aisecurity.llc
hello@aisecurity.llc
Operational Policy · Negotiation Draft
Academy Credential & Completion Policy
What Academy course completion badges and records mean — and explicitly do not mean. Not product-security certification, employment qualification, SOC 2, ISO, or compliance attestation.
This Policy defines what AI Security Academy course completion, Q&A check results, lab badges, and credentials mean — and what they explicitly do not mean. This Policy applies to all learners, enterprise training managers, and platform partners delivering Academy content.
1. Purpose
Academy completion records and credentials are training records. They reflect that a learner completed a defined set of course modules, passed a Q&A check or lab exercise, or participated in a structured training program. They do not certify security posture, employment fitness, regulatory compliance, or any outcome beyond the training activity itself.
This Policy exists to prevent overclaiming, protect employers and learners from relying on training records as standalone hiring or compliance decisions, and ensure that any external reference to Academy credentials is accurate and appropriately scoped.
2. What Completion Records Are
Academy completion records, including course completion status, Q&A check scores, lab completion flags, and speed-run or flash-card results, are:
- Training records — documentation that a learner engaged with and completed a defined learning activity
- Point-in-time signals — reflecting the learner's demonstrated knowledge at the time of the assessment, in the format and context of the Academy exercise
- Development inputs — appropriate for informing coaching, training path decisions, role orientation, and team capability planning
- Internal references — for use by the customer organization in managing and planning its training program
3. What Completion Records Are Not
Academy completion records, badges, and credentials are explicitly not:
- A product-security certification — course completion does not certify that a learner's product, system, or organization is secure
- An employment qualification — Q&A scores and lab completions are learning signals; they may not be used as the sole or primary basis for employment, termination, promotion, or compensation decisions
- A regulatory compliance attestation — completing AI security courses does not constitute SOC 2, ISO 27001, NIST, or any other regulatory compliance
- A penetration test or vulnerability assessment — Academy training is not an authorized security engagement; completion does not authorize or constitute security testing
- A professional certification — AIPSA certification (where applicable) is a separate credentialing program with its own exam and standards; course completion is not equivalent to AIPSA certification unless the AIPSA exam has been passed
- A guarantee of security readiness — completion signals engagement with learning content, not mastery, operational competence, or absence of security risk
4. AIPSA Certification
Where AIPSA certification is referenced, it is governed separately by the AIPSA Certification Program terms. Course completion may satisfy prerequisites for AIPSA exam eligibility but does not itself confer AIPSA certification. AIPSA credentials are issued only after the relevant examination has been passed.
5. Hiring and Employment Use
Academy Q&A checks, lab scores, and course completion results may be used as one input in a human-reviewed hiring, development, or team-planning process. They must not be:
- The sole basis for hiring, termination, promotion, or compensation decisions
- Represented to candidates or employees as a comprehensive competency assessment
- Used without human review of the result in context of the specific role and organization
Employers are responsible for ensuring that any use of Academy results in employment decisions complies with applicable employment law.
6. Partner and Customer Claims
Partners and enterprise customers may reference Academy completion in:
- Internal learning and development records
- Team capability planning and gap analysis
- Role-readiness summaries with appropriate caveats
- Buyer-facing trust documentation where explicitly scoped and caveated
Partners and enterprise customers may not:
- Claim that Academy completion "certifies" a learner, product, or organization without qualification
- Use Academy completion as a standalone security review or audit substitute
- Issue external certificates that imply regulatory or professional certification status beyond the training record
All external claims referencing Academy completion, credential status, or Q&A results must include a reference to the scope, date, and training-record nature of the credential.
7. Completion Language
Approved completion language:
"to be specified during scoping completed the [course name] course in the AI Security Academy on [date]. This reflects completion of the structured course modules and Q&A checks included in that course. This is a training record and does not certify security posture, employment fitness, regulatory compliance, or product security status."
Shortened completion language (for badges and digital credentials):
"AI Security Academy — [course name] — Completed [date] — Training record."
8. Psychometric and Work-Style Outputs
Where Academy or Workforce Readiness modules include work-style signals, readiness diagnostic outputs, or orientation assessments, these outputs are coaching and development signals. They are not:
- Clinical psychometric assessments
- Validated employment selection instruments
- Predictors of job performance in a legally validated sense
These outputs must not be used as standalone employment decisions. Human review, role-specific validation, and compliance with applicable employment law are required.
This Policy applies to all Academy engagements. In the event of conflict with an Order Form or partner agreement, the Order Form or agreement governs where it specifically addresses credential terms. This document does not constitute legal advice.