5 practitioner workshops, 2 hours each, $99 per session. Hands-on, live, and taught by working security architects — not pre-recorded, no replay.
A hands-on, 2-hour LIVE workshop from the security architect who holds a U.S. patent on Cross-Prompt Injection Attack (XPIA) prevention — built for engineers who need working defenses, not theory.
| Module | Content |
|---|---|
| The Threat Landscape | What prompt injection is, why it's fundamentally different from traditional injection attacks (SQLi/XSS), real-world incident examples |
| Attack Taxonomy | Direct injection, indirect injection (via documents/tools/web content), cross-prompt injection attacks (XPIA), multi-turn/session attacks |
| Defense Architecture | Input/output boundary design, trust-tier segmentation, content provenance tracking — the pattern behind the patented XPIA approach |
| Live Walkthrough | Applying the defense pattern to a working example application, identifying gaps in a vulnerable design |
| Your Action Plan | Checklist handout, prioritization framework for fixing existing systems, live Q&A |
Taught by an industry expert with 15+ years of security experience at top companies in the USA.
No — this is a live session only. There is no recording or on-demand access, so you'll want to attend live to get the content and ask questions directly.
No — this is security-first, not model-training content. Basic familiarity with how LLM applications work is helpful.
No. The patterns apply across any LLM provider or agent framework.
Yes, a certificate of completion is provided.
A practical 2-hour LIVE workshop on securing Model Context Protocol (MCP) deployments — taught by the person who founded Microsoft's MCP Security program.
| Module | Content |
|---|---|
| Why MCP Needs Its Own Threat Model | How MCP differs from traditional API security, what makes the agent-tool boundary uniquely risky |
| Core Attack Patterns | Tool poisoning, confused-deputy attacks, consent and scope bypass, malicious tool descriptions |
| Auth, Consent & Scoping | Designing least-privilege tool access, session boundaries, human-in-the-loop consent patterns |
| Securing Your MCP Server | Hands-on checklist walkthrough — hardening a server before it goes to production |
| Vendor Risk & Live Q&A | How to evaluate third-party MCP connectors, open live Q&A |
Taught by an industry expert with 15+ years of security experience at top companies in the USA. This is first-mover content in a space where formal guidance is still scarce.
No — this is a live session only. There is no recording or on-demand access.
No — this works whether you're evaluating MCP or already have it in production.
No, the threat model and checklist apply broadly across MCP deployments.
A 2-hour, LIVE, take-it-back-to-work framework for auditing agentic AI systems — built for GRC, compliance, and internal audit teams who need something usable Monday morning.
| Module | Content |
|---|---|
| Why Traditional Audit Frameworks Fall Short | The unique properties of agentic systems that break standard audit assumptions |
| The Audit Checklist | Permission and scope review, decision-boundary mapping, logging/traceability requirements |
| Mapping to NIST AI RMF | Where agentic-specific controls fit into existing governance frameworks |
| Incident Response Tabletop | A guided walkthrough of an agent-failure scenario and how to respond |
| Building Your Program & Live Q&A | Prioritization guidance, open live Q&A |
Taught by an industry expert with 15+ years of security experience at top companies in the USA.
No — this is a live session only. There is no recording or on-demand access.
No — this is designed for audit/compliance professionals, not engineers.
Yes, the checklist is designed to be adapted directly into audit workpapers.
A 2-hour LIVE workshop demystifying how personal data moves through training, inference, and RAG pipelines — with a practical privacy-review template you can use immediately.
| Module | Content |
|---|---|
| How Data Actually Flows Through AI Systems | Training data, fine-tuning, inference-time context, RAG retrieval — where PII enters and where it can leak |
| Common Leakage Patterns | Memorization, prompt-context leakage, retrieval over-exposure, logging/telemetry risk |
| Differential Privacy, Demystified | What it does and doesn't protect against, when it's worth the complexity |
| The Privacy Review Template | Walking through a practical review process for a new AI feature or vendor |
| Vendor Questions & Live Q&A | The questions to ask any AI vendor, open live Q&A |
Taught by an industry expert with 15+ years of security experience at top companies in the USA.
No — this is a live session only. There is no recording or on-demand access.
The concepts apply across privacy regimes; specific regulatory citations are referenced where relevant but this isn't a legal-compliance course.
No — this is written for privacy and product professionals.
A 2-hour, LIVE, practical workshop for building a lightweight responsible-AI review process your engineering team will actually follow.
| Module | Content |
|---|---|
| Why Most AI Governance Fails | Common failure modes — too slow, too vague, or ignored entirely |
| Bias & Fairness Testing Basics | Practical, low-overhead ways to test for skewed outputs |
| The Lightweight Review Gate | Designing a review process that fits into a two-week sprint, not a quarterly audit cycle |
| Red-Teaming Fundamentals | A practical approach to surfacing harmful or unintended outputs pre-launch |
| Case Studies & Live Q&A | Governance done well vs. poorly, open live Q&A |
Taught by an industry expert with 15+ years of security experience at top companies in the USA.
No — this is a live session only. There is no recording or on-demand access.
No — the whole point of this workshop is a review process designed to fit inside existing sprint cadence, not add a new bottleneck.
No — the framework scales down to small teams and startups.