendor-risk-procurement/page.tsx
AIPSA Academy Course Syllabus — AI Product Security Training
Full course syllabus for AIPSA Academy: 16 hands-on labs, 37 PDF chapters, 200+ assessment questions, and four certification levels across the Map
/academy/syllabusapp/(public)/academy/syllabus/page.tsx
AIPSA Assessment Model — Practitioner Verification
Domain-scored assessment levels benchmarking individual knowledge across AI Product Security domains.
/academy/certificationapp/(public)/academy/certification/page.tsx
AIPSA Badge Catalog — All Badge Families
Complete catalog of AIPSA practitioner assessment records, consultant marks, evidence marks, program badges, and lab badges.
/academy/certification/badgesapp/(public)/academy/certification/badges/page.tsx
AIPSA Leaderboard — Top AI Security Practitioners
The top 50 AI security practitioners by AIPSA lab completions. Updated hourly.
/academy/leaderboardapp/(public)/academy/leaderboard/page.tsx
AIPSA Sample Results
Sample AIPSA assessment result for a Security Engineer scoring Practitioner, with domain breakdown, study plan, and verification record.
/academy/certification/demoapp/(public)/academy/certification/demo/page.tsx
AIPSA Study Flash Cards — AI Product Security Assessment
AIPSA Study Flash Cards for AI Product Security Assessment training across 14 domains and 4 pillars.
/academy/training/flash-cardsapp/(public)/academy/training/flash-cards/page.tsx
Atlas
/academy/reference/crosswalk/atlasapp/(public)/academy/reference/crosswalk/atlas/page.tsx
Badges
/aipsa/badgesapp/(public)/aipsa/badges/page.tsx
Career Explorer — AI Security Career Paths — AI Security…
/academy/reference/career-explorerapp/(public)/academy/reference/career-explorer/page.tsx
Careers
/academy/careersapp/(public)/academy/careers/page.tsx
Certification
/aipsa/certificationapp/(public)/aipsa/certification/page.tsx
Certification
/evidence/certificationapp/(public)/evidence/certification/page.tsx
Data Leakage & Cross-Tenant Exposure Lab
Practice reviewing prompt traces, RAG authorization gaps, tenant data fixtures, and PII leakage evidence in the AIPSA Academy.
/academy/labs/data-leakageapp/(public)/academy/labs/data-leakage/page.tsx
Demo
/aipsa/certification/demoapp/(public)/aipsa/certification/demo/page.tsx
Enterprise AI Security Training
Enterprise AI security training with LMS delivery, private cohorts, Q&A checks, and manager reporting.
/academy/enterpriseapp/(public)/academy/enterprise/page.tsx
Evidence Packs
/aipsa/evidence-packsapp/(public)/aipsa/evidence-packs/page.tsx
Field Notes — AI Security Engineering
Field notes from AI security engineering practice — analysis, patterns, and observations from MADE methodology work.
/academy/journalapp/(public)/academy/journal/page.tsx
Flash Cards
/evidence/certification/train/flash-cardsapp/(public)/evidence/certification/train/flash-cards/page.tsx
ISO 42001 / AIMS | AI Control Crosswalk
Derived ISO 42001 / AIMS readiness browser with clause themes, NIST alignment, and AI Trust Governance dimensions.
/academy/reference/crosswalk/iso-42001app/(public)/academy/reference/crosswalk/iso-42001/page.tsx
Job Navigator Onboardingauth-only
Onboarding flow for imports, preferences, and market snapshot setup.
/academy/job-navigator/onboarding
Labs
/aipsa/labsapp/(public)/aipsa/labs/page.tsx
Lms
/academy/lmsapp/(public)/academy/lms/page.tsx
Lookup
/academy/training/lookupapp/(public)/academy/training/lookup/page.tsx
Lookup
/training/lookupapp/(public)/training/lookup/page.tsx
Memory & Context Poisoning Lab
Inspect poisoned session history and long-horizon memory fixtures to identify how persistent agent memory becomes an attack surface.
/academy/labs/memory-poisoningapp/(public)/academy/labs/memory-poisoning/page.tsx
MLOps Platform Security Lab
Audit a realistic MLOps stack — Jupyter notebook, model registry, CI pipeline, and inference IAM — for credential exposure, overprivileged roles
/academy/labs/mlops-platform-securityapp/(public)/academy/labs/mlops-platform-security/page.tsx
Multimodal Injection Lab
Analyze adversarial payloads in images, EXIF metadata, SVG files, ASCII art, and unicode-encoded text.
/academy/labs/multimodal-injectionapp/(public)/academy/labs/multimodal-injection/page.tsx
My Academy Progress — Academy
Track your lab completions, scores, and AIPSA certification readiness across all 14 AI security domains.
/academy/progressapp/(public)/academy/progress/page.tsx
Navigator
/academy/reference/crosswalk/atlas/navigatorapp/(public)/academy/reference/crosswalk/atlas/navigator/page.tsx
NIST AI RMF | AI Control Crosswalk
Interactive NIST AI RMF browser with Govern, Map, Measure, and Manage playbook actions and scorecard mappings.
/academy/reference/crosswalk/nist-ai-rmfapp/(public)/academy/reference/crosswalk/nist-ai-rmf/page.tsx
Nist Nice
/academy/reference/nist-niceapp/(public)/academy/reference/nist-nice/page.tsx
Output Safety Lab — Academy Labs
Test AI model output across 8 dangerous sink types.
/academy/labs/output-safetyapp/(public)/academy/labs/output-safety/page.tsx
OWASP LLM Top 10 | AI Control Crosswalk
Interactive OWASP LLM Top 10 browser with mitigations, ATLAS crosswalks, NIST AI RMF alignment, and scorecard signals.
/academy/reference/crosswalk/owaspapp/(public)/academy/reference/crosswalk/owasp/page.tsx
Play
/academy/training/speed-run/playapp/(public)/academy/training/speed-run/play/page.tsx
Play
/training/speed-run/playapp/(public)/training/speed-run/play/page.tsx
Prompt Injection Lab — Academy Labs
Run 12 structured prompt injection probes across 10 attack categories.
/academy/labs/injection-harnessapp/(public)/academy/labs/injection-harness/page.tsx
Prompt Security Lab — Academy Labs
Analyze system prompts against 15 security rule categories.
/academy/labs/prompt-reviewerapp/(public)/academy/labs/prompt-reviewer/page.tsx
Purchase Confirmed — AIPSA Academy
Your academy purchase has been confirmed.
/academy/successapp/(public)/academy/success/page.tsx
RAG Security Lab — Academy Labs
Analyze RAG pipeline configurations for authorization gaps, tenant isolation failures, and indirect injection surfaces.
/academy/labs/rag-securityapp/(public)/academy/labs/rag-security/page.tsx
Scorm
/academy/scormapp/(public)/academy/scorm/page.tsx
Speed Run
/academy/training/speed-runapp/(public)/academy/training/speed-run/page.tsx
Speed Run
/evidence/certification/train/speed-runapp/(public)/evidence/certification/train/speed-run/page.tsx
Speed Run
/training/speed-runapp/(public)/training/speed-run/page.tsx
Start
/academy/startapp/(public)/academy/start/page.tsx
Train
/evidence/certification/trainapp/(public)/evidence/certification/train/page.tsx
Training
/academy/trainingapp/(public)/academy/training/page.tsx
undefined — Author
Journal articles by undefined.
authorai security
/academy/journal/author/editorial-team
undefined — Author
Journal articles by undefined.
authorai security
/academy/journal/author/david-wolf
undefined — Author
Journal articles by undefined.
authorai security
/academy/journal/author/tim-kerimbekov
undefined — Author
Journal articles by undefined.
authorai security
/academy/journal/author/alex-eisen
undefined — Author
Journal articles by undefined.
authorai security
/academy/journal/author/dorina-miroyannis
Verify
/aipsa/verifyapp/(public)/aipsa/verify/page.tsx
Verify a Credential — AIPSA
Verify the authenticity of an AIPSA practitioner credential by ID.
/academy/certification/verifyapp/(public)/academy/certification/verify/page.tsx
Agent Security — Journal
Journal articles tagged Agent Security.
Agent Securitytagai security
/academy/journal/tag/agent-security
Agentic Permissions — Journal
Journal articles tagged Agentic Permissions.
Agentic Permissionstagai security
/academy/journal/tag/agentic-permissions
AI Agent Security — Journal
Journal articles tagged AI Agent Security.
AI Agent Securitytagai security
/academy/journal/tag/ai-agent-security
AI Governance Evidence — Journal
Journal articles tagged AI Governance Evidence.
AI Governance Evidencetagai security
/academy/journal/tag/ai-governance-evidence
Ai Impact — Journal
Journal articles tagged Ai Impact.
Ai Impacttagai security
/academy/journal/tag/ai-impact
Ai Integration — Journal
Journal articles tagged Ai Integration.
Ai Integrationtagai security
/academy/journal/tag/ai-integration
AI Red Teaming — Journal
Journal articles tagged AI Red Teaming.
AI Red Teamingtagai security
/academy/journal/tag/ai-red-teaming
AI SDLC & Product Security — Journal
Journal articles tagged AI SDLC & Product Security.
AI SDLC & Product Securitytagai security
/academy/journal/tag/ai-sdlc-and-product-security
AI Security — Journal
Journal articles tagged AI Security.
AI Securitytagai security
/academy/journal/tag/ai-security
AI Security Engineer Career — Journal
Journal articles tagged AI Security Engineer Career.
AI Security Engineer Careertagai security
/academy/journal/tag/ai-security-engineer-career
Ai Security Engineering — Journal
Journal articles tagged Ai Security Engineering.
Ai Security Engineeringtagai security
/academy/journal/tag/ai-security-engineering
AI Security Foundations — Journal
Journal articles tagged AI Security Foundations.
AI Security Foundationstagai security
/academy/journal/tag/ai-security-foundations
AI Security Monitoring — Journal
Journal articles tagged AI Security Monitoring.
AI Security Monitoringtagai security
/academy/journal/tag/ai-security-monitoring
AI Security Tools — Journal
Journal articles tagged AI Security Tools.
AI Security Toolstagai security
/academy/journal/tag/ai-security-tools
AI Supply Chain — Journal
Journal articles tagged AI Supply Chain.
AI Supply Chaintagai security
/academy/journal/tag/ai-supply-chain
AI System Inventory — Journal
Journal articles tagged AI System Inventory.
AI System Inventorytagai security
/academy/journal/tag/ai-system-inventory
Architecture and Trust Boundaries — Journal
Journal articles tagged Architecture and Trust Boundaries.
Architecture and Trust Boundariestagai security
/academy/journal/tag/architecture-and-trust-boundaries
Ats Systems — Journal
Journal articles tagged Ats Systems.
Ats Systemstagai security
/academy/journal/tag/ats-systems
Attack — Journal
Journal articles tagged Attack.
Attacktagai security
/academy/journal/tag/attack
Career Development — Journal
Journal articles tagged Career Development.
Career Developmenttagai security
/academy/journal/tag/career-development
Corporate Culture — Journal
Journal articles tagged Corporate Culture.
Corporate Culturetagai security
/academy/journal/tag/corporate-culture
Corporate Culture And Leadership — Journal
Journal articles tagged Corporate Culture And Leadership.
Corporate Culture And Leadershiptagai security
/academy/journal/tag/corporate-culture-and-leadership
Culture Security — Journal
Journal articles tagged Culture Security.
Culture Securitytagai security
/academy/journal/tag/culture-security
Cyber Security — Journal
Journal articles tagged Cyber Security.
Cyber Securitytagai security
/academy/journal/tag/cyber-security
cybersecurity — Journal
Journal articles tagged cybersecurity.
cybersecuritytagai security
/academy/journal/tag/cybersecurity
Cybersecurity Strategy — Journal
Journal articles tagged Cybersecurity Strategy.
Cybersecurity Strategytagai security
/academy/journal/tag/cybersecurity-strategy
Data Exposure and Privacy — Journal
Journal articles tagged Data Exposure and Privacy.
Data Exposure and Privacytagai security
/academy/journal/tag/data-exposure-and-privacy
Defend — Journal
Journal articles tagged Defend.
Defendtagai security
/academy/journal/tag/defend
Detection Engineering — Journal
Journal articles tagged Detection Engineering.
Detection Engineeringtagai security
/academy/journal/tag/detection-engineering
Distributed Governance — Journal
Journal articles tagged Distributed Governance.
Distributed Governancetagai security
/academy/journal/tag/distributed-governance
Distributed Systems — Journal
Journal articles tagged Distributed Systems.
Distributed Systemstagai security
/academy/journal/tag/distributed-systems
Economic Governance — Journal
Journal articles tagged Economic Governance.
Economic Governancetagai security
/academy/journal/tag/economic-governance
Education — Journal
Journal articles tagged Education.
Educationtagai security
/academy/journal/tag/education
Evaluation and Regression Testing — Journal
Journal articles tagged Evaluation and Regression Testing.
Evaluation and Regression Testingtagai security
/academy/journal/tag/evaluation-and-regression-testing
Evidence — Journal
Journal articles tagged Evidence.
Evidencetagai security
/academy/journal/tag/evidence
Future of Work — Journal
Journal articles tagged Future of Work.
Future of Worktagai security
/academy/journal/tag/future-of-work
governance — Journal
Journal articles tagged governance.
governancetagai security
/academy/journal/tag/governance
Governance And Resilience — Journal
Journal articles tagged Governance And Resilience.
Governance And Resiliencetagai security
/academy/journal/tag/governance-and-resilience
Governance Evidence and Customer Trust — Journal
Journal articles tagged Governance Evidence and Customer Trust.
Governance Evidence and Customer Trusttagai security
/academy/journal/tag/governance-evidence-and-customer-trust
Governance, Risk & Compliance — Journal
Journal articles tagged Governance, Risk & Compliance.
Governance, Risk & Compliancetagai security
/academy/journal/tag/governance-risk-and-compliance
Hiring & Talent — Journal
Journal articles tagged Hiring & Talent.
Hiring & Talenttagai security
/academy/journal/tag/hiring-and-talent
Hiring Strategy — Journal
Journal articles tagged Hiring Strategy.
Hiring Strategytagai security
/academy/journal/tag/hiring-strategy
Incident Response & Observability — Journal
Journal articles tagged Incident Response & Observability.
Incident Response & Observabilitytagai security
/academy/journal/tag/incident-response-and-observability
Leadership And Governance — Journal
Journal articles tagged Leadership And Governance.
Leadership And Governancetagai security
/academy/journal/tag/leadership-and-governance
LLM Application Security — Journal
Journal articles tagged LLM Application Security.
LLM Application Securitytagai security
/academy/journal/tag/llm-application-security
Logging and Telemetry — Journal
Journal articles tagged Logging and Telemetry.
Logging and Telemetrytagai security
/academy/journal/tag/logging-and-telemetry
Map — Journal
Journal articles tagged Map.
Maptagai security
/academy/journal/tag/map
MLOps & Platform Security — Journal
Journal articles tagged MLOps & Platform Security.
MLOps & Platform Securitytagai security
/academy/journal/tag/mlops-and-platform-security
Model and Provider Risk — Journal
Journal articles tagged Model and Provider Risk.
Model and Provider Risktagai security
/academy/journal/tag/model-and-provider-risk
Model Supply Chain — Journal
Journal articles tagged Model Supply Chain.
Model Supply Chaintagai security
/academy/journal/tag/model-supply-chain
Operational Risk — Journal
Journal articles tagged Operational Risk.
Operational Risktagai security
/academy/journal/tag/operational-risk
Organizational Governance — Journal
Journal articles tagged Organizational Governance.
Organizational Governancetagai security
/academy/journal/tag/organizational-governance
Organizational Resilience — Journal
Journal articles tagged Organizational Resilience.
Organizational Resiliencetagai security
/academy/journal/tag/organizational-resilience
Platform Governance — Journal
Journal articles tagged Platform Governance.
Platform Governancetagai security
/academy/journal/tag/platform-governance
Privacy & Data Protection — Journal
Journal articles tagged Privacy & Data Protection.
Privacy & Data Protectiontagai security
/academy/journal/tag/privacy-and-data-protection
Prompt Injection — Journal
Journal articles tagged Prompt Injection.
Prompt Injectiontagai security
/academy/journal/tag/prompt-injection
Psychological Safety — Journal
Journal articles tagged Psychological Safety.
Psychological Safetytagai security
/academy/journal/tag/psychological-safety
psychometrics — Journal
Journal articles tagged psychometrics.
psychometricstagai security
/academy/journal/tag/psychometrics
RAG Authorization — Journal
Journal articles tagged RAG Authorization.
RAG Authorizationtagai security
/academy/journal/tag/rag-authorization
RAG Security — Journal
Journal articles tagged RAG Security.
RAG Securitytagai security
/academy/journal/tag/rag-security
Job Navigator Importauth-only
Import setup for job-market intelligence onboarding.
/academy/job-navigator/onboarding/import
Job Navigator Market Snapshotauth-only
Market snapshot setup for job navigator onboarding.
/academy/job-navigator/onboarding/market-snapshot
Job Navigator Preferencesauth-only
Preferences setup for job navigator onboarding.
/academy/job-navigator/onboarding/preferences

Labs

11 pages

Hands-on adversarial tools and demos

Research

429 pages

Briefs, tools, pains, failure modes, and personas

Research
AI security engineering research, reports, benchmarks, and field intelligence.
/research
AI Security Publications
Research reports, field guides, handbooks, and reference volumes for AI security engineering.
/research/publications
Research Findings
Validated empirical, diagnostic, interpretive, operating-model, and workforce findings.
/research/findings
Vendor Benchmarks
Planned benchmark routes for secure code generation, prompt injection, RAG leakage, agent abuse, guardrails, code review, artifact triage, and model gateway…
/research/benchmarks
Agent Tool Abuse Benchmark
Planned benchmark for agent tool misuse, excessive agency, approval bypass, unsafe chaining, and tool policy enforcement.
/research/benchmarks/agent-tool-abuse
AI Artifact & Binary Triage Benchmark
Active benchmark for AI-assisted triage of binaries, browser extensions, CLI tools, configs, manifests, and packaged agents.
/research/benchmarks/artifact-binary-triage
AI Code Review Quality Benchmark
Active benchmark for evaluating LLM vulnerability detection, severity accuracy, exploit reasoning, and secure fix quality.
/research/benchmarks/ai-code-review-quality
Canonical Statistics
Versioned values with populations, cutoffs, caveats, and supersession state.
/research/statistics
Figures and Models
Data-backed charts, conceptual models, workflows, matrices, and reference diagrams.
/research/figures
Guardrail Robustness Benchmark
Planned benchmark for guardrail bypass, false refusals, overblocking, policy consistency, latency, and cost impact.
/research/benchmarks/guardrail-robustness
Model Gateway Policy Enforcement Benchmark
Planned benchmark for model gateway routing, redaction, logging, policy enforcement, approval flows, tenant boundaries, and audit completeness.
/research/benchmarks/model-gateway-policy
Prompt Injection Resistance Benchmark
Planned benchmark for direct and indirect prompt injection resistance across models, agents, RAG systems, guardrails, and gateways.
/research/benchmarks/prompt-injection-resistance
RAG Leakage & Retrieval Boundary Benchmark
Planned benchmark for RAG leakage, tenant isolation, poisoned context, sensitive document exposure, and citation integrity.
/research/benchmarks/rag-leakage-boundary
Secure Code Generation Benchmark
Active benchmark for comparing how safely LLMs generate code under realistic developer prompts.
/research/benchmarks/secure-code-generation
Research Topics
Topic-level rollups of findings, statistics, figures, concepts, papers, and sources.
/research/topics
Sources and Evidence
Public source records, documents, assertions, statistics, quotations, and citation provenance.
/research/sources
A Layered Security Framework Against Prompt Injection in…
A three-layer framework intercepting direct and indirect prompt injection throughout the inference pipeline, reducing Attack Success Rate from 71.4% to 11.3%…
/research/papers/arxiv-2606-19660
ADR: An Agentic Detection System for Enterprise Agentic AI…
The first large-scale, production-proven enterprise framework for securing AI agents operating through the Model Context Protocol, deployed at Uber for over…
/research/papers/arxiv-2605-17380
Agent Authority Boundary
The sequence through which AI influence reaches retrieval, tools, authorization, action, and external consequence.
/research/concepts/agent-authority-boundary
Agent Security
Security of AI systems that retrieve, invoke tools, authorize actions, and create external consequences.
/research/topics/agent-security
Agent Tool Inventory / Tool BOM
A catalog of tools, action classes, execution paths, credentials, data touched, approval requirements, owners, logging, and risk.
deliverable
/deliverables/agent-tool-inventory
Agent Tool Permission Matrix
A structured matrix showing exactly what each AI agent can read, suggest, draft, queue, approve, execute, log, and change across tools and workflows.
deliverable
/deliverables/agent-tool-permission-matrix
Agentic Anarchy
Agentic product capability is advancing faster than explicit security ownership for identity, tool access, authorization, and external consequence.
/research/findings/agentic-anarchy
AI Architecture Review
A formal architecture review covering model boundary, retrieval boundary, tool boundary, approval boundary, trace boundary, provider boundary, and release…
deliverable
/deliverables/ai-architecture-review
AI Buyer FAQ / Trust-Center FAQ
A structured buyer-facing AI security FAQ with approved answers, evidence references, status, and trust-center usage rules.
deliverable
/deliverables/ai-buyer-faq
AI Control Gap Assessment
A gap assessment mapping missing, partial, implemented, and validated AI controls to evidence, owners, remediation, release blockers, and buyer impact.
deliverable
/deliverables/ai-control-gap-assessment
AI Control Mapping Summary
A compact map from AI controls to standards, frameworks, evidence themes, owners, and buyer questions.
deliverable
/deliverables/ai-control-mapping-summary
AI Evidence Pack Appendix / Artifact Index
An appendix for long-form AI evidence packs indexing artifacts, sources, screenshots, traces, tests, decisions, and evidence.
deliverable
/deliverables/ai-evidence-pack-appendix
AI Governance Evidence Matrix
A control-to-evidence matrix for AI governance, audit, procurement, compliance review, and trust-center proof.
deliverable
/deliverables/ai-governance-evidence-matrix
AI Incident Response Playbook
AI-specific incident triggers, trace preservation, reconstruction, containment, customer notification, communication, and recovery steps.
deliverable
/deliverables/ai-incident-response-playbook
AI Product Supply Chain
An AI product is composed of models, prompts, policies, data, context, tools, orchestration, infrastructure, evaluations, and generated artifacts.
/research/concepts/ai-product-supply-chain
AI Red Team Assessment Executive Summary
An executive-ready summary of adversarial AI testing, validated attack paths, impact, release blockers, remediation, and retest requirements.
deliverable
/deliverables/ai-red-team-executive-summary
AI Red Teaming
Adversarial testing of realistic AI failure paths, authority boundaries, control failures, and external consequences.
/research/topics/ai-red-teaming
AI Red-Team Findings Register
A technical companion to the executive summary with structured findings, severity, reproduction summary, affected boundary, evidence, remediation, and…
deliverable
/deliverables/ai-red-team-findings-register
AI Red-Team Remediation Roadmap
A post-assessment roadmap for prioritized AI red-team fixes, owners, due dates, validation status, retest criteria, and release decisions.
deliverable
/deliverables/ai-red-team-remediation-roadmap
AI Red-Team Scope Document
A formal AI red-team scope covering objectives, exclusions, allowed techniques, severity rubric, evidence format, safety rules, and communications protocol.
deliverable
/deliverables/ai-red-team-scope-document
AI Release Gate Checklist
A practical engineering release gate for model/provider changes, prompts, retrieval sources, tools, logging, privacy, approval, rollback, and signoff.
deliverable
/deliverables/ai-release-gate-checklist
AI Risk Register
A prioritized AI security risk register connecting risks, owners, severity, likelihood, impact, remediation, validation, evidence, and executive decisions.
deliverable
/deliverables/ai-risk-register
AI Security arXiv Corpus 2026
Canonical State 2026 AI-security-tagged arXiv corpus.
/research/data/ai-security-arxiv-2026
AI Security Discovery / Intake Pack
A first-call artifact for scoping AI systems, evidence gaps, stakeholders, urgency, risks, and engagement fit.
deliverable
/deliverables/ai-security-discovery-pack
AI Security Engineering
The engineering discipline responsible for mapping, attacking, defending, and evidencing the security of AI products and systems.
/research/topics/ai-security-engineering
AI Security Evidence
Reproducible evidence that AI security controls exist, operate, and continue to work.
/research/topics/ai-security-evidence
AI Security Execution Gap
The gap between recognizing AI risk and producing reproducible evidence that an engineered control works.
/research/concepts/ai-security-execution-gap
AI Security Governance
Governance language, control ownership, operating accountability, and defensible security claims for AI systems.
/research/topics/ai-security-governance
AI Security Institutional Formation
The research, building, security, governance, incident, staffing, and funding systems through which a discipline becomes real.
/research/topics/ai-security-institutional-formation
AI Security Job Descriptions 2026
Canonical State 2026 ATS job-description corpus.
/research/data/ai-security-job-descriptions-2026
AI Security Maturity Scorecard
A concise assessment output showing AI security maturity by domain, evidence confidence, benchmark posture, top gaps, and the next decision.
deliverable
/deliverables/ai-security-maturity-scorecard
AI Security Media Corpus 2026
Canonical normalized State 2026 rolling media corpus.
/research/data/ai-security-media-2026
AI Security Operating Model Blueprint
A CISO-ready blueprint for AI intake, risk tiering, control ownership, exception handling, release gates, evidence workflows, cadence, and RACI.
deliverable
/deliverables/ai-security-operating-model-blueprint
AI Security Remediation Roadmap
A sequenced 30/60/90-day roadmap that turns AI security findings into owned work, release gates, retest criteria, and executive decision points.
deliverable
/deliverables/ai-security-remediation-roadmap
AI Security Workforce
Hiring, role architecture, skills, seniority, labor supply, and workforce infrastructure for AI Security Engineering.
/research/topics/ai-security-workforce
AI Supply Chain Security
Security of the models, data, prompts, policies, tools, orchestration, infrastructure, and generated artifacts that compose AI products.
/research/topics/ai-supply-chain-security
AI System Inventory / Application Register
A structured inventory of AI-enabled features, owners, models, data classes, retrieval, tools, approvals, traces, and evidence state.
deliverable
/deliverables/ai-system-inventory
AI Trust Boundary Map
A buyer-ready and engineering-ready map of users, AI components, data flows, model providers, tools, observability, controls, and trust boundaries.
deliverable
/deliverables/ai-trust-boundary-map
AI Vulnerability Intelligence
Vulnerability disclosures, exploited records, weakness patterns, and affected AI product surfaces.
/research/topics/ai-vulnerability-intelligence
AI-Relevant Vulnerabilities 2026
Strict canonical State 2026 AI-relevant vulnerability corpus.
/research/data/ai-relevant-vulnerabilities-2026
AI-Relevant Vulnerability Disclosures
Strict canonical AI-relevant vulnerability population.
/research/statistics/ai-relevant-vulnerability-disclosures
AI-Security Papers
AI-security-tagged papers in the State 2026 research corpus.
/research/statistics/ai-security-papers
Boardroom-to-Backlog Gap
Executive AI risk narratives often fail to translate into named controls, owners, and evidence artifacts at the engineering level.
/research/findings/boardroom-to-backlog-gap
ClawGuard: A Runtime Security Framework for Tool-Augmented…
A runtime security framework enforcing a user-confirmed rule set at every tool-call boundary, blocking indirect prompt injection pathways without model…
/research/papers/arxiv-2604-11790
Companies Analyzed
Companies represented in the canonical State 2026 hiring corpus.
/research/statistics/companies-analyzed
Enterprise AI Security Evidence Pack
Sample deliverable for answering enterprise AI security questionnaires, procurement review, legal review, trust review, and customer security due diligence.
deliverable
/deliverables/enterprise-ai-security-evidence-pack
Enterprise AI Security Questionnaire Answer Bank
A controlled answer bank for enterprise AI security questionnaires with approved answers, draft answers, evidence links, owners, freshness, and escalation…
deliverable
/deliverables/enterprise-ai-security-questionnaire-answer-bank
Entry-Level Extinction
AI security hiring is weighted toward experienced practitioners while the discipline lacks mature entry pathways and workforce infrastructure.
/research/findings/entry-level-extinction
From Risk Architecture to Role Architecture
Canonical figure from The State of AI Security Engineering 2026.
/research/figures/from-risk-architecture-to-role-architecture
From Shield to Target: Denial-of-Service Attacks on…
Reveals that the reasoning capabilities enabling LLM-based guardrails introduce a novel vulnerability: attackers can inject crafted data to trap the guardrail…
/research/papers/arxiv-2606-14517
Governance Language Ratio
Established compliance-language prevalence relative to AI-native governance and control vocabulary.
/research/statistics/governance-language-ratio
How a Profession Reproduces Itself
Canonical figure from The State of AI Security Engineering 2026.
/research/figures/how-a-profession-reproduces-itself
Inside-Out AI Security Assurance
Security assurance should begin with the system, boundary, and failure path rather than the desired claim.
/research/concepts/inside-out-ai-security-assurance
Institutionalization
Canonical figure from The State of AI Security Engineering 2026.
/research/figures/institutionalization
ISO/IEC 42001
ISO/IEC 42001 is tracked as a high-trust AI governance standard in the evidence corpus. Extraction and quote-level citation work has not started yet.
/research/sources/iso-42001
Job Descriptions Analyzed
Canonical State 2026 hiring corpus.
/research/statistics/job-descriptions-analyzed
M.A.D.E.
The durable operating functions of AI Security Engineering.
/research/concepts/made
Media Corpus Items
Items represented in the State 2026 rolling media corpus.
/research/statistics/media-corpus-items
MITRE ATLAS
MITRE ATLAS is tracked as a high-trust adversarial-AI security standard in the evidence corpus. Extraction and quote-level citation work has not started yet.
/research/sources/mitre-atlas
Model and Data Security
Security of model artifacts, training and evaluation data, retrieval sources, embeddings, and model promotion workflows.
/research/topics/model-and-data-security
Model Context Protocol Threat Modeling and Analyzing…
Conducts STRIDE and DREAD threat modeling of MCP implementations across five key components, finding tool poisoning -- malicious instructions embedded in tool…
/research/papers/arxiv-2603-22489
Model Provider Boundary Statement
Buyer-ready language on model-provider routing, training use, retention, subprocessors, minimization, traceability, and customer-facing claims.
deliverable
/deliverables/model-provider-boundary-statement
Model Supply Chain Blind Spot
Organizations often treat the model as the AI product while under-modeling the data, context, prompts, tools, orchestration, infrastructure, and generated…
/research/findings/model-supply-chain-blind-spot
NICE Cyber Workforce Framework
The NICE Cyber Workforce Framework is tracked as a high-trust workforce standard in the evidence corpus. Extraction and quote-level citation work has not…
/research/sources/nice-framework
NIST AI Risk Management Framework
The NIST AI Risk Management Framework is tracked as a high-trust AI governance standard in the evidence corpus. Extraction and quote-level citation work has…
/research/sources/nist-ai-rmf
Northstar Support Cloud Sample Pack
A guided sample pack showing how the Northstar Support Cloud engagement turns intake, inventory, architecture, retrieval, tools, evidence, and remediation…
deliverable
/deliverables/northstar-support-cloud-sample-pack
Open Source AI Security
Public repository activity, security tooling, OpenSSF controls, and builder behavior across AI security ecosystems.
/research/topics/open-source-ai-security
OpenSSF Repository Snapshot
Repositories represented in the State 2026 OpenSSF snapshot.
/research/statistics/openssf-repositories
OpenSSF Repository Snapshot 2026
Canonical State 2026 OpenSSF Scorecard repository snapshot.
/research/data/openssf-repository-snapshot-2026
Outside IN
Canonical figure from The State of AI Security Engineering 2026.
/research/figures/outside-in
OWASP Top 10 for LLM Applications
The OWASP Top 10 for LLM Applications is tracked as a high-trust AI security standard in the evidence corpus. Extraction and quote-level citation work has not…
/research/sources/owasp-llm
Public AI Incidents
Public AI incidents represented in the State 2026 incident corpus.
/research/statistics/public-ai-incidents
Public AI Incidents 2026
Canonical State 2026 public AI incident corpus.
/research/data/public-ai-incidents-2026
RAG Authorization Review
An evidence pack for retrieval ACLs, source authorization, chunking, indexing, reranking, and prompt-assembly authorization.
deliverable
/deliverables/rag-authorization-review
RAG Security
Security of retrieval-augmented generation systems, including authorization, poisoned context, retrieval abuse, and data exposure.
/research/topics/rag-security
RAG Security Test Plan and Results Summary
A technical test artifact for retrieval authorization, source poisoning, prompt injection through retrieved content, cross-tenant negatives, chunk visibility…
deliverable
/deliverables/rag-security-test-plan
Research Intelligence Explorer
Search the published registry by object type, source, status, and publication context.
/research/explore
Role Architecture Follows Risk Architecture
AI security roles should be derived from system exposure, required functions, ownership, team structure, tooling, and evidence obligations.
/research/concepts/role-architecture-follows-risk-architecture
ROLE Compression
Canonical figure from The State of AI Security Engineering 2026.
/research/figures/role-compression
Securing the AI Agent: A Unified Framework for Multi-Layer…
Presents AI-Infra-Guard, an open-source framework organizing AI red teaming across infrastructure, protocol/tool, agent behavior, and model layers, spanning…
/research/papers/arxiv-2606-31227
Signal Divergence
AI Security Engineering is forming through research, building, security, public attention, governance, exploitation, harm, staffing, and funding at different…
/research/concepts/signal-divergence
Skill Washing
AI language can appear in security hiring without materially changing the underlying responsibilities, controls, or operating model.
/research/findings/skill-washing
Skills Validation Gap
The market asks for AI security engineering skills before it has standardized, practical evaluation pathways to validate them.
/research/findings/skills-validation-gap
SoK: The Attack Surface of Agentic AI -- Tools, and Autonomy
Systematizes trust boundaries and security risks of agentic LLM-based systems, mapping a taxonomy of attacks spanning prompt-level injections, knowledge-base…
/research/papers/arxiv-2603-22928
TEMPLATEFUZZ: Fine-Grained Chat Template Fuzzing for…
A fine-grained fuzzing framework that systematically exposes vulnerabilities in chat templates, a critical yet underexplored attack surface, achieving a 98.2%…
/research/papers/arxiv-2604-12232
The Agent Authority Boundary
Canonical figure from The State of AI Security Engineering 2026.
/research/figures/the-agent-authority-boundary
The Agentic Surface Emergence
Prompt-injection, function-calling, and tool-calling security signals remain a small share of the research and tooling surface today, but are rising quickly.
/research/findings/agentic-surface-emergence
The AI Product Supply Chain
Canonical figure from The State of AI Security Engineering 2026.
/research/figures/the-ai-product-supply-chain
The Attention Deficit
Across 53,680 analyzed media items, capability coverage outpaces security coverage by roughly 5.0:1 (8,447 capability items vs. 1,682 across every…
/research/findings/attention-deficit
The Builder Vacuum
94.3% of observed repositories in GHArchive's bounded rolling-window sample (412 of 437) remain unclassified as AI-security-specific — the AI-native tooling…
/research/findings/builder-vacuum
The Compliance Reflex
Established compliance language substantially outweighs AI-native governance and control vocabulary in hiring language.
/research/findings/compliance-reflex
The Durable Functions of AI Security Engineering
Canonical figure from The State of AI Security Engineering 2026.
/research/figures/the-durable-functions-of-ai-security-engineering
The Evidence Gap
Organizations frequently move from policy or tooling claims directly to assurance without demonstrating the control, test, telemetry, and evidence chain.
/research/findings/evidence-gap
The Exploited Present
53 AI-relevant CVEs have reached CISA Known Exploited Vulnerability status — actively exploited in the wild today, not a theoretical future risk.
/research/findings/exploited-present
The Framework Paradox
Of 8 tracked AI-native security frameworks, 5 are document-only and only 3 are machine-readable — none are natively integrated into CI/CD pipelines, security…
/research/findings/framework-paradox
The Frankenstein Role
AI security hiring often compresses responsibilities historically distributed across several security disciplines into one requisition.
/research/findings/frankenstein-role
The Frontier Paper Stack
3,411 of 10,152 unique arXiv papers in the current pull are strict AI-security papers, already naming concrete work in prompt/generation security, agentic…
/research/findings/frontier-paper-stack
The Knowledge Desert
Only 8 Wikimedia pages are narrowly tagged AI-security-specific against a field with 3,411 strict AI-security arXiv papers and 437 classified GitHub repos…
/research/findings/knowledge-desert
The Privacy Asymmetry
Differential privacy and privacy-preserving ML remain active arXiv research terms (112 and 32 papers in the current pull), but privacy still appears in hiring…
/research/findings/privacy-asymmetry
The Probability Pivot
AI security hiring language increasingly reflects probabilistic systems reasoning and ambiguity tolerance rather than deterministic pass/fail control thinking.
/research/findings/probability-pivot
The Red Team Misnomer
AI red teaming is frequently described as a standalone activity even though durable value depends on control engineering, telemetry, replay, remediation, and…
/research/findings/red-team-misnomer
The Telemetry Blind Spot
arXiv puts only 1.99% of papers (202 of 10,152) in detection and runtime monitoring, and media coverage of AI cyber defense is just 0.9% of volume (486 of…
/research/findings/telemetry-blind-spot
The Tool Incumbency Trap
Compliance automation incumbents appear in hiring language more visibly than AI-native security testing and evaluation tooling.
/research/findings/tool-incumbency-trap
The Unicorn Index
The market prices one role while frequently describing team-level capability breadth, compressing five or more specialties into a single requisition.
/research/findings/unicorn-index
The vCISO Vacuum
Some organizations are too small to hire the unicorn role the market has priced, but too exposed to defer AI security entirely.
/research/findings/vciso-vacuum
TraceSafe: A Systematic Assessment of LLM Guardrails on…
As large language models evolve from static chatbots into autonomous agents, the primary vulnerability surface shifts from final outputs to intermediate…
/research/papers/arxiv-2604-07223
VATS: Exploiting Implicit Authority in Error-Path…
As the Model Context Protocol standardizes tool-calling for autonomous agents, it introduces a critical, unexamined attack surface: the error-handling loop.…
/research/papers/arxiv-2606-07992
Agent Approval Bypass
Human oversight that exists in language but not in action paths.
/failure-modes/agent-approval-bypass
Agentic Risk Brief
Practical brief for tool-using agents, RAG systems, and delegated action security.
/briefs/agentic-risk-brief
AI Governance Executive Brief
Executive brief for moving AI governance from policy to operating model.
/briefs/ai-governance-executive-brief
AI Governance Theater
Policy and committee language that does not change controls, evidence, or decisions.
/pains/ai-governance-theater
AI Logging Collapse
The inability to reconstruct what the system retrieved, generated, invoked, or exposed.
/failure-modes/ai-logging-collapse
AI Platform Lead Persona
Engineering leader persona for agentic systems, RAG security, and tool permissions.
/personas/ai-platform-engineering-lead
AI Security Diligence Portal Brief
Live diligence brief for buyers, investors, and internal reviewers grounded in current corpus metrics and claim-readiness gaps.
/briefs/ai-security-diligence-portal-brief
AI Security Maturity Blindness
The inability to see where AI security work is reactive, owned, or evidenced.
/pains/ai-security-maturity-blindness
AI Security Role Frankenstein
Hybrid AI security roles created when ownership is split without design.
/pains/ai-security-role-frankenstein
CISO Persona
Security leader persona for AI governance, evidence, and operating-model decisions.
/personas/ciso-ai-governance
Concepts and Frameworks
Named models, methods, principles, taxonomies, and durable operating frameworks.
/research/concepts
Enterprise AI Procurement Pain
Buyer friction caused by weak governance evidence, data handling detail, and logging evidence.
/pains/enterprise-ai-procurement
Enterprise AI Readiness Brief
Buyer-facing brief for enterprise AI security questions and evidence.
/briefs/enterprise-ai-readiness-brief
Executive Persona
AI SaaS founder persona focused on enterprise readiness, procurement friction, and buyer evidence.
/personas/founder-enterprise-ai-saas
Governance Evidence Gap
Policy language without durable evidence that AI systems are controlled and monitored.
/pains/governance-evidence-gap
Governance Without Controls
Governance language without intake, owners, gates, evidence, or monitoring.
/failure-modes/governance-without-controls
Procurement Buyer Persona
Enterprise AI buyer persona focused on evidence, governance evidence, and trust posture.
/personas/enterprise-ai-procurement-buyer
Product Security Persona
Product security leader persona for AI launches, review gates, and evidence packs.
/personas/product-security-leader-ai
Prompt Injection Paths
Prompt injection that crosses trust boundaries into retrieval, tools, and privileged context.
/failure-modes/prompt-injection-paths
RAG Data Leakage
Retrieval systems exposing sensitive information through authorization or context failures.
/pains/rag-data-leakage
Retrieval Poisoning
Hostile or stale retrieved content influencing model behavior as trusted ground truth.
/failure-modes/retrieval-poisoning
Secure AI Product Launch Brief
Launch-readiness brief for customer-facing AI features and real review cycles.
/briefs/secure-ai-product-launch-brief
Unsafe Agent Permissions
Agentic risk created when tools, approvals, or state changes are not bounded.
/pains/unsafe-agent-permissions
Unsafe Tool Escalation
Delegated action that can move from suggestion to action without real control.
/failure-modes/unsafe-tool-escalation
Research Paper Index
AI-security research papers connected to concepts, findings, tools, and institutional signals.
/research/papers
Adversarial Hubness Detector
AI security tool for rag & appsec scanners.
rag-securityai-application-security
/tools/adversarial-hubness-detector
Adversarial-VQA
AI security tool for benchmarks for security & safety.
evaluation-benchmarkingresearch-education
/tools/adversarial-vqa
Agent-BOM
AI security tool for ai supply chain security.
model-supply-chainsecure-ai-sdlc
/tools/agent-bom
Agentic Radar
AI security tool for agentic & mcp security.
agent-securityai-application-security
/tools/agentic-radar
Agentic Security
AI security tool for agentic & mcp security.
agent-securityai-application-security
/tools/agentic-security
AgentOps
AI security tool for llm evaluation & tracing.
evaluation-benchmarkingai-observability
/tools/agentops
AI Fairness 360 (AIF360)
AI security tool for bias, fairness & accountability.
ai-governance-risk-complianceresearch-education
/tools/ai-fairness-360-aif360
ai-bom (Trusera)
AI security tool for ai asset management & inventory.
ai-governance-risk-compliancemodel-supply-chain
/tools/ai-bom-trusera
AI-Governance-Starter-Pack
AI security tool for ai grc & policy-as-code (compliance).
ai-governance-risk-compliancepolicy-enforcement
/tools/ai-governance-starter-pack
AI4DigitalForensics
AI security tool for ai forensics & incident response.
ai-incident-responsethreat-intelligence
/tools/ai4digitalforensics
AIGovHub
AI security tool for ai grc & policy-as-code (compliance).
ai-governance-risk-compliancepolicy-enforcement
/tools/aigovhub
AIGuard
AI security tool for guardrail frameworks (runtime protection).
llm-securitypolicy-enforcement
/tools/aiguard
AIR Blackbox
AI security tool for ai grc & policy-as-code (compliance).
ai-governance-risk-compliancepolicy-enforcement
/tools/air-blackbox
AIsbom
AI security tool for ai asset management & inventory.
ai-governance-risk-compliancemodel-supply-chain
/tools/aisbom
alpha-beta-CROWN
AI security tool for formal verification & robustness.
model-securityevaluation-benchmarking
/tools/alpha-beta-crown
Arize Phoenix
Open-source observability and evaluation tool for LLM, RAG, and machine learning systems.
ai-observabilityrag-securityevaluation-benchmarkingai-observability-platform
/tools/arize-phoenix
AugLy (Meta)
AI security tool for multimodal & safety test suites.
ai-red-teamingevaluation-benchmarking
/tools/augly-meta
Awesome AI Guardrails
AI security tool for curated "awesome" lists (aggregators).
research-educationthreat-intelligence
/tools/awesome-ai-guardrails
Awesome AI Security
AI security tool for curated "awesome" lists (aggregators).
research-educationthreat-intelligence
/tools/awesome-ai-security
Awesome LLM Security
AI security tool for curated "awesome" lists (aggregators).
research-educationthreat-intelligence
/tools/awesome-llm-security
Awesome MPC
AI security tool for curated "awesome" lists (aggregators).
research-educationthreat-intelligence
/tools/awesome-mpc
Awesome Prompt Injection
AI security tool for curated "awesome" lists (aggregators).
research-educationthreat-intelligence
/tools/awesome-prompt-injection
BackdoorLLM
AI security tool for data poisoning & model theft defense.
model-securityllm-security
/tools/backdoorllm
BlackIce
AI security tool for red teaming & vulnerability scanning.
ai-red-teamingevaluation-benchmarking
/tools/blackice
CalypsoAI Platform
Commercial AI security and governance platform for enterprise generative AI usage.
ai-governance-risk-compliancellm-securitypolicy-enforcementai-governance-platform
/tools/calypsoai-platform
Cisco AI BOM
AI security tool for ai asset management & inventory.
ai-governance-risk-compliancemodel-supply-chain
/tools/cisco-ai-bom
CleverHans
AI security tool for red teaming & vulnerability scanning.
ai-red-teamingevaluation-benchmarking
/tools/cleverhans
COMPL-AI
AI security tool for ai grc & policy-as-code (compliance).
ai-governance-risk-compliancepolicy-enforcement
/tools/compl-ai
Concrete-ML
AI security tool for federated learning & privacy-preserving ai.
data-security-privacyresearch-education
/tools/concrete-ml
Confidential Containers
AI security tool for 🖥️ confidential computing & tees.
llm-security
/tools/confidential-containers
Counterfit (Microsoft)
AI security tool for red teaming & vulnerability scanning.
ai-red-teamingevaluation-benchmarking
/tools/counterfit-microsoft
CrypTen (Meta Research)
AI security tool for secure multi-party computation (smpc) & private ai.
data-security-privacyresearch-education
/tools/crypten-meta-research
Dataset Index
Canonical datasets behind the State 2026 registry, with provenance and cutoffs.
/research/data
DecodingTrust
AI security tool for multimodal & safety test suites.
ai-red-teamingevaluation-benchmarking
/tools/decodingtrust
Deep Model Watermarking
AI security tool for model watermarking & ip protection.
model-securitymodel-supply-chain
/tools/deep-model-watermarking
DeepEval
AI security tool for llm evaluation & tracing.
evaluation-benchmarkingai-observability
/tools/deepeval
dstack
AI security tool for hardware & gpu security.
model-supply-chaincloud-ai-security
/tools/dstack
DVC
AI security tool for ai asset management & inventory.
ai-governance-risk-compliancemodel-supply-chain
/tools/dvc
Enarx
AI security tool for 🖥️ confidential computing & tees.
llm-security
/tools/enarx
ERAN
AI security tool for formal verification & robustness.
model-securityevaluation-benchmarking
/tools/eran
Ethos
AI security tool for bias, fairness & accountability.
ai-governance-risk-complianceresearch-education
/tools/ethos
EU-Compliance-Bridge
AI security tool for ai grc & policy-as-code (compliance).
ai-governance-risk-compliancepolicy-enforcement
/tools/eu-compliance-bridge
Evidently AI
AI security tool for model observability & monitoring.
ai-observabilityai-application-security
/tools/evidently-ai
Fairlearn
AI security tool for bias, fairness & accountability.
ai-governance-risk-complianceresearch-education
/tools/fairlearn
Fairness Indicators
AI security tool for bias, fairness & accountability.
ai-governance-risk-complianceresearch-education
/tools/fairness-indicators
FATE
AI security tool for federated learning & privacy-preserving ai.
data-security-privacyresearch-education
/tools/fate
FedML
AI security tool for federated learning & privacy-preserving ai.
data-security-privacyresearch-education
/tools/fedml
Fickling (Trail of Bits)
AI security tool for ai supply chain security.
model-supply-chainsecure-ai-sdlc
/tools/fickling-trail-of-bits
Flower
AI security tool for secure multi-party computation (smpc) & private ai.
data-security-privacyresearch-education
/tools/flower
FVEval
AI security tool for hardware & gpu security.
model-supply-chaincloud-ai-security
/tools/fveval
garak
Open-source LLM vulnerability scanner for probing models and applications with adversarial tests.
llm-securityai-red-teamingevaluation-benchmarkingprompt-injection-tester
/tools/garak
Giskard
AI security tool for red teaming & vulnerability scanning.
ai-red-teamingevaluation-benchmarking
/tools/giskard
Google Differential Privacy
AI security tool for differential privacy.
data-security-privacyresearch-education
/tools/google-differential-privacy
GPU.zip
AI security tool for hardware & gpu security.
model-supply-chaincloud-ai-security
/tools/gpuzip
Gramine
AI security tool for 🖥️ confidential computing & tees.
llm-security
/tools/gramine
Guardrails AI
Framework for validating, constraining, and monitoring LLM inputs and outputs.
llm-securitypolicy-enforcementdeveloper-securityguardrails-framework
/tools/guardrails-ai
HaluEval
AI security tool for benchmarks for security & safety.
evaluation-benchmarkingresearch-education
/tools/halueval
HarmBench
AI security tool for benchmarks for security & safety.
evaluation-benchmarkingresearch-education
/tools/harmbench
HiddenLayer AISec
Security platform for protecting AI models from adversarial attacks and theft.
model-securityai-incident-responsecommercial-product
/tools/hiddenlayer-aisec
HiddenLayer Platform
Commercial AI security platform focused on model threat detection and AI system protection.
model-securityai-incident-responsemodel-supply-chainmodel-scanner
/tools/hiddenlayer-platform
Inspect (UK AI Safety Institute)
AI security tool for red teaming & vulnerability scanning.
ai-red-teamingevaluation-benchmarking
/tools/inspect-uk-ai-safety-institute
JailbreakBench
AI security tool for multimodal & safety test suites.
ai-red-teamingevaluation-benchmarking
/tools/jailbreakbench
JAX Privacy
AI security tool for differential privacy.
data-security-privacyresearch-education
/tools/jax-privacy
Keystone
AI security tool for 🖥️ confidential computing & tees.
llm-security
/tools/keystone
KitOp
AI security tool for ai supply chain security.
model-supply-chainsecure-ai-sdlc
/tools/kitop
Lakera Guard
Enterprise-grade protection against prompt injections, PII leakage, and other LLM vulnerabilities.
llm-securitydata-security-privacycommercial-product
/tools/lakera-guard
LangChain
Framework for developing applications powered by large language models (LLMs).
ai-application-securityagent-securityopen-source-project
/tools/langchain
Langfuse
Open-source LLM observability platform useful for traces, evaluation, debugging, and AI incident evidence.
ai-observabilitysecure-ai-sdlcai-incident-responseai-observability-platform
/tools/langfuse
LangKit
AI security tool for llm evaluation & tracing.
evaluation-benchmarkingai-observability
/tools/langkit
LangKit (WhyLabs)
AI security tool for model observability & monitoring.
ai-observabilityai-application-security
/tools/langkit-whylabs
LangSmith
Commercial observability and evaluation platform for LLM applications.
ai-observabilityevaluation-benchmarkingsecure-ai-sdlcai-observability-platform
/tools/langsmith
Langtrace
AI security tool for model observability & monitoring.
ai-observabilityai-application-security
/tools/langtrace
Llama Guard (Meta)
AI security tool for guardrail frameworks (runtime protection).
llm-securitypolicy-enforcement
/tools/llama-guard-meta
LlamaIndex
Data framework for LLM applications to connect custom data sources.
rag-securitydata-security-privacyopen-source-project
/tools/llamaindex
LLM Fuzzer
AI security tool for red teaming & vulnerability scanning.
ai-red-teamingevaluation-benchmarking
/tools/llm-fuzzer
LLM Guard
Open-source security toolkit for sanitizing and validating LLM inputs and outputs.
llm-securitydata-security-privacypolicy-enforcementguardrails-framework
/tools/llm-guard
LLM Guard (Protect AI)
AI security tool for guardrail frameworks (runtime protection).
llm-securitypolicy-enforcement
/tools/llm-guard-protect-ai
Marabou
AI security tool for formal verification & robustness.
model-securityevaluation-benchmarking
/tools/marabou
MarbleRun
AI security tool for 🖥️ confidential computing & tees.
llm-security
/tools/marblerun
MCP Forensic Toolkit
AI security tool for ai forensics & incident response.
ai-incident-responsethreat-intelligence
/tools/mcp-forensic-toolkit
MCP Security Checklist
AI security tool for agentic & mcp security.
agent-securityai-application-security
/tools/mcp-security-checklist
Microsoft Agent Governance Toolkit
AI security tool for ai grc & policy-as-code (compliance).
ai-governance-risk-compliancepolicy-enforcement
/tools/microsoft-agent-governance-toolkit
MIPSEval
AI security tool for llm evaluation & tracing.
evaluation-benchmarkingai-observability
/tools/mipseval
MITRE ATLAS
Knowledge base of adversarial tactics and techniques against AI-enabled systems.
threat-intelligenceai-red-teamingai-governance-risk-compliancethreat-modeling-tool
/tools/mitre-atlas
ML Model Watermarking
AI security tool for model watermarking & ip protection.
model-securitymodel-supply-chain
/tools/ml-model-watermarking
MLflow Registry
AI security tool for ai asset management & inventory.
ai-governance-risk-compliancemodel-supply-chain
/tools/mlflow-registry
Model Provenance Kit (Cisco)
AI security tool for ai supply chain security.
model-supply-chainsecure-ai-sdlc
/tools/model-provenance-kit-cisco
Model Stealing Defenses
AI security tool for data poisoning & model theft defense.
model-securityllm-security
/tools/model-stealing-defenses
ModelScan
Open-source model scanning tool for detecting unsafe model serialization and artifact risks.
model-securitymodel-supply-chaindeveloper-securitymodel-scanner
/tools/modelscan
ModelScan
Protection against insecure AI models by scanning for serialized model files that execute arbitrary code.
model-securitymodel-supply-chainopen-source-project
/tools/protect-ai-modelscan
ModelScan (Protect AI)
AI security tool for ai supply chain security.
model-supply-chainsecure-ai-sdlc
/tools/modelscan-protect-ai
MP-SPDZ
AI security tool for secure multi-party computation (smpc) & private ai.
data-security-privacyresearch-education
/tools/mp-spdz
Multimodal Safety Test Suite
AI security tool for multimodal & safety test suites.
ai-red-teamingevaluation-benchmarking
/tools/multimodal-safety-test-suite
NeMo Evaluator
Evaluation tooling for generative AI models and systems in NVIDIA AI workflows.
evaluation-benchmarkingmodel-securityresearch-educationeval-orchestration-framework
/tools/nvidia-nemo-evaluator
NeMo Guardrails
Open-source toolkit for easily adding programmable guardrails to LLM-based conversational systems.
llm-securityai-application-securityopen-source-project
/tools/nemo-guardrails
NNV (Neural Network Verification)
AI security tool for formal verification & robustness.
model-securityevaluation-benchmarking
/tools/nnv-neural-network-verification
NVIDIA NeMo-Guardrails
AI security tool for guardrail frameworks (runtime protection).
llm-securitypolicy-enforcement
/tools/nvidia-nemo-guardrails
Open Policy Agent
General-purpose policy engine increasingly relevant to AI gateway, agent, and SDLC policy enforcement.
policy-enforcementsecure-ai-sdlcidentity-access-controlpolicy-as-code-engine
/tools/open-policy-agent
OpenAI Evals
Open-source evaluation framework for testing language model behavior.
evaluation-benchmarkingllm-securityresearch-educationeval-orchestration-framework
/tools/openai-evals
OpenDP
AI security tool for differential privacy.
data-security-privacyresearch-education
/tools/opendp
OpenFL
AI security tool for federated learning & privacy-preserving ai.
data-security-privacyresearch-education
/tools/openfl
OpenMined / PySyft
AI security tool for federated learning & privacy-preserving ai.
data-security-privacyresearch-education
/tools/openmined-pysyft
OpenTPU
AI security tool for hardware & gpu security.
model-supply-chaincloud-ai-security
/tools/opentpu
PhantomWall
AI security tool for guardrail frameworks (runtime protection).
llm-securitypolicy-enforcement
/tools/phantomwall
Phoenix (Arize AI)
AI security tool for model observability & monitoring.
ai-observabilityai-application-security
/tools/phoenix-arize-ai
PipeLock
AI security tool for agentic & mcp security.
agent-securityai-application-security
/tools/pipelock
PoisonedRAG Defense
AI security tool for data poisoning & model theft defense.
model-securityllm-security
/tools/poisonedrag-defense
PRADA
AI security tool for data poisoning & model theft defense.
model-securityllm-security
/tools/prada
Project AIR
AI security tool for ai forensics & incident response.
ai-incident-responsethreat-intelligence
/tools/project-air
promptfoo
Developer-focused LLM evaluation and red-team testing framework for prompts and applications.
evaluation-benchmarkingllm-securitysecure-ai-sdlceval-orchestration-framework
/tools/promptfoo
PromptLint
AI security tool for prompt engineering & template security.
llm-securitydeveloper-security
/tools/promptlint
PromptLinter
AI security tool for prompt engineering & template security.
llm-securitydeveloper-security
/tools/promptlinter
PromptPwnd
AI security tool for prompt engineering & template security.
llm-securitydeveloper-security
/tools/promptpwnd
Protect AI Platform
Commercial AI and ML security platform focused on model supply chain, scanning, and governance.
model-supply-chainmodel-securityai-governance-risk-compliancemodel-scanner
/tools/protect-ai-platform
Purple Llama (Meta)
AI security tool for red teaming & vulnerability scanning.
ai-red-teamingevaluation-benchmarking
/tools/purple-llama-meta
PyDP
AI security tool for differential privacy.
data-security-privacyresearch-education
/tools/pydp
PyRIT
Python Risk Identification Tool for generative AI (PyRIT) for red teaming.
ai-red-teamingevaluation-benchmarkingopen-source-project
/tools/microsoft-pyrit
PyRIT
Open-source Python Risk Identification Toolkit for generative AI red teaming.
ai-red-teamingllm-securityevaluation-benchmarkingai-red-team-platform
/tools/pyrit
PyRIT (Microsoft)
AI security tool for red teaming & vulnerability scanning.
ai-red-teamingevaluation-benchmarking
/tools/pyrit-microsoft
PySyft (OpenMined)
AI security tool for secure multi-party computation (smpc) & private ai.
data-security-privacyresearch-education
/tools/pysyft-openmined
RAG Security Scanner
AI security tool for rag & appsec scanners.
rag-securityai-application-security
/tools/rag-security-scanner
RAGAS
AI security tool for rag & appsec scanners.
rag-securityai-application-security
/tools/ragas
RAGLeakLab
AI security tool for rag & appsec scanners.
rag-securityai-application-security
/tools/ragleaklab
Rebuff
Self-hosted or managed API to detect and prevent prompt injection attacks.
ai-application-securityllm-securityopen-source-projectmanaged-service
/tools/rebuff
Research Methodology
The annual report is a frozen editorial snapshot of continuous research.
/research/methodology
RobustBench
AI security tool for formal verification & robustness.
model-securityevaluation-benchmarking
/tools/robustbench
SCAAML (Google)
AI security tool for hardware & gpu security.
model-supply-chaincloud-ai-security
/tools/scaaml-google
SecEng Adversarial Range
Comprehensive scenario library for AI red-team engagements.
ai-red-teamingevaluation-benchmarkingai-red-team-platformjailbreak-tester
/tools/adversarial-range
SecEng Artifact Analyzer
Forensics and capability extraction for AI models and binaries.
model-securitythreat-intelligencemodel-scanner
/tools/artifact-analyzer
SecEng Surface Scanner
Browser, repo, and IDE discovery for AI assets and shadow AI.
ai-asset-management-&-inventoryai-vendor-riskvulnerability-discovery-tool
/tools/surface-scanner
SecEng Threat Canvas
DFD-style AI threat modeling and trust-boundary mapping instrument.
ai-application-securityllm-securitythreat-modeling-tool
/tools/threat-canvas
Secure Diffusion Watermarking Survey
AI security tool for model watermarking & ip protection.
model-securitymodel-supply-chain
/tools/secure-diffusion-watermarking-survey
Skill-Scanner
AI security tool for agentic & mcp security.
agent-securityai-application-security
/tools/skill-scanner
StrongREJECT
AI security tool for benchmarks for security & safety.
evaluation-benchmarkingresearch-education
/tools/strongreject
Systima Comply
AI security tool for ai grc & policy-as-code (compliance).
ai-governance-risk-compliancepolicy-enforcement
/tools/systima-comply
TensorFlow Privacy
AI security tool for differential privacy.
data-security-privacyresearch-education
/tools/tensorflow-privacy
TF Encrypted
AI security tool for secure multi-party computation (smpc) & private ai.
data-security-privacyresearch-education
/tools/tf-encrypted
Themis-ml
AI security tool for bias, fairness & accountability.
ai-governance-risk-complianceresearch-education
/tools/themis-ml
ThinkWatch
AI security tool for agentic & mcp security.
agent-securityai-application-security
/tools/thinkwatch
TruLens
Open-source evaluation and tracking toolkit for LLM and RAG application quality.
evaluation-benchmarkingrag-securityai-observabilityeval-orchestration-framework
/tools/trulens
TruthfulQA
AI security tool for benchmarks for security & safety.
evaluation-benchmarkingresearch-education
/tools/truthfulqa
Unfold
AI security tool for ai forensics & incident response.
ai-incident-responsethreat-intelligence
/tools/unfold
UnMarker
AI security tool for model watermarking & ip protection.
model-securitymodel-supply-chain
/tools/unmarker
UpTrain
AI security tool for llm evaluation & tracing.
evaluation-benchmarkingai-observability
/tools/uptrain
Venturalitica SDK
AI security tool for ai grc & policy-as-code (compliance).
ai-governance-risk-compliancepolicy-enforcement
/tools/venturalitica-sdk
VerifyWise
AI security tool for ai grc & policy-as-code (compliance).
ai-governance-risk-compliancepolicy-enforcement
/tools/verifywise
Veritensor
AI security tool for rag & appsec scanners.
rag-securityai-application-security
/tools/veritensor
Vigil LLM
AI security tool for guardrail frameworks (runtime protection).
llm-securitypolicy-enforcement
/tools/vigil-llm
VirusInfectionAttack
AI security tool for data poisoning & model theft defense.
model-securityllm-security
/tools/virusinfectionattack
What-If Tool
AI security tool for bias, fairness & accountability.
ai-governance-risk-complianceresearch-education
/tools/what-if-tool
zk-Autograd
AI security tool for ai supply chain security.
model-supply-chainsecure-ai-sdlc
/tools/zk-autograd
Signals
Live and time-boxed observations feeding the canonical registry.
/research/signals
Academic
/signals/academicapp/(public)/signals/academic/page.tsx
AI Security Tools Directory
/toolsapp/(public)/tools/page.tsx
Books
/research/booksapp/(public)/research/books/page.tsx
Brand Voice Checker
/tools/brand-voice-checkerapp/(public)/tools/brand-voice-checker/page.tsx
Concept Maturity
/signals/concept-maturityapp/(public)/signals/concept-maturity/page.tsx
Controls Crosswalk
/signals/controls-crosswalkapp/(public)/signals/controls-crosswalk/page.tsx
Convergence
/signals/convergenceapp/(public)/signals/convergence/page.tsx
Deliverables
/deliverablesapp/(public)/deliverables/page.tsx
Media
/signals/mediaapp/(public)/signals/media/page.tsx
Open Source Velocity — The State of AI Security…
Where the builder ecosystem is allocating attention: repo growth, contributor density, and event activity across AI security domains.
/signals/open-sourceapp/(public)/signals/open-source/page.tsx
Signals
/signalsapp/(public)/signals/page.tsx
Survey
/research/surveyapp/(public)/research/survey/page.tsx
Vulnerabilities
/signals/vulnerabilitiesapp/(public)/signals/vulnerabilities/page.tsx
Adversarial Testing Workflow
Attack testing moves from scoped hypotheses through controlled execution and evidence capture to qualified findings.
attackprocess-railTesting workflowSafety and evidence controls
/publication-dsl/figures/ATT-03
AI Red Team Scope
AI red teaming should state which prompt, retrieval, tool, agent, authority, multimodal, and workflow surfaces are actually tested.
red-teamcoverage-matrixAttack surfacesTesting activities
/publication-dsl/figures/RED-01
AI Scanner and Conventional AppSec
AI-native analysis extends conventional code scanning by following prompts, retrieval, tools, agents, and authority through application logic.
scannercomparisonConventional AppSec coverageAI-native extension
/publication-dsl/figures/SCN-04
AI-Native Scanner Coverage
The scanner evaluates AI-specific code and workflow surfaces that conventional AppSec categories do not fully describe.
scannercoverage-matrixAI security surfacesAnalysis stages
/publication-dsl/figures/SCN-01
Analyst-Reviewed Path
A proposed path becomes publishable only after evidence challenge, correction, and explicit analyst review.
apcgrounding-boundaryProposed pathGrounded core
/publication-dsl/figures/APC-07
APC Result Contract
The path engine returns clusters, chokepoints, evidence links, residual state, and retest-ready outputs.
apctransformation-enginePath evidenceQualification and control analysis
/publication-dsl/figures/APC-06
APC Validation Pipeline
Independent validators challenge evidence, ordering, consequence, and alternative explanations before a path is accepted.
apcgoverned-lifecycleValidation pipelineValidation controls
/publication-dsl/figures/APC-05
APC-Backed Review Uplift
A path-qualified review adds evidence, sequencing, shared weaknesses, and remediation leverage to an ordinary finding set.
apc-reviewcomparisonFinding setAPC-backed review
/publication-dsl/figures/APCS-01
Artifact Analyzer Overview
The analyzer turns code, binaries, browser artifacts, and protocol surfaces into structured capability and authority context.
artifact-analyzertransformation-engineImplementation artifactsArtifact analysis
/publication-dsl/figures/ART-01
Artifact Evidence Outputs
The analyzer returns structured findings, extracted metadata, authority context, and evidence references for downstream review.
artifact-analyzerartifact-stackExtraction evidenceCapability and authority context
/publication-dsl/figures/ART-03
Artifact to Authority Context
Raw implementation artifacts become more useful when their exposed capabilities, identities, permissions, and sinks are made explicit.
artifact-analyzercomparisonRaw artifactStructured authority context
/publication-dsl/figures/ART-02
Attack Engine and Evidence Plane
The partner keeps attack generation and operator workflow while SecEng adds context, qualification, evidence, and defensible return objects.
offensive-platformscomparisonPartner attack engineSecEng context and evidence plane
/publication-dsl/figures/OP-04
Attack-to-Defend Handoff
Qualified paths become prioritized control opportunities, remediation hypotheses, and retest plans.
attacktransformation-engineQualified attack resultsControl analysis
/publication-dsl/figures/ATT-05
Authority Graph Overview
The authority graph models which identities and agents can invoke which tools, data, approvals, and consequential actions.
authority-graphtopology-mapActors and identitiesPermissions and approvals
/publication-dsl/figures/AUTH-01
Authority to Control Chokepoint
A small change to permission, approval, or action scope can break several unsafe authority paths.
authority-graphchokepointUnsafe authority pathsShared authority weakness
/publication-dsl/figures/AUTH-03
Black-Box to Gray-Box Uplift
System context turns observed behavior into better-qualified risk without replacing the partner or operator attack engine.
attackcomparisonBlack-box observationGray-box context
/publication-dsl/figures/ATT-04
Break the Chain
The highest-value control is often the chokepoint that disrupts several plausible attack paths at once.
defendchokepointQualified pathsShared weakness
/publication-dsl/figures/DEF-02
Break the chain.
Multiple attack paths may converge on a small number of authority, approval, or tool-access weaknesses that offer better remediation leverage than fixing…
apc-throughlinechokepointObserved attack pathsShared weaknesses
/publication-dsl/figures/APC-02
Buyer Offer Map
The marketplace organizes products, services, licensing, and partner offers by the buyer problem they solve.
marketplaceecosystem-mapBuyer problemProducts
/publication-dsl/figures/MKT-04
Canonical contracts between heterogeneous systems.
Canonical objects isolate security and learning semantics from any one vendor transport, endpoint, or proprietary data model.
interoperabilitytransformation-enginePartner-native objectsCanonical SecEng contracts
/publication-dsl/figures/INT-01
Chokepoint Remediation Plan
The review prioritizes controls that interrupt several qualified paths while preserving residual-risk visibility.
apc-reviewchokepointQualified path setShared weakness
/publication-dsl/figures/APCS-03
Choose the brand and product-control model.
The licensing spectrum ranges from SecEng-branded delivery through co-branding and private label to a deeply partner-branded white-label experience.
brand-licensingbranding-spectrumBrand and control spectrumControl dimensions
/publication-dsl/figures/BL-01
Choose the capability layer.
Partners can embed one bounded SecEng capability or combine a controlled module set without adopting the entire SecEng interface.
oemcapability-planePartner needSecEng OEM engine
/publication-dsl/figures/OEM-01
Choose the partner motion.
The right program depends on who owns the product and who owns the customer and delivery.
partners-hubquadrant-matrixDeliverEmbed
/publication-dsl/figures/HUB-02
Claim State Boundary
Observed, reproduced, grounded, inferred, rejected, and analyst-reviewed claims must remain visibly distinct.
evidencegrounding-boundarySource evidenceSupported claim
/publication-dsl/figures/EVD-03
Commercial Path Overview
A partner engagement moves from motion selection and representative proof through commercial fit, integration, launch, and expansion.
partners-hubprocess-railPartner pathProgram controls
/publication-dsl/figures/HUB-05
Consulting partner delivery model.
The consulting partner owns advisory context, stakeholder management, and implementation while SecEng supplies repeatable technical workflows, evidence, and…
consultingoperating-modelConsulting partner ownsSecEng supplies
/publication-dsl/figures/CON-01
Consulting-to-Product Handoff
A consulting engagement should leave reusable tests, evidence, controls, and productized capability rather than only a static report.
consultingtransformation-engineEngagement outputsProductization handoff
/publication-dsl/figures/CON-04
Course Packaging Engine
Canonical curriculum can compile into partner-ready modules, assessments, lab assets, and reporting packages without duplicating source content.
academytransformation-engineCanonical learning sourcePackaging and validation
/publication-dsl/figures/AC-04
Cross-Product Evidence Contract
Shared evidence and lifecycle states allow scanner, range, graph, APC, and reporting capabilities to exchange results without losing provenance.
workbenchintegration-round-tripCapability outputShared evidence contract
/publication-dsl/figures/PROD-02
Deployment Control Spectrum
Hosted, local-worker, sidecar, and air-gapped models trade operating simplicity for customer control and isolation.
enterpriseordered-spectrumDeployment modelsDecision dimensions
/publication-dsl/figures/ENT-02
Discover, map, validate, and publish an integration.
A technology integration should progress from capability discovery through schema mapping and fixture validation to a supported published status.
technology-partnersgoverned-lifecycleIntegration lifecycleValidation exceptions
/publication-dsl/figures/TECH-02
Enterprise Evidence Package
Enterprise delivery should preserve machine-readable findings, retest records, control evidence, and executive reporting in one traceable stack.
enterpriseartifact-stackTechnical evidenceFindings and paths
/publication-dsl/figures/ENT-03
Enterprise Operating Model
AppSec, platform, product, data, governance, and engineering teams need explicit ownership across the AI security lifecycle.
enterpriseoperating-modelAppSec and SecurityAI and Platform
/publication-dsl/figures/ENT-01
Evaluation-to-Regression Lifecycle
An observed failure becomes durable security capability when it is converted into a replayable regression fixture.
adversarial-rangegoverned-lifecycleEvaluation lifecycle
/publication-dsl/figures/RANGE-02
Evidence Lifecycle
Evidence moves from observation through validation, remediation, retest, and controlled reuse without losing claim state.
evidencegoverned-lifecycleEvidence lifecycleLifecycle controls
/publication-dsl/figures/EVD-02
Evidence Readiness Boundary
A useful map separates observed relationships from inferred connections and explicitly exposes evidence gaps.
mapgrounding-boundaryObserved system evidenceGrounded map
/publication-dsl/figures/MAP-03
Evidence-to-Decision Stack
Executive conclusions remain trustworthy only when they stay traceable to technical evidence and replayable proof.
evidenceartifact-stackObserved and reproduced evidenceStructured findings and paths
/publication-dsl/figures/EVD-04
Fix, Retest, Prove
A remediation is not complete until the control change is retested and the resulting evidence closes or updates the finding.
defendgoverned-lifecycleRemediation lifecycleGoverned outcome
/publication-dsl/figures/DEF-04
From assessment through remediation and retest.
A consulting engagement should connect discovery, evidence, findings, recommendations, implementation, retest, and residual risk rather than ending at report…
consultinggoverned-lifecycleEngagement lifecycleEngagement exceptions
/publication-dsl/figures/CON-02
From attack result to qualified path.
A successful attack or trace is not automatically a defensible multi-step path; context, grounding, validation, and review must remain explicit.
offensive-platformsgoverned-lifecyclePath qualification lifecycleException paths
/publication-dsl/figures/OP-02
From branded pilot to partner-operated offer.
Branding is only one part of launch; the operating path also needs tenant provisioning, offer configuration, acceptance, support, upgrades, and commercial…
brand-licensinggoverned-lifecycleLaunch lifecycleLaunch exceptions
/publication-dsl/figures/BL-03
From candidate to defensible finding.
Detection is only the beginning; evidence, validation, review, and claim status determine whether a result is reportable.
scanner-providersgoverned-lifecyclePrimary finding lifecycleException paths
/publication-dsl/figures/SP-02
From completion to defensible readiness claim.
Course completion, lab activity, and self-reporting become readiness evidence only after mapping, scoring, validation, and claim controls.
workforce-readinessgoverned-lifecycleReadiness evidence lifecycleException paths
/publication-dsl/figures/WR-02
From customer onboarding to recurring assurance.
A managed service becomes scalable when scope, evidence, decisions, remediation, retest, and renewal are handled as a repeatable lifecycle.
msspgoverned-lifecycleRecurring service lifecycleService decision paths
/publication-dsl/figures/MS-02
From evaluation package to production OEM.
The path to production proves integration, evidence quality, deployment fit, entitlement, support, and a credible commercial operating model.
oempilot-contractEvaluationPilot and productization
/publication-dsl/figures/OEM-03
From findings to Throughline.
Throughline combines fragmented security observations with system, identity, and authority context to construct evidence-qualified paths and structured…
apc-throughlinetransformation-engineIsolated observationsThroughline engine
/publication-dsl/figures/APC-03
From first conversation to a supported partner motion.
Every partner path begins with fit and a representative object, then advances through proof, operating-model design, launch, and support.
partners-hubprocess-railEngagement ladderPartner resources
/publication-dsl/figures/HUB-03
From headless engine to partner-native product.
A bounded input invokes a headless SecEng capability and returns a structured object that fits the partner data model, lifecycle, and interface.
oemtransformation-engineBounded partner inputHeadless SecEng capability
/publication-dsl/figures/OEM-02
From Isolated Finding to Defensible Path
A defensible attack path connects observed steps, evidence, and consequences rather than merely grouping nearby findings.
attackcomparisonIsolated findingDefensible path
/publication-dsl/figures/ATT-02
From lead registration through renewal.
A repeatable channel motion needs lead ownership, qualification, technical proof, commercial coordination, delivery handoff, support, and renewal rules.
resellersgoverned-lifecycleChannel lifecycleChannel exceptions
/publication-dsl/figures/RS-02
From partner capability to transactable listing.
A marketplace offer moves through packaging, validation, listing, discovery, commercial action, provisioning, and delivery.
marketplaceprocess-railMarketplace listing lifecycleListing proof points
/publication-dsl/figures/MKT-01
From source material to published learning product.
A reusable learning offer needs editorial review, instructional packaging, standards validation, platform testing, publication controls, and versioned updates.
academygoverned-lifecycleContent publishing lifecyclePublishing exceptions
/publication-dsl/figures/AC-02
Generic Bridge and Native Adapter
A generic exchange proves interoperability; a native adapter preserves richer partner concepts, workflow state, and user experience.
scanner-providerscomparisonGeneric bridgeNative adapter
/publication-dsl/figures/SP-05
Grounded core and explicit inference.
Throughline separates what the evidence directly supports from what remains a speculative extension requiring validation or analyst review.
apc-throughlinegrounding-boundaryObserved evidenceGrounded path
/publication-dsl/figures/APC-01
Human-Guided and Autonomous Modes
Analyst-guided, model-guided, and replay-driven testing serve different purposes and require different controls.
adversarial-rangequadrant-matrixAnalyst-guided explorationModel-guided execution
/publication-dsl/figures/RANGE-03
Integration Family Map
Technology partnerships span data sources, scanners, offensive platforms, identity systems, workflow tools, and evidence consumers.
technologyradial-hubSecEng interoperability coreData and telemetry
/publication-dsl/figures/TECH-04
Interoperability Maturity Ladder
Integration maturity progresses from file exchange to structured contracts, native round trips, and embedded workflow state.
interoperabilityordered-spectrumInteroperability maturityWhat matures
/publication-dsl/figures/INT-04
Inventory and Trace Workflow
Mapping progresses from intake through architecture capture and trace review to a reviewable security model.
mapprocess-railMapping workflowWorkflow controls
/publication-dsl/figures/MAP-05
Keep the attack engine. Add the context and evidence plane.
The offensive platform retains attack generation and orchestration while SecEng adds system context, authority reasoning, evidence qualification, and…
offensive-platformscapability-planePartner attack platformSecEng context and evidence plane
/publication-dsl/figures/OP-01
Keep the attack engine. Add the context and evidence plane.
The offensive platform continues generating and chaining attacks while SecEng adds system context, evidence qualification, remediation chokepoints, and…
vernocapability-planeExisting offensive platformSecEng context and evidence plane
/publication-dsl/figures/V-01
Keep the client relationship. Add the AI product-security…
The MSSP owns the service, account, and operating model while SecEng adds repeatable technical workflows, evidence discipline, and productized delivery assets.
msspcapability-planeMSSP service operationSecEng delivery layer
/publication-dsl/figures/MS-01
Keep the learning platform. Add the readiness and evidence…
The partner continues delivering learning experiences while SecEng adds role models, assessments, evidence-backed scoring, and workforce reporting.
workforce-readinesscapability-planePartner learning platformSecEng readiness suite
/publication-dsl/figures/WR-01
Keep the LMS and marketplace. Add the AI security content…
Learning platforms, course marketplaces, and enterprise training programs keep their delivery experience while SecEng supplies structured, standards-ready AI…
academycapability-planeDelivery channel: LMS or marketplaceSecEng content and packaging
/publication-dsl/figures/AC-01
Keep the scanner. Add the finding and evidence plane.
The scanner remains the product surface while SecEng adds AI-native finding depth, evidence discipline, attack-path context, and lifecycle support.
scanner-providerslayered-cutawayPartner scannerSecEng OEM engine
/publication-dsl/figures/SP-01
Launch Review Deliverable Stack
The buyer receives traceable technical findings, launch blockers, remediation priorities, and decision-ready evidence.
launch-reviewartifact-stackReview evidenceRisk and launch findings
/publication-dsl/figures/LAUNCH-03
Launch Review Engagement Lifecycle
The engagement moves from intake and mapping through validation, prioritized findings, remediation planning, and retest.
launch-reviewgoverned-lifecycleEngagement lifecycleDecision ownership
/publication-dsl/figures/LAUNCH-02
Launch Review Scope
A launch review covers the architecture, data, models, retrieval, tools, authority, and evidence needed to make a release decision.
launch-reviewcoverage-matrixReview domainsReview stages
/publication-dsl/figures/LAUNCH-01
Licensing and Control Spectrum
Branded, co-branded, white-label, private-label, and embedded models vary in presentation control, product ownership, and operating responsibility.
brand-licensingordered-spectrumCommercial modelsWhat changes
/publication-dsl/figures/BL-04
Managed Delivery Lifecycle
The MSSP owns customer delivery while SecEng supplies reusable capability, evidence contracts, and escalation-ready technical outputs.
msspgoverned-lifecycleManaged delivery lifecycleOwnership boundary
/publication-dsl/figures/MS-04
Map-to-Attack Handoff
Mapped assets, authority, and trust boundaries become bounded attack hypotheses and a prioritized test plan.
maptransformation-engineMapped system contextHypothesis shaping
/publication-dsl/figures/MAP-04
Marketplace operating model.
The vendor, marketplace, SecEng, and customer each own distinct responsibilities across listing, transaction, entitlement, delivery, support, and renewal.
marketplaceoperating-modelPartner or vendorMarketplace
/publication-dsl/figures/MKT-02
Observed Attack Round Trip
A useful integration accepts a representative attack object, enriches and validates it, and returns a partner-native result.
offensive-platformsintegration-round-tripRepresentative partner objectContract and context
/publication-dsl/figures/OP-05
OEM Deployment Spectrum
OEM delivery can progress from hosted API access through local workers and embedded sidecars to controlled private deployment.
oemordered-spectrumDeployment modelsTradeoffs
/publication-dsl/figures/OEM-04
OEM Pilot to Production
A representative-object pilot should prove contract fit, output value, return-path fidelity, and operational ownership before production expansion.
oemgoverned-lifecyclePilot lifecycle
/publication-dsl/figures/OEM-05
Offer-to-Pilot Journey
A marketplace listing becomes useful when it leads cleanly from problem selection through scope, pilot, evidence, and production decision.
marketplacegoverned-lifecycleBuyer journey
/publication-dsl/figures/MKT-05
One client engagement pilot.
A bounded engagement proves joint delivery, evidence quality, role boundaries, remediation usefulness, and the ability to repeat the work under the consulting…
consultingpilot-contractConsulting partner providesJoint delivery proves
/publication-dsl/figures/CON-03
One course. One platform. One distribution pilot.
A bounded pilot packages one representative course, validates it in the target LMS or marketplace workflow, and returns the operational assets needed for…
academytimeline-horizonPartner providesSecEng proves
/publication-dsl/figures/AC-03
One customer opportunity and handoff pilot.
A bounded opportunity proves qualification, technical support, proposal coordination, provisioning, delivery handoff, and shared account ownership.
resellerspilot-contractReseller providesJoint motion proves
/publication-dsl/figures/RS-03
One customer. One bounded service pilot.
A pilot should prove that SecEng workflows can fit the MSSP operating model, produce customer-ready evidence, and support a repeatable recurring service.
mssppilot-contractMSSP providesSecEng proves
/publication-dsl/figures/MS-03
One joint solution pilot.
A bounded pilot combines one partner capability with one SecEng capability and proves a measurable customer outcome plus a product-native return.
technology-partnerspilot-contractTechnology partner contributesJoint solution proves
/publication-dsl/figures/TECH-03
One listing and fulfillment pilot.
A bounded pilot proves the listing metadata, commercial action, provisioning, delivery, usage signal, and renewal path for one offer.
marketplacepilot-contractPartner providesMarketplace flow proves
/publication-dsl/figures/MKT-03
One object, round trip, lifecycle preserved.
Interoperability is complete only when identifiers, provenance, state transitions, and retest behavior survive the return to the partner workflow.
interoperabilityintegration-round-tripRound-trip lifecycleRound-trip acceptance criteria
/publication-dsl/figures/INT-03
One representative attack, enriched.
A single sanitized result is enough to compare the current product object with the evidence, authority, and remediation context SecEng can add.
vernocomparisonCurrent resultOne sanitized object
/publication-dsl/figures/V-02
One representative attack. One measurable platform pilot.
A bounded pilot compares the current result with an evidence-qualified, context-enriched path and returns the useful fields to the partner platform.
offensive-platformspilot-contractPartner providesSecEng proves
/publication-dsl/figures/OP-03
One representative finding. One measurable OEM pilot.
A bounded integration test proves the create, update, evidence, deduplication, rescan, remediation, and retest lifecycle.
scanner-providerspilot-contractPartner providesSecEng maps and validates
/publication-dsl/figures/SP-03
One role. One cohort. One measurable readiness pilot.
A bounded pilot maps one role and learner population into the partner platform, then returns evidence-backed readiness results and next actions.
workforce-readinesspilot-contractPartner providesSecEng proves
/publication-dsl/figures/WR-03
Partner Findings Lifecycle
AI-native findings must return into the partner product with lifecycle state preserved through review, remediation, and rescan.
scanner-providersintegration-round-tripPartner scan contextSecEng enrichment
/publication-dsl/figures/SP-04
Partner Motion Selector
What does the partner want to own?
partners-hubdecision-treeEmbedSell or resell
/publication-dsl/figures/HUB-04
Path Validation Workflow
Candidate paths are challenged for evidence, ordering, consequence, and alternatives before they become reportable.
apc-reviewgoverned-lifecycleReview workflowReview controls
/publication-dsl/figures/APCS-02
Pilot input and return contract.
The pilot is complete only when a partner-native result returns to the intended product workflow.
vernopilot-contractPartner providesSecEng proves
/publication-dsl/figures/V-03
Protocol adapter versus vendor binding.
A portable adapter handles transport and normalization; a vendor binding adds endpoint, authentication, lifecycle, and sandbox behavior that must be…
interoperabilitycomparisonPortable adapter layerValidated vendor binding
/publication-dsl/figures/INT-02
RAG Failure-Mode Coverage
A useful harness separates prompt injection, corpus poisoning, cross-tenant retrieval, provenance loss, and unsafe action propagation.
rag-harnesscoverage-matrixFailure modesPipeline stages
/publication-dsl/figures/RAG-02
RAG Retest and Evidence Flow
A retrieval failure is closed only after corpus, ranking, policy, or action controls are changed and replayed.
rag-harnessgoverned-lifecycleRAG retest lifecycle
/publication-dsl/figures/RAG-03
Red Team Engagement Flow
A controlled engagement moves from scoping and scenario design through execution, reproduction, evidence, and reporting.
red-teamprocess-railEngagement flowSafety and decision controls
/publication-dsl/figures/RED-02
Remediation Operating Model
Security, product, platform, and engineering teams need explicit ownership for control design, implementation, and proof.
defendoperating-modelSecurityProduct
/publication-dsl/figures/DEF-03
Reseller Delivery Boundary
The reseller owns opportunity and relationship while delivery, support, and technical accountability remain explicitly assigned.
resellersoperating-modelResellerSecEng
/publication-dsl/figures/RS-04
Retrieval Trust Topology
RAG security depends on the full path from query and corpus boundaries through ranking, prompt assembly, model behavior, and output.
rag-harnessimported-graphInput and identityRetrieval boundary
/publication-dsl/figures/RAG-01
Role-to-Cohort Scoring Flow
Role definitions, assessment evidence, calibrated scoring, and cohort reporting form one workforce-readiness pipeline.
workforce-readinesstransformation-engineWorkforce inputsScoring and calibration
/publication-dsl/figures/WR-04
Scanner Output Contract
One scan can produce machine-readable findings, reviewable evidence, path inputs, and remediation-ready artifacts.
scannerartifact-stackAnalysis evidenceStructured findings
/publication-dsl/figures/SCN-03
Scanner Workflow
The scanner moves from target discovery through analysis, evidence grouping, remediation, and rescan.
scannerprocess-railScanner workflowWorkflow controls
/publication-dsl/figures/SCN-02
Scenario Pack Architecture
Reusable scenario packs organize prompt, retrieval, tool, authority, multimodal, and workflow abuse into repeatable tests.
adversarial-rangeecosystem-mapControlled adversarial rangePrompt and instruction
/publication-dsl/figures/RANGE-01
The SecEng partner ecosystem.
Different partner types connect through distinct commercial motions while sharing a common capability, evidence, interoperability, and support foundation.
partners-hubecosystem-mapSecEng partner foundationEmbed and integrate
/publication-dsl/figures/HUB-01
Throughline Value Proposition
Throughline qualifies and explains multi-step risk rather than merely correlating alerts or drawing speculative paths.
apcevidence-dossierCorrelation or path sketchThroughline qualification
/publication-dsl/figures/APC-04
Trust and Authority Topology
Security-relevant behavior emerges from relationships among identities, agents, tools, data, and approval gates.
maptopology-mapActors and identitiesContext and data
/publication-dsl/figures/MAP-02
Unsafe Authority Composition
Individually reasonable permissions can combine into a dangerous end-to-end authority path.
authority-graphtransformation-engineIndividually reasonable capabilitiesComposed authority
/publication-dsl/figures/AUTH-02
What Attack Tests
Attack turns mapped exposure into reproducible tests across prompts, retrieval, agents, tools, authority, and workflows.
attackcapability-planeBounded attack hypothesesAttack
/publication-dsl/figures/ATT-01
What changes and what remains governed.
Brand, domain, packaging, and customer experience may shift to the partner while evidence semantics, security boundaries, release integrity, and entitlement…
brand-licensingoperating-modelPartner controlsSecEng-governed foundations
/publication-dsl/figures/BL-02
What Defend Changes
Defend reduces dangerous authority, strengthens control boundaries, and converts remediation into retestable system changes.
defendcapability-planeQualified risk contextDefend
/publication-dsl/figures/DEF-01
What Evidence Makes Defensible
Evidence preserves provenance, validation state, and retest history so technical findings can support real decisions.
evidencecapability-planeTechnical source materialEvidence
/publication-dsl/figures/EVD-01
What Map Establishes
Map turns architecture, authority, data movement, and trust boundaries into a security model that can be tested.
mapcapability-planeSystem realityMap
/publication-dsl/figures/MAP-01
What Qualifies as a Finding
Theoretical exposure, observed anomaly, reproduced failure, evidence-qualified path, and analyst-reviewed finding are different claim states.
red-teamgrounding-boundaryEarly signalSupported failure
/publication-dsl/figures/RED-03
Where technology partners connect.
Technology partners contribute complementary data, controls, orchestration, evidence, and downstream workflows around a shared customer outcome.
technology-partnersecosystem-mapInputs and contextSecEng capability core
/publication-dsl/figures/TECH-01
Who sells, delivers, and supports.
The reseller owns market access and customer coordination while SecEng supplies technical proof, provisioning, product delivery, and escalation support.
resellersoperating-modelReseller ownsSecEng supplies
/publication-dsl/figures/RS-01
Workbench Capability Flow
Map, scan, test, chain, defend, and prove operate as connected capabilities rather than isolated tools.
workbenchecosystem-mapSecEng WorkbenchMap
/publication-dsl/figures/PROD-01
Repository Indexauth-only
Public repositories connected to AI security classifications, OpenSSF controls, tools, and findings.
/research/repositories

Consultants

27 pages

Consultant profiles and engagement pages

Alex Karoulias
Alex is a CS student at Athens Technical University, Class of 2027. He is deeply focused on the intersection of backend scalability and adversarial security. Hi
/consultants/alex-karoulias
Alon Braun
Alon Braun is the strategy and operating-model counterpart behind the project. His background combines MAMRAM and IDF technical training, a foundation in softwa
/consultants/alon-braun
Dorina Miroyannis
Experienced maritime lawyer and business leader with over a decade of expertise in claims management, maritime law, insurance, and shipping operations. Dorina i
/consultants/dorina-miroyannis
Filippos Kritsalis
Filippos is a mathematically trained software engineer (University of Nottingham) and current backend engineer at Wikifarmer. As the Engineering Intern Lead, he
/consultants/filippos-kritsalis
James Traynor
James Traynor's public profile shows a long-running blend of technical support, web development, marketing operations, and training. He is best suited to blue-t
/consultants/james-traynor
Laurie Myers
Laurie is a globally respected strategist and platform architect with a track record of delivering high-impact partnerships and convening critical conversations
/consultants/laurie-myers
Tim Kerimbekov
Tim Kerimbekov's public profile reflects a blend of cyber risk leadership, product management, and data-protection work. He focuses on helping teams simplify co
/consultants/tim-kerimbekov
Agentic Workflow Abuse Review — Consultants
Find AI security consultants specializing in agentic workflow abuse review.
consultantai securityagentic-workflow-abuse-review
/consultants/service/agentic-workflow-abuse-review
Agentic Workflow Security Hardening — Consultants
Find AI security consultants specializing in agentic workflow security hardening.
consultantai securityagentic-workflow-security-hardening
/consultants/service/agentic-workflow-security-hardening
Ai Governance Security Program Build — Consultants
Find AI security consultants specializing in ai governance security program build.
consultantai securityai-governance-security-program-build
/consultants/service/ai-governance-security-program-build
Ai Guardrails Evals Review — Consultants
Find AI security consultants specializing in ai guardrails evals review.
consultantai securityai-guardrails-evals-review
/consultants/service/ai-guardrails-evals-review
Ai Launch Security Review — Consultants
Find AI security consultants specializing in ai launch security review.
consultantai securityai-launch-security-review
/consultants/service/ai-launch-security-review
Ai Product Security Assessment — Consultants
Find AI security consultants specializing in ai product security assessment.
consultantai securityai-product-security-assessment
/consultants/service/ai-product-security-assessment
Ai Red Team Adversarial Testing — Consultants
Find AI security consultants specializing in ai red team adversarial testing.
consultantai securityai-red-team-adversarial-testing
/consultants/service/ai-red-team-adversarial-testing
Ai Security Maturity Benchmark — Consultants
Find AI security consultants specializing in ai security maturity benchmark.
consultantai securityai-security-maturity-benchmark
/consultants/service/ai-security-maturity-benchmark
Ai Security Sales Enablement — Consultants
Find AI security consultants specializing in ai security sales enablement.
consultantai securityai-security-sales-enablement
/consultants/service/ai-security-sales-enablement
Work With Alex Karoulias
Engagement page for alex karoulias.
engagementconsultantai security
/consultants/alex-karoulias/work-with-me
Work With Alon Braun
Engagement page for alon braun.
engagementconsultantai security
/consultants/alon-braun/work-with-me
Work With David Wolf
Engagement page for david wolf.
engagementconsultantai security
/consultants/david-wolf/work-with-me
Work With Dorina Miroyannis
Engagement page for dorina miroyannis.
engagementconsultantai security
/consultants/dorina-miroyannis/work-with-me
Work With Filippos Kritsalis
Engagement page for filippos kritsalis.
engagementconsultantai security
/consultants/filippos-kritsalis/work-with-me
Work With James Traynor
Engagement page for james traynor.
engagementconsultantai security
/consultants/james-traynor/work-with-me
Work With Laurie Myers
Engagement page for laurie myers.
engagementconsultantai security
/consultants/laurie-myers/work-with-me
Work With Tim Kerimbekov
Engagement page for tim kerimbekov.
engagementconsultantai security
/consultants/tim-kerimbekov/work-with-me
Consultants
/consultantsapp/(public)/consultants/page.tsx
David Wolf
/consultants/david-wolfapp/(public)/consultants/david-wolf/page.tsx
Join Consultant Roster
Independent AI security consultants can join the roster, keep control of clients, rates, and billing, and opt into scoped missions.
/consultants/joinapp/(public)/consultants/join/page.tsx

Projects

153 pages

Portfolio projects, case studies, and published deliverables

Agentic Browser Security Assessment
Conducted a deep product-security assessment of browser trust boundaries across native and agentic browser surfaces, including a privacy-focused Windows…
assessment
/portfolio/agentic-browser-security-assessment
AI Governance Controls with Garak, NeMo Guardrails…
Designed a practical AI governance control layer using Garak, NeMo Guardrails, Microsoft Presidio, Promptfoo, agentic identities, permission scoping…
product
/portfolio/ai-governance-controls-garak-nemo-presidio-promptfoo
AI Product Security Control Plane
Framed AI product security as a product-control problem and translated AI risk categories into evidence, backlog, and governance language that product and…
consulting
/portfolio/ai-product-security-control-plane
Caya Forex PCI DSS Level 3 Compliance
Delivered a PCI DSS Level 3 compliance engagement for Caya, a forex trading and payment processing platform. Work covered scoping, cardholder data environment…
consulting
/portfolio/caya-forex-pci-dss-level-3-compliance
Cendant / Orbitz Affiliate Growth, ML Itinerary Generation…
Supported affiliate-program growth and technical marketing by developing ML-style methods for generating high-value niche multileg flight itineraries, and…
fte
/portfolio/cendant-orbitz-affiliate-ml-multileg-itinerary-growth
Cogstate Cognitive Measurement Delivery for the Australian…
Contributed to technology delivery in a Cogstate engagement on behalf of the Australian Defence Force, where cognitive-assessment and regulated health-data…
consulting
/portfolio/cogstate-regulated-health-data-product-delivery
Cornerstone FedRAMP Moderate ATO Security Controls
Supported Cornerstone's FedRAMP Moderate authorization effort by helping turn formal control requirements into security policies, standards, guidelines…
fte
/portfolio/cornerstone-fedramp-moderate-ato-security-controls
Devo Security Research & Conference Program
Developed and contributed to Devo security research that converted customer deployment analysis, SIEM maturity patterns, detection taxonomy work, cloud-native…
report
/portfolio/devo-security-research-conference-program
Devo SIEM Reference Architecture, Taxonomy & Detection…
Led and contributed to Devo architecture innovation work focused on SIEM reference architectures, detection taxonomy, Exchange-content validation, enterprise…
report
/portfolio/devo-siem-reference-architecture-taxonomy-validation
Disney IAM SIEM Alert Debugging & Executive Dashboard
Delivered Splunk-focused IAM and SIEM work for Disney, debugging identity and access-control alerts, building a custom Splunk app, and creating executive…
consulting
/portfolio/disney-iam-siem-alert-debugging-splunk-dashboard
Forescout Banking on Security Financial Services Research
Contributed to Forescout's Banking on Security financial-services research, using Device Cloud analytics and Elastic/Kibana-style workflows to help examine…
report
/portfolio/forescout-banking-on-security-financial-services-research
Forescout Connected Medical Device Security Report
Contributed to Forescout connected medical-device research using Device Cloud analytics to examine segmentation failures, insecure protocols, default…
report
/portfolio/forescout-connected-medical-device-security-report
Forescout Device Cloud Elastic/Kibana Analytics Platform
Built and executed Elastic/Kibana-style analytics workflows over Forescout Device Cloud data to support security research, sector-specific report findings…
report
/portfolio/forescout-device-cloud-elastic-kibana-analytics-platform
Forescout DTEN / WIRED-Featured Offensive Security Research
Contributed to offensive security research involving DTEN and connected-device risk, helping expose how enterprise collaboration and IoT-style devices can…
report
/portfolio/forescout-dten-wired-offensive-security-research
Forescout Enterprise of Things Security Report 2020
Contributed to Forescout's Enterprise of Things Security Report research, using Device Cloud analytics and Elastic/Kibana-style workflows to help identify and…
report
/portfolio/forescout-enterprise-of-things-security-report-2020
Forescout Operational Technology Security Research
Contributed to Forescout operational-technology and Enterprise-of-Things research by using Device Cloud analytics and Elastic/Kibana-style workflows to help…
report
/portfolio/forescout-operational-technology-security-research
Forescout Rapid Response Program
Contributed to Forescout rapid response work by helping coordinate security research, product risk triage, technical validation, customer-impact analysis…
fte
/portfolio/forescout-rapid-response-program
Forescout Smart IoT Security Lab
Built and directed Forescout's Smart IoT Building security research lab — a live, instrumented environment designed to surface real-world attack paths across…
fte
/portfolio/forescout-smart-iot-security-lab
GitOps Multi-Agent SDLC Automation Platform
Designed and implemented a GitOps-oriented multi-agent SDLC automation platform where AI agents analyze repositories, propose fixes, remediate bugs, generate…
product
/portfolio/gitops-multi-agent-sdlc-automation-platform
Glowing Plant Project
Contributed research lineage and scientific context that became part of the Glowing Plant Project, a prominent synthetic-biology effort that brought…
research
/portfolio/glowing-plant-project-synthetic-biology-culture
Hotel Marketers Hospitality Booking Intelligence & GIS…
Reconstructed from 2005-era Hotel Marketers site copy, this case study captures technical hospitality work focused on direct-booking enablement, destination…
consulting
/portfolio/hotel-marketers-hospitality-booking-intelligence
Internet Rising
Created a feature-length interview documentary exploring how the internet was reshaping creativity, identity, culture, consciousness, media, entrepreneurship…
film
/portfolio/internet-rising-documentary-digital-consciousness
Mandiant — Operation Aurora DFIR & FBI Cybercrime Training
Principal consultant at Mandiant during one of the most consequential periods in enterprise security history — deployed on Operation Aurora DFIR efforts at…
consulting
/portfolio/mandiant-operation-aurora-dfir
Mapping Motives: Analysis of 2,000 Enterprise Cloud…
Presented Cloud Native SecurityCon North America 2023 research with Joshua Smith at Devo, analyzing 2,000 enterprise cloud detections to explain how cloud…
report
/portfolio/devo-cloud-native-security-conference-mapping-motives
MYTHOS: The AI Security Narrative
MYTHOS examines the dominant narratives — the myths, metaphors, and mental models — that shape how security teams, executives, and builders approach AI risk.…
product
/portfolio/mythos-book-2026
NIST NICE Cyber Workforce Research Program
Developed a NIST NICE Cyber Workforce research program focused on role language, workforce taxonomy, and cyber-workforce signal extraction, then translated…
consulting
/portfolio/nist-nice-cyber-workforce-research-program
Pathwwway iGaming — Deputy Head of Technology & ISO 27001…
Served as Deputy Head of Technology for a Pathwwway iGaming engagement before Forescout, guiding technology delivery, platform operations, and security-aware…
fte
/portfolio/pathwwway-igaming-deputy-head-of-technology
RiverBanks Workforce Development LMS Suite
Designed and built a workforce-development LMS product suite around three major frameworks: EMPOWER for psychometrics and personality intelligence, CORE for…
product
/portfolio/riverbanks-workforce-development-lms-suite
ServiceNow Principal Security Research Program
Led advanced security research across product security, application security, and AI risk management at ServiceNow — one of the most widely deployed…
fte
/portfolio/servicenow-security-research-scientist
Splunk Product Security Program Buildout
Partnered with Splunk to build and scale the product security program, strengthen secure development practices, and create the evidence, process, and…
fte
/portfolio/splunk-product-security-program-buildout
Syntryx OSINT Platform Product Buildout
Led product and engineering for Syntryx, an open-source intelligence platform for multi-channel web and behavioral data, managing an 11-person team, serving…
fte
/portfolio/syntryx-osint-platform-product-buildout
Tauri Rust AI Sidecar, Apple Bridge & Capability Mesh
Designed and built a native AI sidecar platform using Tauri and Rust, combining MITM proxying, WebSocket pub/sub bridges, 164 schema normalizers/adapters…
product
/portfolio/tauri-rust-ai-sidecar-apple-bridge-capability-mesh
The AI Security Engineer's Handbook
Created a practitioner-oriented AI Security Engineering Handbook that translates AI risk, governance, product-security, and agentic-system concerns into…
product
/portfolio/ai-security-engineers-handbook-2026
The AI Security Engineering Field Guide
The AI Security Engineering Field Guide is a compact, action-oriented companion for practitioners who need direct guidance — not long-form reference. It…
product
/portfolio/ai-security-engineering-field-guide-2026
The Mimicking Octopus
Researched and wrote The Mimicking Octopus: A Journey to True Self, drawing on an exceptional maritime Southeast Asia journey to investigate the mimic octopus…
book
/portfolio/mimicking-octopus-journey-true-self
The State of AI Security Engineering Report 2026
Designed and authored a flagship 2026 research report on AI security engineering, using a corpus of AI and security job descriptions, role analysis, market…
report
/portfolio/ai-security-engineering-report-2026
Trada — Data.com B2B Sales Contact Intelligence & ABM…
Delivered B2B contact intelligence, OSINT-driven contact mining, and ABM outreach campaign execution for Trada, a performance advertising platform. Achieved…
consulting
/portfolio/trada-datacom-b2b-rainmaker-contact-intelligence
UNUM LLM Attack Story & Detection Engineering
Delivered a two-month consulting engagement for UNUM that used LLM-assisted attack-tree and attack-story generation, MITRE ATT&CK mapping, ServiceNow asset…
consulting
/portfolio/unum-llm-attack-story-detection-engineering
Portfolio
/portfolioapp/(public)/portfolio/page.tsx
Agentic Browser Security Assessment — A-Teamauth-only
/portfolio/agentic-browser-security-assessment/a-team
Agentic Browser Security Assessment — One Pagerauth-only
/portfolio/agentic-browser-security-assessment/one-pager
AI Governance Controls with Garak, NeMo Guardrails…auth-only
/portfolio/ai-governance-controls-garak-nemo-presidio-promptfoo/one-pager
AI Governance Controls with Garak, NeMo Guardrails…auth-only
/portfolio/ai-governance-controls-garak-nemo-presidio-promptfoo/a-team
AI Product Security Control Plane — A-Teamauth-only
/portfolio/ai-product-security-control-plane/a-team
AI Product Security Control Plane — One Pagerauth-only
/portfolio/ai-product-security-control-plane/one-pager
Caya Forex PCI DSS Level 3 Compliance — A-Teamauth-only
/portfolio/caya-forex-pci-dss-level-3-compliance/a-team
Caya Forex PCI DSS Level 3 Compliance — One Pagerauth-only
/portfolio/caya-forex-pci-dss-level-3-compliance/one-pager
Cendant / Orbitz Affiliate Growth, ML Itinerary Generation…auth-only
/portfolio/cendant-orbitz-affiliate-ml-multileg-itinerary-growth/one-pager
Cendant / Orbitz Affiliate Growth, ML Itinerary Generation…auth-only
/portfolio/cendant-orbitz-affiliate-ml-multileg-itinerary-growth/a-team
Cogstate Cognitive Measurement Delivery for the Australian…auth-only
/portfolio/cogstate-regulated-health-data-product-delivery/one-pager
Cogstate Cognitive Measurement Delivery for the Australian…auth-only
/portfolio/cogstate-regulated-health-data-product-delivery/a-team
Cornerstone FedRAMP Moderate ATO Security Controls — A-Teamauth-only
/portfolio/cornerstone-fedramp-moderate-ato-security-controls/a-team
Cornerstone FedRAMP Moderate ATO Security Controls — One…auth-only
/portfolio/cornerstone-fedramp-moderate-ato-security-controls/one-pager
Devo Security Research & Conference Program — A-Teamauth-only
/portfolio/devo-security-research-conference-program/a-team
Devo Security Research & Conference Program — One Pagerauth-only
/portfolio/devo-security-research-conference-program/one-pager
Devo SIEM Reference Architecture, Taxonomy & Detection…auth-only
/portfolio/devo-siem-reference-architecture-taxonomy-validation/one-pager
Devo SIEM Reference Architecture, Taxonomy & Detection…auth-only
/portfolio/devo-siem-reference-architecture-taxonomy-validation/a-team
Disney IAM SIEM Alert Debugging & Executive Dashboard…auth-only
/portfolio/disney-iam-siem-alert-debugging-splunk-dashboard/one-pager
Disney IAM SIEM Alert Debugging & Executive Dashboard…auth-only
/portfolio/disney-iam-siem-alert-debugging-splunk-dashboard/a-team
Forescout Banking on Security Financial Services Research…auth-only
/portfolio/forescout-banking-on-security-financial-services-research/one-pager
Forescout Banking on Security Financial Services Research…auth-only
/portfolio/forescout-banking-on-security-financial-services-research/a-team
Forescout Connected Medical Device Security Report — A-Teamauth-only
/portfolio/forescout-connected-medical-device-security-report/a-team
Forescout Connected Medical Device Security Report — One…auth-only
/portfolio/forescout-connected-medical-device-security-report/one-pager
Forescout Device Cloud Elastic/Kibana Analytics Platform…auth-only
/portfolio/forescout-device-cloud-elastic-kibana-analytics-platform/one-pager
Forescout Device Cloud Elastic/Kibana Analytics Platform…auth-only
/portfolio/forescout-device-cloud-elastic-kibana-analytics-platform/a-team
Forescout DTEN / WIRED-Featured Offensive Security…auth-only
/portfolio/forescout-dten-wired-offensive-security-research/one-pager
Forescout DTEN / WIRED-Featured Offensive Security…auth-only
/portfolio/forescout-dten-wired-offensive-security-research/a-team
Forescout Enterprise of Things Security Report 2020 — A-Teamauth-only
/portfolio/forescout-enterprise-of-things-security-report-2020/a-team
Forescout Enterprise of Things Security Report 2020 — One…auth-only
/portfolio/forescout-enterprise-of-things-security-report-2020/one-pager
Forescout Operational Technology Security Research — A-Teamauth-only
/portfolio/forescout-operational-technology-security-research/a-team
Forescout Operational Technology Security Research — One…auth-only
/portfolio/forescout-operational-technology-security-research/one-pager
Forescout Rapid Response Program — A-Teamauth-only
/portfolio/forescout-rapid-response-program/a-team
Forescout Rapid Response Program — One Pagerauth-only
/portfolio/forescout-rapid-response-program/one-pager
Forescout Smart IoT Security Lab — A-Teamauth-only
/portfolio/forescout-smart-iot-security-lab/a-team
Forescout Smart IoT Security Lab — One Pagerauth-only
/portfolio/forescout-smart-iot-security-lab/one-pager
GitOps Multi-Agent SDLC Automation Platform — A-Teamauth-only
/portfolio/gitops-multi-agent-sdlc-automation-platform/a-team
GitOps Multi-Agent SDLC Automation Platform — One Pagerauth-only
/portfolio/gitops-multi-agent-sdlc-automation-platform/one-pager
Glowing Plant Project — A-Teamauth-only
/portfolio/glowing-plant-project-synthetic-biology-culture/a-team
Glowing Plant Project — One Pagerauth-only
/portfolio/glowing-plant-project-synthetic-biology-culture/one-pager
Hotel Marketers Hospitality Booking Intelligence & GIS…auth-only
/portfolio/hotel-marketers-hospitality-booking-intelligence/one-pager
Hotel Marketers Hospitality Booking Intelligence & GIS…auth-only
/portfolio/hotel-marketers-hospitality-booking-intelligence/a-team
Internet Rising — A-Teamauth-only
/portfolio/internet-rising-documentary-digital-consciousness/a-team
Internet Rising — One Pagerauth-only
/portfolio/internet-rising-documentary-digital-consciousness/one-pager
Mandiant — Operation Aurora DFIR & FBI Cybercrime Training…auth-only
/portfolio/mandiant-operation-aurora-dfir/one-pager
Mandiant — Operation Aurora DFIR & FBI Cybercrime Training…auth-only
/portfolio/mandiant-operation-aurora-dfir/a-team
Mapping Motives: Analysis of 2,000 Enterprise Cloud…auth-only
/portfolio/devo-cloud-native-security-conference-mapping-motives/one-pager
Mapping Motives: Analysis of 2,000 Enterprise Cloud…auth-only
/portfolio/devo-cloud-native-security-conference-mapping-motives/a-team
MYTHOS: The AI Security Narrative — A-Teamauth-only
/portfolio/mythos-book-2026/a-team
MYTHOS: The AI Security Narrative — One Pagerauth-only
/portfolio/mythos-book-2026/one-pager
NIST NICE Cyber Workforce Research Program — A-Teamauth-only
/portfolio/nist-nice-cyber-workforce-research-program/a-team
NIST NICE Cyber Workforce Research Program — One Pagerauth-only
/portfolio/nist-nice-cyber-workforce-research-program/one-pager
Pathwwway iGaming — Deputy Head of Technology & ISO 27001…auth-only
/portfolio/pathwwway-igaming-deputy-head-of-technology/one-pager
Pathwwway iGaming — Deputy Head of Technology & ISO 27001…auth-only
/portfolio/pathwwway-igaming-deputy-head-of-technology/a-team
RiverBanks Workforce Development LMS Suite — A-Teamauth-only
/portfolio/riverbanks-workforce-development-lms-suite/a-team
RiverBanks Workforce Development LMS Suite — One Pagerauth-only
/portfolio/riverbanks-workforce-development-lms-suite/one-pager
ServiceNow Principal Security Research Program — A-Teamauth-only
/portfolio/servicenow-security-research-scientist/a-team
ServiceNow Principal Security Research Program — One Pagerauth-only
/portfolio/servicenow-security-research-scientist/one-pager
Splunk Product Security Program Buildout — A-Teamauth-only
/portfolio/splunk-product-security-program-buildout/a-team
Splunk Product Security Program Buildout — One Pagerauth-only
/portfolio/splunk-product-security-program-buildout/one-pager
Syntryx OSINT Platform Product Buildout — A-Teamauth-only
/portfolio/syntryx-osint-platform-product-buildout/a-team
Syntryx OSINT Platform Product Buildout — One Pagerauth-only
/portfolio/syntryx-osint-platform-product-buildout/one-pager
Tauri Rust AI Sidecar, Apple Bridge & Capability Mesh…auth-only
/portfolio/tauri-rust-ai-sidecar-apple-bridge-capability-mesh/one-pager
Tauri Rust AI Sidecar, Apple Bridge & Capability Mesh…auth-only
/portfolio/tauri-rust-ai-sidecar-apple-bridge-capability-mesh/a-team
The AI Security Engineer's Handbook — A-Teamauth-only
/portfolio/ai-security-engineers-handbook-2026/a-team
The AI Security Engineer's Handbook — One Pagerauth-only
/portfolio/ai-security-engineers-handbook-2026/one-pager
The AI Security Engineering Field Guide — A-Teamauth-only
/portfolio/ai-security-engineering-field-guide-2026/a-team
The AI Security Engineering Field Guide — One Pagerauth-only
/portfolio/ai-security-engineering-field-guide-2026/one-pager
The Mimicking Octopus — A-Teamauth-only
/portfolio/mimicking-octopus-journey-true-self/a-team
The Mimicking Octopus — One Pagerauth-only
/portfolio/mimicking-octopus-journey-true-self/one-pager
The State of AI Security Engineering Report 2026 — A-Teamauth-only
/portfolio/ai-security-engineering-report-2026/a-team
The State of AI Security Engineering Report 2026 — One Pagerauth-only
/portfolio/ai-security-engineering-report-2026/one-pager
Trada — Data.com B2B Sales Contact Intelligence & ABM…auth-only
/portfolio/trada-datacom-b2b-rainmaker-contact-intelligence/one-pager
Trada — Data.com B2B Sales Contact Intelligence & ABM…auth-only
/portfolio/trada-datacom-b2b-rainmaker-contact-intelligence/a-team
UNUM LLM Attack Story & Detection Engineering — A-Teamauth-only
/portfolio/unum-llm-attack-story-detection-engineering/a-team
UNUM LLM Attack Story & Detection Engineering — One Pagerauth-only
/portfolio/unum-llm-attack-story-detection-engineering/one-pager
Agentic Browser Security Assessment — LinkedInauth-only
/portfolio/agentic-browser-security-assessment/linkedin
AI Governance Controls with Garak, NeMo Guardrails…auth-only
/portfolio/ai-governance-controls-garak-nemo-presidio-promptfoo/linkedin
AI Product Security Control Plane — LinkedInauth-only
/portfolio/ai-product-security-control-plane/linkedin
Caya Forex PCI DSS Level 3 Compliance — LinkedInauth-only
/portfolio/caya-forex-pci-dss-level-3-compliance/linkedin
Cendant / Orbitz Affiliate Growth, ML Itinerary Generation…auth-only
/portfolio/cendant-orbitz-affiliate-ml-multileg-itinerary-growth/linkedin
Cogstate Cognitive Measurement Delivery for the Australian…auth-only
/portfolio/cogstate-regulated-health-data-product-delivery/linkedin
Cornerstone FedRAMP Moderate ATO Security Controls…auth-only
/portfolio/cornerstone-fedramp-moderate-ato-security-controls/linkedin
Devo Security Research & Conference Program — LinkedInauth-only
/portfolio/devo-security-research-conference-program/linkedin
Devo SIEM Reference Architecture, Taxonomy & Detection…auth-only
/portfolio/devo-siem-reference-architecture-taxonomy-validation/linkedin
Disney IAM SIEM Alert Debugging & Executive Dashboard…auth-only
/portfolio/disney-iam-siem-alert-debugging-splunk-dashboard/linkedin
Forescout Banking on Security Financial Services Research…auth-only
/portfolio/forescout-banking-on-security-financial-services-research/linkedin
Forescout Connected Medical Device Security Report…auth-only
/portfolio/forescout-connected-medical-device-security-report/linkedin
Forescout Device Cloud Elastic/Kibana Analytics Platform…auth-only
/portfolio/forescout-device-cloud-elastic-kibana-analytics-platform/linkedin
Forescout DTEN / WIRED-Featured Offensive Security…auth-only
/portfolio/forescout-dten-wired-offensive-security-research/linkedin
Forescout Enterprise of Things Security Report 2020…auth-only
/portfolio/forescout-enterprise-of-things-security-report-2020/linkedin
Forescout Operational Technology Security Research…auth-only
/portfolio/forescout-operational-technology-security-research/linkedin
Forescout Rapid Response Program — LinkedInauth-only
/portfolio/forescout-rapid-response-program/linkedin
Forescout Smart IoT Security Lab — LinkedInauth-only
/portfolio/forescout-smart-iot-security-lab/linkedin
GitOps Multi-Agent SDLC Automation Platform — LinkedInauth-only
/portfolio/gitops-multi-agent-sdlc-automation-platform/linkedin
Glowing Plant Project — LinkedInauth-only
/portfolio/glowing-plant-project-synthetic-biology-culture/linkedin
Hotel Marketers Hospitality Booking Intelligence & GIS…auth-only
/portfolio/hotel-marketers-hospitality-booking-intelligence/linkedin
Internet Rising — LinkedInauth-only
/portfolio/internet-rising-documentary-digital-consciousness/linkedin
Mandiant — Operation Aurora DFIR & FBI Cybercrime Training…auth-only
/portfolio/mandiant-operation-aurora-dfir/linkedin
Mapping Motives: Analysis of 2,000 Enterprise Cloud…auth-only
/portfolio/devo-cloud-native-security-conference-mapping-motives/linkedin
MYTHOS: The AI Security Narrative — LinkedInauth-only
/portfolio/mythos-book-2026/linkedin
NIST NICE Cyber Workforce Research Program — LinkedInauth-only
/portfolio/nist-nice-cyber-workforce-research-program/linkedin
Pathwwway iGaming — Deputy Head of Technology & ISO 27001…auth-only
/portfolio/pathwwway-igaming-deputy-head-of-technology/linkedin
RiverBanks Workforce Development LMS Suite — LinkedInauth-only
/portfolio/riverbanks-workforce-development-lms-suite/linkedin
ServiceNow Principal Security Research Program — LinkedInauth-only
/portfolio/servicenow-security-research-scientist/linkedin
Splunk Product Security Program Buildout — LinkedInauth-only
/portfolio/splunk-product-security-program-buildout/linkedin
Syntryx OSINT Platform Product Buildout — LinkedInauth-only
/portfolio/syntryx-osint-platform-product-buildout/linkedin
Tauri Rust AI Sidecar, Apple Bridge & Capability Mesh…auth-only
/portfolio/tauri-rust-ai-sidecar-apple-bridge-capability-mesh/linkedin
The AI Security Engineer's Handbook — LinkedInauth-only
/portfolio/ai-security-engineers-handbook-2026/linkedin
The AI Security Engineering Field Guide — LinkedInauth-only
/portfolio/ai-security-engineering-field-guide-2026/linkedin
The Mimicking Octopus — LinkedInauth-only
/portfolio/mimicking-octopus-journey-true-self/linkedin
The State of AI Security Engineering Report 2026 — LinkedInauth-only
/portfolio/ai-security-engineering-report-2026/linkedin
Trada — Data.com B2B Sales Contact Intelligence & ABM…auth-only
/portfolio/trada-datacom-b2b-rainmaker-contact-intelligence/linkedin
UNUM LLM Attack Story & Detection Engineering — LinkedInauth-only
/portfolio/unum-llm-attack-story-detection-engineering/linkedin

Commercial

40 pages

Licensing, partners, programs, and operations

Workforce Platform Partners | SecEng
Add AI security readiness inside the platform your learners already use — role taxonomy, evidence model, and enterprise reporting under a bounded partner or…
/commercial/partners/workforce-readiness
Integrations
How SecEng integrates with scanner providers, offensive-security platforms, and OEM partners.
/commercial/integrations
Partner Interoperability Framework
Canonical contract layer for scanner findings, attack traces, partner evidence, APC results, workforce content, and learner outcomes.
/commercial/partners/interoperability
Partner Application
Public qualification route for prospective AI Security LLC partners before portal access.
/commercial/partners/apply
Academic AI Security Licensing
Academic licensing for AI security research, AIPSA Academy programs, labs, educational content
/commercial/licensing/academicapp/(public)/commercial/licensing/academic/page.tsx
AI Security Deployment Models
Compare SaaS, local worker, private worker, OEM sidecar, hybrid, offline, and air-gapped deployment models for AI Security LLC.
/commercial/operations/deploymentapp/(public)/commercial/operations/deployment/page.tsx
AI Security OEM for Scanner Providers | SecEng Workbench
Add AI-native coverage for agents, retrieval, MCP, and tool use to an existing scanner. SecEng runs behind the partner workflow and returns findings…
/commercial/partners/scanner-providersapp/(public)/commercial/partners/scanner-providers/page.tsx
AI Security Procurement
Procurement pathways for enterprise licenses, OEM agreements, reseller orders, partner pilots, private offers, statements of work, and vendor onboarding.
/commercial/licensing/procurementapp/(public)/commercial/licensing/procurement/page.tsx
AI Security Reseller Program
Resell AI Security LLC assessments, Academy products, SecEng workbench licenses, OEM modules, and enterprise security enablement packages.
/commercial/partners/resellersapp/(public)/commercial/partners/resellers/page.tsx
AI Security Usage Credits
Usage-credit licensing for metered AI security scans, evidence exports, attack-pack runs, RAG checks, agent analysis, and OEM partner customer usage.
/commercial/licensing/usage-creditsapp/(public)/commercial/licensing/usage-credits/page.tsx
AIPSA Academy Content Preview — Path → Module → Section
Real, already-shipped AIPSA Academy content (6 courses, 16 labs, 513 assessment questions) browsable in a Path → Module → Section shape, for training and…
/commercial/partners/academy-content-previewapp/(public)/commercial/partners/academy-content-preview/page.tsx
Air-Gapped AI Security Licensing
Air-gapped deployment and licensing options for sensitive AI security programs that require disconnected workers, private evidence
/commercial/licensing/air-gappedapp/(public)/commercial/licensing/air-gapped/page.tsx
Commercial
/commercialapp/(public)/commercial/page.tsx
Commercial Audit and Reporting
Audit, usage reporting, partner rollups, customer org reporting, evidence traceability, and commercial reconciliation for AI Security LLC.
/commercial/operations/auditapp/(public)/commercial/operations/audit/page.tsx
Commercial Contact
Start an OEM, reseller, MSSP, private-label, enterprise licensing, or procurement conversation with AI Security LLC.
/commercial/contactapp/(public)/commercial/contact/page.tsx
Commercial Implementation
Implementation planning for AI Security LLC partner integrations, OEM sidecars, private workers, usage metering, evidence exports
/commercial/operations/implementationapp/(public)/commercial/operations/implementation/page.tsx
Commercial Legal Center
OEM, reseller, private-label, white-label, support, data-processing, security, scan-scope, and order-form documents for commercial programs.
/commercial/legalapp/(public)/commercial/legal/page.tsx
Commercial Licensing
Enterprise, embedded, OEM, white-label, offline, air-gapped, academic, startup, and usage-credit licensing for AI security programs.
/commercial/licensingapp/(public)/commercial/licensing/page.tsx
Commercial Operations
Deployment, support, SLA, security, data-processing, audit, customer-success, and implementation operations for AI Security LLC commercial programs.
/commercial/operationsapp/(public)/commercial/operations/page.tsx
Commercial Programs
Design partner, startup, academic, research, channel, and technology alliance programs for AI Security LLC.
/commercial/programsapp/(public)/commercial/programs/page.tsx
Commercial Security Controls
Security controls for partner licensing, local workers, OEM binaries, usage metering, signed outputs, token handling, audit events
/commercial/operations/securityapp/(public)/commercial/operations/security/page.tsx
Commercial Support
Commercial support options for OEM partners, MSSPs, resellers, enterprise customers, scanner vendors, and private-label programs.
/commercial/operations/supportapp/(public)/commercial/operations/support/page.tsx
Consulting Partner Program
Use SecEng tooling, playbooks, evidence packs, Academy content, and private-label delivery assets to expand an advisory, pentest
/commercial/partners/consultingapp/(public)/commercial/partners/consulting/page.tsx
Customer Success
Customer-success motion for enterprise, OEM, MSSP, reseller, startup, and private-label AI security programs.
/commercial/operations/customer-successapp/(public)/commercial/operations/customer-success/page.tsx
Data Processing and Privacy
Data-processing, privacy, retention, customer evidence, local execution, audit trails, and partner deployment controls for AI security commercial programs.
/commercial/operations/data-processingapp/(public)/commercial/operations/data-processing/page.tsx
Design Partner Program
Work directly with AI Security LLC to shape OEM modules, SecEng engine capabilities, evidence outputs, Academy products
/commercial/programs/design-partnerapp/(public)/commercial/programs/design-partner/page.tsx
Enterprise AI Security Licensing
Enterprise licensing for organization-wide AI security programs, private workers, evidence generation, Academy access, procurement support
/commercial/licensing/enterpriseapp/(public)/commercial/licensing/enterprise/page.tsx
MSSP AI Security Partner Program
Launch managed AI security assessments, AI blue-team monitoring, evidence generation
/commercial/partners/msspapp/(public)/commercial/partners/mssp/page.tsx
OEM Engine: Embed AI Security Capability | SecEng
License one bounded SecEng capability or a selected module set, invoke it headlessly, and return versioned findings, evidence, and lifecycle state through…
/commercial/partners/oemapp/(public)/commercial/partners/oem/page.tsx
OEM Licensing
OEM licensing for partners embedding the SecEng Code Scanner as a headless engine, CLI, local HTTP sidecar, JSON output, and SARIF output.
/commercial/licensing/oemapp/(public)/commercial/licensing/oem/page.tsx
Offensive Platform OEM: System Context Behind the Attack |…
Bring one representative attack, trace, or campaign result. SecEng tests whether approved system context explains the path, separates grounded evidence from…
/commercial/partners/offensive-security-platformsapp/(public)/commercial/partners/offensive-security-platforms/page.tsx
Offline AI Security Licensing
Offline licensing for local scans, private workers, hard-capped usage credits, signed license grants, evidence bundles
/commercial/licensing/offlineapp/(public)/commercial/licensing/offline/page.tsx
Partner FAQ
Answers for OEM, reseller, MSSP, private-label, scanner-provider, technology, and consulting partners evaluating AI Security LLC.
/commercial/partners/faqapp/(public)/commercial/partners/faq/page.tsx
Partner Marketplace
Package partner-ready AI security modules, SecEng capabilities, Academy products, and evidence add-ons for commercial distribution and integration.
/commercial/partners/marketplaceapp/(public)/commercial/partners/marketplace/page.tsx
Partner Programs
Partner with AI Security LLC through OEM, scanner-provider, MSSP, reseller, consulting, private-label, and technology alliance programs.
/commercial/partnersapp/(public)/commercial/partners/page.tsx
Private-Label AI Security Assessments
Deliver AI product security assessments, RAG reviews, agent workflow testing, and buyer-ready evidence under your own advisory or consulting brand.
/commercial/partners/private-labelapp/(public)/commercial/partners/private-label/page.tsx
Research Partner Program
Collaborate on AI security research, vulnerability discovery, benchmarks, disclosure workflows, adversarial datasets, and evidence-backed reporting.
/commercial/programs/researchapp/(public)/commercial/programs/research/page.tsx
Startup AI Security Licensing
Startup licensing for AI-native teams that need buyer-ready evidence, AI product security testing, Academy access
/commercial/licensing/startupapp/(public)/commercial/licensing/startup/page.tsx
White-Label AI Security Engine
License SecEng AI security capabilities under your brand with custom reporting language, partner-controlled packaging, and commercial support options.
/commercial/partners/white-labelapp/(public)/commercial/partners/white-label/page.tsx
White-Label Licensing
White-label licensing for partner-branded AI security modules, private-label assessments, custom report language, and embedded commercial distribution.
/commercial/licensing/white-labelapp/(public)/commercial/licensing/white-label/page.tsx

Marketplace

52 pages

Pricing, packages, and commercial catalog

AWS-Compatible Roadmap
AWS-compatible packaging schemas and future AWS Marketplace roadmap. Current buying path is direct SOW scoping.
/marketplace/aws
Marketplace
The commercial catalog for AI security: assessments, SecEng products, packaged solutions, Academy training, integrations, and enterprise private offers.
/marketplace
Pricing
Direct consulting pricing bands for AI security assessments, adversarial testing, hardening, and evidence buildouts.
/pricing
Vendor Benchmarking
Private benchmark scoping for vendors, products, and model families.
/marketplace/vendor-benchmarking
Request a Private Offer
Request an enterprise private offer that bundles AI security products, services, training, and evidence work into one scoped engagement.
/marketplace/private-offers
Academy White-Label Partner Pack — AWS-Compatible Roadmap
AWS-compatible marketplace packaging route for Academy White-Label Partner Pack.
awsmarketplaceacademy_lms
/marketplace/aws/academy-white-label-partner-pack
AI Launch Security Review — AWS-Compatible Roadmap
AWS-compatible marketplace packaging route for AI Launch Security Review.
awsmarketplacelaunch_review
/marketplace/aws/ai-launch-security-review
AI Security Academy — AWS-Compatible Roadmap
AWS-compatible marketplace packaging route for AI Security Academy.
awsmarketplaceacademy
/marketplace/aws/academy-enterprise-training-pack
AIPSA Academy Access — AWS-Compatible Roadmap
AWS-compatible marketplace packaging route for AIPSA Academy Access.
awsmarketplaceanalytics
/marketplace/aws/academy-access
Attack Domain Bundle — AWS-Compatible Roadmap
AWS-compatible marketplace packaging route for Attack Domain Bundle.
awsmarketplaceanalytics
/marketplace/aws/academy-bundle-attack
Complete Academy Bundle — AWS-Compatible Roadmap
AWS-compatible marketplace packaging route for Complete Academy Bundle.
awsmarketplaceanalytics
/marketplace/aws/academy-bundle-complete
Defend Domain Bundle — AWS-Compatible Roadmap
AWS-compatible marketplace packaging route for Defend Domain Bundle.
awsmarketplaceanalytics
/marketplace/aws/academy-bundle-defend
Evidence Domain Bundle — AWS-Compatible Roadmap
AWS-compatible marketplace packaging route for Evidence Domain Bundle.
awsmarketplaceanalytics
/marketplace/aws/academy-bundle-evidence
Individual Lab Access — AWS-Compatible Roadmap
AWS-compatible marketplace packaging route for Individual Lab Access.
awsmarketplaceanalytics
/marketplace/aws/academy-lab-access
Map Domain Bundle — AWS-Compatible Roadmap
AWS-compatible marketplace packaging route for Map Domain Bundle.
awsmarketplaceanalytics
/marketplace/aws/academy-bundle-map
Pen Test & Red Team Readiness Packet — AWS-Compatible…
AWS-compatible marketplace packaging route for Pen Test & Red Team Readiness Packet.
awsmarketplacepentest_readiness
/marketplace/aws/pen-test-red-team-readiness-packet
Role Readiness / Platform Partner Add-On — AWS-Compatible…
AWS-compatible marketplace packaging route for Role Readiness / Platform Partner Add-On.
awsmarketplaceworkforce_readiness
/marketplace/aws/ai-security-workforce-readiness-pack
SecEng Adversarial Range — AWS-Compatible Roadmap
AWS-compatible marketplace packaging route for SecEng Adversarial Range.
awsmarketplaceattack_range
/marketplace/aws/seceng-ai-attack-range
SecEng AI Security Program Jumpstart — AWS-Compatible…
AWS-compatible marketplace packaging route for SecEng AI Security Program Jumpstart.
awsmarketplaceprofessional_services
/marketplace/aws/seceng-program-jumpstart
SecEng Code Scanner OEM Pilot — AWS-Compatible Roadmap
AWS-compatible marketplace packaging route for SecEng Code Scanner OEM Pilot.
awsmarketplaceoem_scanner
/marketplace/aws/seceng-scan-oem-pack
SecEng Code Scanner Team License — AWS-Compatible Roadmap
AWS-compatible marketplace packaging route for SecEng Code Scanner Team License.
awsmarketplaceworkbench
/marketplace/aws/seceng-code-scanner-team
SecEng Enterprise AI Security Buildout — AWS-Compatible…
AWS-compatible marketplace packaging route for SecEng Enterprise AI Security Buildout.
awsmarketplaceenterprise_buildout
/marketplace/aws/seceng-enterprise-buildout
SecEng Evidence Analytics — AWS-Compatible Roadmap
AWS-compatible marketplace packaging route for SecEng Evidence Analytics.
awsmarketplaceanalytics
/marketplace/aws/seceng-analytics-pack
SecEng Trust Scanner — AWS-Compatible Roadmap
AWS-compatible marketplace packaging route for SecEng Trust Scanner.
awsmarketplacetrust_scanner
/marketplace/aws/seceng-trust-scanner
SecEng Workbench — AWS-Compatible Roadmap
AWS-compatible marketplace packaging route for SecEng Workbench.
awsmarketplaceworkbench
/marketplace/aws/seceng-workbench
AI Red Team Range Mug
A branded mug for AI red-team labs, prompt injection workshops, and long evidence-review sessions.
mug
/store/products/ai-red-team-range-mug
AI Security Engineer's Field Guide
A practical field guide for securing AI-enabled products, RAG systems, agent workflows, model integrations, and governance evidence programs.
ebook
/store/products/ai-security-engineers-field-guide
AIPSA Advanced — Exam Voucher
An exam voucher for the AIPSA Advanced credential. Demonstrates advanced knowledge and ability to design, assess, and improve AI security controls. Score range:
certification_voucher
/store/products/aipsa-advanced-voucher
AIPSA Associate — Exam Voucher
An exam voucher for the AIPSA Associate credential. Covers all 14 AI Product Security Assessment domains at the foundational level. Score range: 70–79.
certification_voucher
/store/products/aipsa-associate-voucher
AIPSA Distinguished — Exam Voucher
An exam voucher for the AIPSA Distinguished credential. Demonstrates expert-level mastery and leadership across all AI Product Security Assessment domains. Scor
certification_voucher
/store/products/aipsa-distinguished-voucher
AIPSA Distinguished Credential Notebook
A premium notebook for advanced AI Product Security Assessment work, executive review notes, and credential evidence planning.
notebook
/store/products/aipsa-distinguished-credential-notebook
AIPSA Practitioner — Exam Voucher
An exam voucher for the AIPSA Practitioner credential. Demonstrates proficient understanding and practical application across all 14 AI Product Security Assessm
certification_voucher
/store/products/aipsa-practitioner-voucher
AIPSA Practitioner Journal
A structured practitioner journal for tracking AI Product Security Assessment domains, evidence, findings, and remediation notes.
journal
/store/products/aipsa-practitioner-journal
Consultant Mission Notebook
A field notebook for independent consultants and mission teams scoping AI security engagements, SOWs, findings, and remediation plans.
notebook
/store/products/consultant-mission-notebook
Engineered for Adversarial Terrain Hoodie
A premium hoodie carrying the aisecurity.llc field slogan: Engineered for Adversarial Terrain.
apparel
/store/products/engineered-for-adversarial-terrain-hoodie
Framework Crosswalk Poster
A visual reference poster mapping AI security and governance frameworks across attack techniques, risks, governance functions, management-system themes, and sco
poster
/store/products/framework-crosswalk-poster
Governance Evidence Cards
A compact card deck for turning AI governance, security, legal, and trust-center questions into evidence prompts and artifact backlogs.
cards
/store/products/governance-evidence-cards
Security Review Attestation Stationery Pack
A branded stationery-inspired template pack for security review attestations, scope summaries, findings transmittals, and buyer-facing evidence statements.
stationery
/store/products/security-review-attestation-stationery-pack
Technical Tee
A clean aisecurity.llc technical tee for labs, workshops, conferences, and field sessions.
apparel
/store/products/aisecurity-technical-tee
The State of AI Security Engineering Report 2026
A research-backed market report on AI security roles, maturity signals, governance evidence, framework adoption, and the emerging AI Security Engineering discip
digital_report
/store/products/state-of-ai-security-engineering-report-2026
Trust Scanner Desk Pad
A desk pad inspired by Trust Scanner workflows: public artifacts, scorecard dimensions, caveats, and evidence backlog thinking.
desk_pad
/store/products/trust-scanner-desk-pad
AIPSA Credential Gear
Credential journals and notebooks for AI Product Security practice.
/store/collections/aipsa-credential-gear
Apparel
Branded shirts, hoodies, and fieldwear.
/store/collections/apparel
Desk & Field Gear
Mugs, desk pads, and field notebooks.
/store/collections/desk-field-gear
Posters & Evidence Tools
Visual references, cards, and evidence workflow aids.
/store/collections/posters-evidence-tools
Reports & Books
Research reports, field guides, and practitioner publications.
/store/collections/reports-books
Stationery
Client-facing stationery and attestation support materials.
/store/collections/stationery
Cartauth-only
/store/cartapp/store/cart/page.tsx
Checkoutauth-only
/store/checkoutapp/store/checkout/page.tsx
Order Confirmedauth-only
Your order has been received.
/store/successapp/store/success/page.tsx
Storeauth-only
/storeapp/store/page.tsx
Templates & Tooling — AI Security
Downloadable policy templates, program blueprints, playbooks, and tooling packs for AI security programs.
/marketplace/templatesapp/(public)/marketplace/templates/page.tsx

Integrations

1 page

Platform and toolchain integrations

Products

23 pages

SecEng platform products

SecEng Workbench
AI security program, trust evidence, and remediation workbench
/products/seceng-workbench
SecEng Trust Scanner
AI and security claim scanner for customer-facing trust language
/products/seceng-trust-scanner
SecEng Adversarial Range
Deployable AI security lab for RAG, agents, telemetry, and evidence validation
/products/seceng-ai-attack-range
SecEng AI Security Program Jumpstart
Expert-led AI security program launch via direct SOW
/products/seceng-program-jumpstart
Academy White-Label Partner Pack
Partner-ready AI security training content — courses, Q&A bank, LMS packages, and workforce readiness modules for training platforms, cyber ranges, and…
/products/academy-white-label-partner-pack
AI Launch Security Review
Pre-launch AI security review for product teams shipping LLM features, RAG systems, copilots, agents, or AI workflows.
/products/ai-launch-security-review
AI Security Academy
Structured AI security training for security, engineering, product, governance, and trust teams — courses, Q&A checks, LMS delivery, and private cohorts.
/products/academy-enterprise-training-pack
AIPSA Academy Access
Unlimited access to all 14 AIPSA Academy labs, reference desk, study cards, and exam prep materials
/products/academy-access
AIPSA Certification Voucher
Single-use proctored exam voucher for AIPSA Associate, Practitioner, Advanced, or Distinguished
/products/aipsa-certification-voucher
AIPSA Credential Renewal
Renew an expiring or expired AIPSA credential at any level for another 2 years
/products/aipsa-credential-renewal
AIPSA SCORM Training Package
LMS-compatible AI product security training — 16 hands-on labs, SCORM 2004, xAPI, and LTI 1.3
/products/aipsa-scorm-training
Attack Domain Bundle
All 5 Attack domain labs — Supply Chain, Memory Poisoning, Multimodal Injection, plus scanner labs
/products/academy-bundle-attack
Complete Academy Bundle
All 14 AIPSA Academy labs across Map, Attack, Defend, and Evidence
/products/academy-bundle-complete
Defend Domain Bundle
All 3 Defend domain labs — Output Safety, Agent Permissions, RAG Security
/products/academy-bundle-defend
Evidence Domain Bundle
All 4 Evidence domain runner labs — Governance, Logging & Forensics, Incident Response, RAG Data Leakage
/products/academy-bundle-evidence
Individual Lab Access
Single AIPSA Academy runner lab — scored completion, evidence export, and certificate
/products/academy-lab-access
Map Domain Bundle
All 2 Map domain runner labs — AI Inventory and AI Threat Modeling
/products/academy-bundle-map
Pen Test & Red Team Readiness Packet
Structured readiness assessment for teams scoping an external pen test or red team engagement — scope, authorization, ROE, evidence handling, and vendor…
/products/pen-test-red-team-readiness-packet
Role Readiness / Platform Partner Add-On
The role-readiness layer for cybersecurity training platforms, cyber ranges, and enterprise security teams. Role taxonomy, Q&A bank, job-market signals…
/products/ai-security-workforce-readiness-pack
SecEng Code Scanner OEM Pilot
White-label AI security scanning for vendors that already own vulnerability management, DAST, API, infrastructure, AppSec, or remediation workflows.
/products/seceng-scan-oem-pack
SecEng Code Scanner Team License
Recurring AI attack-path scanning for product security, AppSec, and developer teams
/products/seceng-code-scanner-team
SecEng Enterprise AI Security Buildout
Full-scope enterprise AI security program design, implementation, and enablement
/products/seceng-enterprise-buildout
SecEng Evidence Analytics
Evidence debt, high-risk claim, and AI security analytics for SIEM and BI platforms
/products/seceng-analytics-pack

Investor Portal

49 pages

Data room, diligence documents, and investor materials

Acquisition Scorecardauth-only
Conversation-ready acquisition posture with evidence-backed check status.
/portal/investors/acquisition
Asset Mapauth-only
Inventory of the GTM/acquisition asset tree and portal-ready routes.
/portal/investors/assets
Data Roomauth-only
Diligence room index and request list.
/portal/investors/data-room
Diligence Roomauth-only
Current repo-grounded diligence snapshot for buyer and investor review.
/portal/investors/diligence
Investor Disclosureauth-only
Public, gated, caveated, and internal disclosure boundary.
/portal/investors/disclosure
Investor Portalauth-only
Authenticated diligence portal with live corpus metrics, proof dashboards, acquisition scorecards, and asset inventory.
/portal
IP Protectionsauth-only
Ownership, source, license, and confidentiality boundaries.
/portal/investors/ip
Partner Portal
Authenticated portal for approved partners — contracts, billing, onboarding, and GTM resources.
/portal/partners
Deltaauth-only
Refresh summary and content changes since the last portal sync.
/portal/investors/delta
FAQauth-only
Quick answers for buyers, investors, and internal reviewers using the portal.
/portal/investors/faq
Methodologyauth-only
How the investor portal is sourced, refreshed, labeled, and validated.
/portal/investors/methodology
Policyauth-only
Access, sharing, and claim-posture policy for the portal.
/portal/investors/policy
Proof Dashboardauth-only
Live proof metrics and current validation gaps.
/portal/investors/proof
Rules of Engagementauth-only
Access, sharing, forwarding, and claim-use rules for the portal.
/portal/investors/rules-of-engagement
Valuationauth-only
Transparent valuation framework with TBD financial inputs.
/portal/investors/valuation
Abmauth-only
/portal/consultants/abmapp/(public)/portal/consultants/abm/page.tsx
Accessauth-only
/portal/admin/accessapp/(public)/portal/admin/access/page.tsx
Adminauth-only
/portal/adminapp/(public)/portal/admin/page.tsx
Alertsauth-only
/portal/admin/alertsapp/(public)/portal/admin/alerts/page.tsx
Analyticsauth-only
/portal/admin/analyticsapp/(public)/portal/admin/analytics/page.tsx
Clientsauth-only
/portal/consultants/clientsapp/(public)/portal/consultants/clients/page.tsx
Co Brandingauth-only
/portal/partners/co-brandingapp/(public)/portal/partners/co-branding/page.tsx
Commercial Proposalsauth-only
/portal/admin/commercial-proposalsapp/(public)/portal/admin/commercial-proposals/page.tsx
Consultantsauth-only
/portal/consultantsapp/(public)/portal/consultants/page.tsx
Contractsauth-only
/portal/partners/contractsapp/(public)/portal/partners/contracts/page.tsx
Customersauth-only
/portal/admin/customersapp/(public)/portal/admin/customers/page.tsx
Customersauth-only
/portal/partners/customersapp/(public)/portal/partners/customers/page.tsx
Deliverablesauth-only
/portal/admin/deliverablesapp/(public)/portal/admin/deliverables/page.tsx
Documentsauth-only
/portal/admin/documentsapp/(public)/portal/admin/documents/page.tsx
Engagementsauth-only
/portal/admin/engagementsapp/(public)/portal/admin/engagements/page.tsx
Entitlementsauth-only
/portal/admin/entitlementsapp/(public)/portal/admin/entitlements/page.tsx
Evidenceauth-only
/portal/admin/evidenceapp/(public)/portal/admin/evidence/page.tsx
Gtmauth-only
/portal/partners/gtmapp/(public)/portal/partners/gtm/page.tsx
Intakesauth-only
/portal/admin/intakesapp/(public)/portal/admin/intakes/page.tsx
Investorsauth-only
/portal/investorsapp/(public)/portal/investors/page.tsx
Launch Roomsauth-only
/portal/admin/launch-roomsapp/(public)/portal/admin/launch-rooms/page.tsx
Notificationsauth-only
/portal/admin/notificationsapp/(public)/portal/admin/notifications/page.tsx
Onboardingauth-only
/portal/partners/onboardingapp/(public)/portal/partners/onboarding/page.tsx
Opportunitiesauth-only
/portal/admin/opportunitiesapp/(public)/portal/admin/opportunities/page.tsx
Pipelineauth-only
/portal/admin/pipelineapp/(public)/portal/admin/pipeline/page.tsx
Proposalsauth-only
/portal/admin/proposalsapp/(public)/portal/admin/proposals/page.tsx
Quotesauth-only
/portal/admin/quotesapp/(public)/portal/admin/quotes/page.tsx
Releasesauth-only
/portal/partners/releasesapp/(public)/portal/partners/releases/page.tsx
Resourcesauth-only
/portal/partners/resourcesapp/(public)/portal/partners/resources/page.tsx
Settingsauth-only
/portal/partners/settingsapp/(public)/portal/partners/settings/page.tsx
Stripe Eventsauth-only
/portal/admin/stripe-eventsapp/(public)/portal/admin/stripe-events/page.tsx
Supportauth-only
/portal/partners/supportapp/(public)/portal/partners/support/page.tsx
Technicalauth-only
/portal/partners/technicalapp/(public)/portal/partners/technical/page.tsx
Usageauth-only
/portal/partners/usageapp/(public)/portal/partners/usage/page.tsx

Trust Center

49 pages

Attestations, contracts, and published security posture

Academy Content License Addendum
Licensed content definition, permitted use, white-label rights, sublicensing limits, prohibited uses, IP ownership, claim boundaries, and wind-down terms for…
contractlegalacademy
/trust-center/contracts/academy-content-license-addendum
Academy Credential & Completion Policy
What Academy course completion badges and records mean — and explicitly do not mean. Not product-security certification, employment qualification, SOC 2, ISO…
contractlegalacademy
/trust-center/contracts/academy-credential-completion-policy
Academy Enterprise Training Terms
Enterprise seat access, materials rights, LMS package terms, private cohort conditions, completion records, data handling, acceptable use, support, and claim…
contractlegalacademy
/trust-center/contracts/academy-enterprise-training-terms
Academy LMS Package Addendum
LMS delivery rights, seat limits, SCORM 1.2 preview status, modification restrictions, branding, reporting, update obligations, and expiration for enterprise…
contractlegalacademy
/trust-center/contracts/academy-lms-package-addendum
Agentic Workflow ROE Addendum
Bounds testing of tool-using agents and automated workflows — tools/actions in scope, authorized adversarial techniques, action boundaries, rollback…
contractlegalagentic
/trust-center/contracts/agentic-workflow-roe-addendum
AI Launch Security Review SOW
Scoped statement of work for the pre-release AI Launch Security Review — first findings in 5 business days, launch-ready review in 5–10. Auto-populated from…
contractlegalai
/trust-center/contracts/ai-launch-review-sow
AI Red Team Rules of Engagement
Rules of engagement for authorized AI red-team validation, including targets, test windows, allowed techniques, prohibited actions, safety controls, evidence…
contractlegalai
/trust-center/contracts/ai-red-team-rules-of-engagement
Annual OEM License Order Form
Annual OEM license order form: partner details, licensed modules, seat/org counts, pricing schedule, payment terms, and effective date.
contractlegalannual
/trust-center/contracts/annual-oem-license-order-form
Assessment Terms Addendum
Scope, authorization, evidence use, testing boundaries, safe harbor, retesting, reporting limitations, and reliance limits for AI product security assessments.
contractlegalassessment
/trust-center/contracts/assessment-terms-addendum
Attestations
/trust-center/attestationsapp/(public)/trust-center/attestations/page.tsx
Cloud Testing Boundary Addendum
Bounds cloud/infrastructure testing — separates customer-owned active testing targets from configuration-review targets and from provider infrastructure, with…
contractlegalcloud
/trust-center/contracts/cloud-testing-boundary-addendum
Commercial Services Addendum
Converts the services framework into scoped paid work with rate card, invoicing, and activation terms.
contractlegalretainer
/trust-center/contracts/retainer-billing-addendum
Consultant Mission Brief
Defines specialist role, client relationship model, confidentiality, deliverables, and independence boundary for consultant-led missions.
contractlegalconsultant
/trust-center/contracts/consultant-mission-brief
Contracts
/trust-center/contractsapp/(public)/trust-center/contracts/page.tsx
Data Processing Addendum
Controller/processor allocation, data protection obligations, subprocessing, security measures, AI provider boundaries, and customer-data handling for scoped…
contractlegaldpa
/trust-center/contracts/dpa-lite-addendum
Data Retention & Redaction Policy
How aisecurity.llc retains, redacts, returns, and deletes platform records, scoping data, evidence, packets, billing records, and operational logs across…
contractlegaldata
/trust-center/contracts/data-retention-redaction-policy
Evidence Handling Policy
How aisecurity.llc collects, protects, uses, redacts, retains, and shares security evidence across scoping, assessments, red-team work, generated packets, and…
contractlegalevidence
/trust-center/contracts/evidence-handling-policy
Governance
/trust-center/attestations/governanceapp/(public)/trust-center/attestations/governance/page.tsx
Launch Gate Assessment Terms Addendum
Authorized scope, safe harbor, reliance limits, and claim caveats for pre-release AI Launch Security Reviews. Required for all launch-gate engagements.
contractlegallaunch
/trust-center/contracts/launch-gate-assessment-terms-addendum
Launch Gate Evidence Handling Policy
Evidence handling, retention schedule, destruction obligations, and redaction requirements for launch-gate review evidence. Governs working notes…
contractlegallaunch
/trust-center/contracts/launch-gate-evidence-handling-policy
Launch Gate Statement of Work
Scope template for the AI Launch Security Review: targets, testing window, deliverables (Launch Risk Memo, Abuse-Path Findings, Release Gate Checklist, Sprint…
contractlegallaunch
/trust-center/contracts/launch-gate-sow
Mutual NDA
Mutual confidentiality protections for pre-sales, delivery, and research collaboration contexts.
contractlegalmutual
/trust-center/contracts/mutual-nda
No-Cost Scoping Retainer
Pre-engagement scoping: $0 fees, no obligation, NDA path, access boundaries, and a draft review plan before any paid work. Converts to a paid SOW only after…
contractlegalno
/trust-center/contracts/no-cost-scoping-retainer
OEM Scanner License Addendum
Technical licensing terms for scanner OEM embeddings: permitted use, redistribution scope, white-label rights, customer-org tracking, usage credit…
contractlegaloem
/trust-center/contracts/oem-scanner-license-addendum
Penetration Test & Red Team Rules of Engagement
Rules of engagement for scoped penetration testing and adversarial red team work — authorization, targets, allowed and prohibited techniques, testing window…
contractlegalpentest
/trust-center/contracts/pentest-rules-of-engagement
Publication & Claim-Readiness Policy
Claim-readiness criteria for public research, trust pages, scorecards, attestations, sponsor materials, security review outputs, and buyer-facing evidence.
contractlegalpublication
/trust-center/contracts/publication-claim-readiness-policy
Rag Authorization
/trust-center/attestations/rag-authorizationapp/(public)/trust-center/attestations/rag-authorization/page.tsx
Red Team
/trust-center/attestations/red-teamapp/(public)/trust-center/attestations/red-team/page.tsx
Sample
/trust-center/attestations/governance/sampleapp/(public)/trust-center/attestations/governance/sample/page.tsx
Sample
/trust-center/attestations/rag-authorization/sampleapp/(public)/trust-center/attestations/rag-authorization/sample/page.tsx
Sample
/trust-center/attestations/red-team/sampleapp/(public)/trust-center/attestations/red-team/sample/page.tsx
Sample
/trust-center/attestations/sampleapp/(public)/trust-center/attestations/sample/page.tsx
Sample
/trust-center/attestations/trust-surface/sampleapp/(public)/trust-center/attestations/trust-surface/sample/page.tsx
Scanner Provider Pilot SOW
30-day OEM pilot scope for scanner vendors: integration path, success criteria, support boundaries, usage credits, and conversion path to production OEM…
contractlegalscanner
/trust-center/contracts/scanner-provider-pilot-sow
Scoped Services Framework
Master services framework for discovery, product review, red-team validation, governance evidence, and paid scopes without a standing retainer.
contractlegalzero
/trust-center/contracts/zero-dollar-services-retainer
Secure Sdlc
/trust-center/secure-sdlcapp/(public)/trust-center/secure-sdlc/page.tsx
Security
/trust-center/securityapp/(public)/trust-center/security/page.tsx
Security Operations Schedule
Operational control schedule for authorized AI security work, covering access, credentials, logging, AI/ML testing boundaries, incident handling, evidence…
contractlegalsecurity
/trust-center/contracts/security-operations-schedule
Special Approval Addendum
Explicit authorization gate for high-impact activities (DoS/stress, phishing, social engineering, physical, malware/C2, third-party/shared-tenant). Excluded…
contractlegalspecial
/trust-center/contracts/special-approval-addendum
Sponsorship Agreement
Commercial sponsorship terms with explicit research-independence and disclosure boundaries.
contractlegalsponsorship
/trust-center/contracts/sponsorship-agreement
Sponsorship Launch Addendum
Campaign schedule, sponsor assets, labeling, approval process, and launch deliverables.
contractlegalsponsorship
/trust-center/contracts/sponsorship-launch-addendum
Statement of Work Template
Mission-specific scope, deliverables, timeline, access, assumptions, and acceptance criteria for scoped AI security engagements.
contractlegalstatement
/trust-center/contracts/statement-of-work
Trust Center
/trust-centerapp/(public)/trust-center/page.tsx
Trust Surface
/trust-center/attestations/trust-surfaceapp/(public)/trust-center/attestations/trust-surface/page.tsx
Vendor Pilot | Trust Center
Prove one representative workflow before production licensing. Bounded pilot scope, acceptance criteria, responsibility matrix, data boundary, IP ownership…
/trust-center/vendor-pilotapp/(public)/trust-center/vendor-pilot/page.tsx
Vendor Review & Procurement
Review aisecurity.llc security, responsible AI, data handling, contracts, vendor onboarding, and OEM partner diligence in one place.
/trust-center/vendor-packetapp/(public)/trust-center/vendor-packet/page.tsx
Workforce Content License Agreement
Content licensing terms for workforce readiness programs: permitted uses, role-taxonomy rights, Q&A bank access, white-label conditions, sublicensing limits…
contractlegalworkforce
/trust-center/contracts/workforce-content-license-agreement
Workforce Partner Pilot SOW
Pilot engagement scope for workforce readiness partners: delivery scope, cohort configuration, success criteria, data handling, support terms, and production…
contractlegalworkforce
/trust-center/contracts/workforce-partner-pilot-sow
Workforce Platform Order Form
Order form for workforce platform access: organization details, seat counts, licensed modules, pricing, and effective date.
contractlegalworkforce
/trust-center/contracts/workforce-platform-order-form

Documentation

25 pages

Guides and reference material

SecEng Developer Center
Integrate SecEng behind your existing product: CLI, HTTP sidecar, structured outputs, and partner adapters.
/developers/seceng
Generated Reference
CLI, API, schema, error, capability, and example reference generated from the shipping SecEng engine.
/developers/seceng/reference
CLI Quickstart
Invoke the SecEng CLI as a headless process and consume structured outputs.
/developers/seceng/quickstart/cli
Deployment and Security
Choose an integration mode while preserving target, credential, and evidence boundaries.
/developers/seceng/deployment-and-security
HTTP Sidecar Quickstart
Run SecEng behind a persistent local service for job submission, polling, and cancellation.
/developers/seceng/quickstart/http-sidecar
Integration Patterns
Reusable patterns for scanners, offensive platforms, OEM products, and managed services.
/developers/seceng/integration-patterns
Outputs and Evidence
How SecEng structures findings, SARIF, evidence, and attack-path results.
/developers/seceng/outputs-and-evidence
Partner Pilots
Prove one representative contract before building a native integration.
/developers/seceng/partner-pilots
Diagnostics and Support
Collect safe operational context without exposing customer secrets.
/developers/seceng/diagnostics
Examples
Run generated golden workflows rather than copying stale hand-authored payloads.
/developers/seceng/examples
Versioning and Upgrades
How SecEng tracks compatibility across the engine, API, schemas, and individual capabilities.
/developers/seceng/versioning
API Reference
Generated OpenAPI summary for SecEng HTTP operations.
/developers/seceng/reference/api
Capabilities Reference
Generated SecEng capability registry.
/developers/seceng/reference/capabilities
CLI Reference
Generated seceng CLI command index.
/developers/seceng/reference/cli
Examples Reference
Generated fixture index from seceng-scan-content.
/developers/seceng/reference/examples
Schema Reference
Generated JSON Schema index from seceng-scan-content.
/developers/seceng/reference/schemas
Errors Reference
Status of the SecEng partner-facing error catalog.
/developers/seceng/reference/errors
Downloads
Packaged Developer Center downloads — currently none; reference pages are the live source.
/developers/seceng/downloads
Workforce Accountauth-only
Authenticated workspace for EMPOWER, CORE, and RISE attempts, assessments, reports, and results.
/account/workforce
AI Model Gateways and Secure Platforms Printauth-only
Print-oriented manuscript for the AI Model Gateways and Secure Platforms course.
/academy/courses/model-gateways-and-secure-ai-platform-engineering/print
AI Product Management for Secure AI Features Printauth-only
Print-oriented manuscript for the AI Product Management for Secure AI Features course.
/academy/courses/ai-product-management-for-secure-ai-features/print
AI Red Teaming for Product Teams Printauth-only
Print-oriented manuscript for the AI Red Teaming for Product Teams course.
/academy/courses/ai-red-teaming-for-product-teams/print
AI Security for Sales Engineers Printauth-only
Print-oriented manuscript for the AI Security for Sales Engineers course.
/academy/courses/ai-security-for-sales-engineers/print
Hiring AI-Savvy Talent Without Unicorn Hunting Printauth-only
Print-oriented manuscript for the Hiring AI-Savvy Talent Without Unicorn Hunting course.
/academy/courses/hiring-ai-savvy-talent-without-unicorn-hunting/print
Secure Coding with GenAI Printauth-only
Print-oriented manuscript for the Secure Coding with GenAI course.
/academy/courses/secure-coding-with-genai/print

Auth & Account

5 pages

Sign-in, workspace, and account access

More

89 pages

Additional pages and resources

AIPSA
AI Product Security Assessment route.
/aipsa
${mythosBook.title}
Strategic report and operating playbook for securing AI-native products as AI-assisted discovery compresses defender time.
/mythosapp/(public)/mythos/page.tsx
About
AI security engineering for teams shipping LLM apps, RAG systems, agents, copilots, and AI workflows.
/aboutapp/(public)/about/page.tsx
Ai Governance
/ai-governanceapp/(public)/ai-governance/page.tsx
AI Security Engineering Field Guide
Practitioner playbooks for securing LLM apps, RAG systems, agents, AI workflows, and governance evidence.
/field-guideapp/(public)/field-guide/page.tsx
AI Security Engineering for Real AI Products (v0 backup)
Product security for AI systems. Map risk, test abuse paths, harden release controls, and prepare evidence that survives enterprise review.
/index-v0app/(public)/index-v0/page.tsx
AI Security Engineering Handbook 2026 — Study Companion
A structured study companion for AI security engineering practitioners, candidates, and teams covering foundations, roles, controls, evidence, and assessment.
/handbookapp/(public)/handbook/page.tsx
AI Security Products & SecEng Workbench
Security engineering you can use directly and infrastructure that makes expert testing deeper.
/productsapp/(public)/products/page.tsx
AIPSA Flash Cards — Study Now
150+ practitioner-level cards across all four M.A.D.E. pillars. Study free in-browser or buy the physical deck.
/study-cards/previewapp/(public)/study-cards/preview/page.tsx
Api
/apiapp/(public)/api/page.tsx
Books
Long-form research from The State of AI Security Engineering Report project.
/booksapp/(public)/books/page.tsx
Buy a Time Bank
Pre-purchase expert security hours with no expiry. Use them for any service — red team, detection, governance, or advisory.
/engage/bookapp/(public)/engage/book/page.tsx
Charts
/chartsapp/(public)/charts/page.tsx
Citationsauth-only
/citationsapp/citations/page.tsx
Co-brand The State of AI Security Engineering Report 2026
One Founding Research Partnership and up to two Presenting Sponsor placements on the 2026 report and the research roadmap behind it. Disclosed sponsorship…
/sponsorsapp/(public)/sponsors/page.tsx
Contracts
/contractsapp/(public)/contracts/page.tsx
Corrections — The State of AI Security Engineering 2026
Correction status and dated correction entries for The State of AI Security Engineering 2026.
/report/correctionsapp/(public)/report/corrections/page.tsx
Customer Data And Model Training
/ai-governance/customer-data-and-model-trainingapp/(public)/ai-governance/customer-data-and-model-training/page.tsx
Data
/dataapp/(public)/data/page.tsx
Engagement Planner
Your AI security program deployment dashboard — tracking stages, team rollout, milestones, and your dedicated architect contact.
/enterprise/plannerapp/(public)/enterprise/planner/page.tsx
Enterprise AI Security
Enterprise-grade AI security engineering programs.
/enterpriseapp/(public)/enterprise/page.tsx
Enterprise SSO Waitlist
Early access for SAML 2.0, SCIM 2.0, and IdP-initiated SSO.
/enterprise/ssoapp/(public)/enterprise/sso/page.tsx
Figure Compiler Repair Proof Gallery
/publication-dsl/figures/proofapp/(public)/publication-dsl/figures/proof/page.tsx
Footer Preview
/footer-previewapp/(public)/footer-preview/page.tsx
Historical
/historicalapp/(public)/historical/page.tsx
Internships
/careers/internshipsapp/(public)/careers/internships/page.tsx
Join the Roster
Join the AI security consulting roster. Maintain your own clients, billing, and calendar. Build a public profile and opt into missions.
/roster/joinapp/(public)/roster/join/page.tsx
LinkedIn Mastheads
Publication-ready LinkedIn masthead compositions for aisecurity.llc profiles and company pages.
/linkedin-mastheadsapp/(public)/linkedin-mastheads/page.tsx
Methodology
/methodologyapp/(public)/methodology/page.tsx
Participate — The State of AI Security Engineering 2026
Take the AI security practitioner survey or test your competency with domain-specific assessments.
/participateapp/(public)/participate/page.tsx
Press
/pressapp/(public)/press/page.tsx
Press & Media
Logo assets, brand lockups, icons, colors, boilerplate, press copy, and publication resources.
/mediaapp/(public)/media/page.tsx
Previewauth-only
/internal/figure-studio/previewapp/(internal)/internal/figure-studio/preview/page.tsx
Profiles
/profilesapp/(public)/profiles/page.tsx
Publication Dsl
/publication-dslapp/(public)/publication-dsl/page.tsx
Publications
/publicationsapp/(public)/publications/page.tsx
Request Received | AI Security Workbench
Your early access request has been received. We'll activate your access shortly.
/waitlist/confirmationapp/(public)/waitlist/confirmation/page.tsx
Responsible Ai
/ai-governance/responsible-aiapp/(public)/ai-governance/responsible-ai/page.tsx
Resume / CV | David Wolf
Resume and CV links for David Wolf, with pointers to portfolio evidence and consulting surfaces.
/resumeapp/(public)/resume/page.tsx
Retainer
/retainerapp/(public)/retainer/page.tsx
Roles
/rolesapp/(public)/roles/page.tsx
Scopeauth-only
/start/scopeapp/start/scope/page.tsx
SCOPE — Engagement Planner
SCOPE is a 5–10 minute interactive planner that turns AI security ambiguity into a clear, measurable prescription. No account required.
/scopeapp/(public)/scope/page.tsx
Scope an Engagement
Scope buyer-ready AI security support, procurement review, or evidence-backed advisory work.
/engageapp/(public)/engage/page.tsx
SCOPE Discovery Session
Answer targeted questions to build your working hypothesis and receive a prescriptive recommendation.
/scope/sessionapp/(public)/scope/session/page.tsx
SCOPE Results — Prescription & Artifacts
Your SCOPE prescription, PoC charter, candidate comparison, and evaluation plan.
/scope/resultsapp/(public)/scope/results/page.tsx
Scorecard
/scorecardapp/(public)/scorecard/page.tsx
Seceng Code Scanner
/products/seceng-code-scannerapp/(public)/products/seceng-code-scanner/page.tsx
SecEng Figure Library
/publication-dsl/figuresapp/(public)/publication-dsl/figures/page.tsx
SecEng Figure Studioauth-only
/internal/figure-studioapp/(internal)/internal/figure-studio/page.tsx
SecEng Workbench | AI Security Engineering Platform
Map AI systems, reproduce adversarial behavior, validate attack paths, harden controls, and preserve engineering and buyer evidence with the SecEng Workbench.
/platformapp/(public)/platform/page.tsx
Sitemap
Complete index of the AI Security Engineering site.
/sitemapapp/(public)/sitemap/page.tsx
Social
/socialapp/(public)/social/page.tsx
Start AI Security Scoping
Start from the decision you need to make and route to the smallest useful AI security engagement.
/startapp/(public)/start/page.tsx
Status
Live operational status for site services and dependencies.
/statusapp/(public)/status/page.tsx
Survey Findings & Live Dashboard
Primary research findings and live aggregate results from The State of AI Security Engineering 2026 survey program.
/survey/resultsapp/(public)/survey/results/page.tsx
Surveys
Survey instruments and methodology notes for AI security hiring, leadership, practitioner, and workforce readiness testing.
/surveyapp/(public)/survey/page.tsx
Talent
/talentapp/(public)/talent/page.tsx
Terms
/termsapp/(public)/terms/page.tsx
Thanksauth-only
/start/scope/thanksapp/start/scope/thanks/page.tsx
The State of AI Security Engineering Report 2026
Job-description intelligence on what companies are actually hiring for when they say AI Security Engineer.
/reportapp/(public)/report/page.tsx
Unsubscribe
/unsubscribeapp/(public)/unsubscribe/page.tsx
Vciso
/vcisoapp/(public)/vciso/page.tsx
Verticals
/verticalsapp/(public)/verticals/page.tsx
Workshops
/workshopsapp/(public)/workshops/page.tsx
Agentic Riskauth-only
/outreach/ai-platform/agentic-risk
Ai Security Maturityauth-only
/outreach/ciso/ai-security-maturity
Enterprise Readinessauth-only
/outreach/founders/enterprise-readiness
Governance Operating Modelauth-only
/outreach/ciso/governance-operating-model
Procurement Frictionauth-only
/outreach/founders/procurement-friction
Research Partnershipauth-only
/outreach/sponsors/research-partnership
Sponsor The Reportauth-only
/outreach/sponsors/sponsor-the-report
Tool Permission Boundariesauth-only
/outreach/ai-platform/tool-permission-boundaries
Academyauth-only
/account/academyapp/(public)/account/academy/page.tsx
Accountauth-only
/accountapp/(public)/account/page.tsx
Adminauth-only
/account/workforce/adminapp/(public)/account/workforce/admin/page.tsx
Assessmentsauth-only
/account/workforce/assessmentsapp/(public)/account/workforce/assessments/page.tsx
Attemptsauth-only
/account/workforce/attemptsapp/(public)/account/workforce/attempts/page.tsx
Billingauth-only
Manage subscriptions, view invoice history, and access the billing portal.
/account/billingapp/(public)/account/billing/page.tsx
Deliverablesauth-only
/account/deliverablesapp/(public)/account/deliverables/page.tsx
Downloadsauth-only
/account/downloadsapp/(public)/account/downloads/page.tsx
Engagementsauth-only
/account/engagementsapp/(public)/account/engagements/page.tsx
Evidenceauth-only
/account/evidenceapp/(public)/account/evidence/page.tsx
Intakesauth-only
/account/intakesapp/(public)/account/intakes/page.tsx
Launchauth-only
/account/launchapp/(public)/account/launch/page.tsx
Orgauth-only
/onboard/orgapp/(public)/onboard/org/page.tsx
Projectsauth-only
/account/projectsapp/(public)/account/projects/page.tsx
Sessionsauth-only
/account/sessionsapp/(public)/account/sessions/page.tsx
Teamauth-only
/account/academy/teamapp/(public)/account/academy/team/page.tsx

Product

13 pages
AI Security Workforce Readiness
Role readiness, EMPOWER readiness signals, CORE interview practice, RISE planning, job-market intelligence, and white-label workforce reporting for AI…
/products/ai-security-workforce-readiness
AI Security Career Explorer
NIST NICE-aligned career planning extended for AI product security, red teaming, RAG, agentic workflows, and governance.
/products/ai-security-workforce-readiness/career-explorer
CORE Interview Practice
Technical and behavioral interview practice for AI security roles using scenario judgment, STAR evidence, and structured feedback.
/products/ai-security-workforce-readiness/core-interview-practice
EMPOWER Readiness Surveys
EMPOWER survey-based work-style and readiness signals for AI security training, coaching, role orientation, and interview preparation.
/products/ai-security-workforce-readiness/readiness-surveys
AI Security Hiring Calibration
Define the real AI security role, rewrite the JD, build a calibrated interview loop, and align the panel on what good looks like.
/products/ai-security-workforce-readiness/hiring-calibration
AI Security Job Navigator
Live AI security job-market intelligence: title normalization, hiring signals, role archetypes, and role-market mapping.
/products/ai-security-workforce-readiness/job-navigator
Q&A Credential Bank
Scenario-based AI security knowledge checks for role readiness, academy support, enterprise benchmarking, and white-label partner programs.
/products/ai-security-workforce-readiness/q-and-a-credential-bank
RISE Journey
Reflective planning and self-discovery for AI security practitioners and teams.
/products/ai-security-workforce-readiness/rise
Eval Coverage Auditor
Measure whether AI security evaluations cover prompt injection, tool abuse, RAG, memory, tenant isolation, and other critical risks.
/evidence/eval-coverage-auditor
Prompt Asset Scanner
Inventory system prompts, developer prompts, agent instructions, tool prompts, and prompt templates across repositories.
/map/prompt-asset-scanner
Agent Permission Diff | Agent Permission Review & Hardening
Compare declared tool permissions against observed capabilities, scopes, and side effects to reduce excessive agent privileges.
/defend/agent-authority-diff
AI Dependency Risk | AI-Aware Dependency Risk Interpretation
Identify AI-specific dependency, model loader, framework, vector store, and supply-chain risks without replacing existing SCA tools.
/defend/supply-chain-risk
Tool Capsule Analysis
Analyze MCP servers, OpenAPI specifications, and AI tool definitions to understand capabilities, permissions, side effects, and attack surface.
/map/tool-capsule-analyzer

Generated July 31, 2026 · 1,416 total routes