Skip to content

Courses / Live bootcamps

Live bootcampTaught live on Zoom, one instructor

AI Security and Red-Teaming Bootcamp

Attack and defend LLM applications: prompt injection, data exfiltration, model abuse.

weeks, live on Zoom
12
hours a week
15
deployed projects
6
minutes 1-1, every week
30

Who it is for, and what you receive.

Engineers who have built or tested an LLM application, ideally with some security background, who want to attack and defend AI systems for a living.

Before you start

You have built or tested an LLM application; some security background helps.

Skills

  • Python
  • LLM security
  • prompt injection
  • guardrails
  • sandboxing
  • reporting

A week, about 15 hours

Live on Zoom
4h
Recorded lessons and exercises
6h
The project
5h
  1. 1

    Six deployed projects

    Each graded by Nova against a published rubric and signed off by the instructor at the gate.

  2. 2

    The recorded lessons

    The track's lessons and exercises, graded line by line, open for twelve months after the cohort ends.

  3. 3

    Live on Zoom every week

    A 90-minute live code review, a 60-minute squad lab, 60 minutes of office hours, and a 30-minute 1-1 with your instructor.

  4. 4

    Your hiring plan

    Opened in week 1 and reviewed in every 1-1: target roles, the gap map, the proof list, weekly actions, an interview log, the outcome.

  5. 5

    The record

    Every grade and every project with its repository at square1ai.com/u/{handle}, and the recording of your viva, verifiable by any employer.

  6. 6

    The certificate

    A credential ID that resolves at square1ai.com/verify to the real completion.

  7. 7

    The hiring sprint

    Weeks 11 and 12: CV and portfolio from graded work, applications, mock interviews scored against the role, demo day.

  8. 8

    Nova for twelve weeks

    A tutor with every submission of yours in its memory, at 2am as well as in class.

Twelve weeks in six blocks.

Each block teaches for a week, then you build and deploy a project, then a gate checks it before the next block opens. The project and its gate are the block's record entry.

Live time each week on Zoom: a 90-minute class where the instructor reviews real submissions, a 60-minute squad lab, 60 minutes of office hours, and your own 30-minute 1-1. Nothing is lectured live; the recorded lessons do that.

  1. 1

    The attack surface

    Weeks 1 to 2

    Week 1

    The attack surface

    • How LLM applications fail
    • Prompt injection, direct and indirect
    • Tool and agent abuse

    You build: A vulnerable lab app

    Week 2

    Project 1: the attack log

    • Attack taxonomies
    • Reproducible attacks

    You build: A vulnerable app and an attack log covering five classes

    Project 1, the gate at week 2

    The attack log

    Build a deliberately vulnerable LLM application and break it five ways.

    You hand in

    • Lab app
    • Attack log
    • Reproductions

    The gate

    Five distinct attack classes demonstrated.

  2. 2

    Automated red-teaming

    Weeks 3 to 4

    Week 3

    Automated red-teaming

    • Attack generation
    • Fuzzing prompts and tools
    • Scoring harm

    You build: A red-team harness

    Week 4

    Project 2: the harness

    • Seeded vulnerabilities
    • Coverage

    You build: An automated harness that finds the seeded vulnerabilities

    Project 2, the gate at week 4

    The harness

    Automate the attacks.

    You hand in

    • Attack generator
    • Fuzzer
    • Harm scoring
    • Coverage report

    The gate

    The harness finds the seeded vulnerabilities.

  3. 3

    Defences

    Weeks 5 to 6

    Week 5

    Defences

    • Input and output guardrails
    • Permission design for agents
    • Isolation and sandboxing

    You build: A defended app; squads form

    Week 6

    Project 3: defended

    • Measuring attack reduction
    • Not hurting the good cases

    You build: A defended version with measured attack reduction

    Project 3, the gate at week 6

    Defended

    Cut the attack success rate without breaking the app.

    You hand in

    • Guardrails
    • Permission model
    • Sandboxing
    • Before-and-after measurement

    The gate

    Attack success drops below a stated rate.

  4. 4

    Data and models

    Weeks 7 to 8

    Week 7

    Data and models

    • Training-data poisoning and extraction
    • Model theft and watermarking
    • Supply chain for models

    You build: A supply-chain audit

    Week 8

    Project 4: the audit

    • Reproducing findings
    • Provenance

    You build: A model supply-chain audit with findings

    Project 4, the gate at week 8

    The audit

    Audit a model's data and supply chain.

    You hand in

    • Audit
    • Findings
    • Reproductions
    • Provenance report

    The gate

    Findings are reproduced.

  5. 5

    Programmes

    Weeks 9 to 10

    Week 9

    Programmes

    • Running an AI red-team programme
    • Reporting to leadership
    • Regulation and standards

    You build: Engagement plan

    Week 10

    Project 5 and the viva

    • A full engagement
    • Defending a finding and its fix

    You build: A red-team engagement on a real application with a report; the viva

    Project 5, the gate at week 10

    The engagement

    Run a full red-team engagement on a real application and report to leadership.

    You hand in

    • Scope
    • Findings
    • Fixes
    • Leadership report

    The gate

    The viva: defend a finding and its fix.

  6. 6

    Employer brief and hiring sprint

    Weeks 11 to 12

    Week 11

    Employer brief

    • A real problem from a hiring partner, in squads
    • A partner's AI security problem
    • Working to someone else's definition of done

    You build: The employer brief in progress

    Week 12

    Hiring sprint

    • CV and portfolio built from graded work
    • Applications and follow-ups in the hiring plan
    • Mock interviews scored against the role
    • Demo day

    You build: Project 6 delivered; demo day

    Project 6, the gate at week 12

    Employer brief

    A partner's AI security problem.

    You hand in

    • The brief delivered
    • Demo day

    The gate

    The brief's owner accepts the result.

What you can do by week 12.

Six red-team and defence projects and a reusable harness, in a field where the number of people who can do this is far smaller than the number of companies who need it.

  1. 1

    Demonstrate the attack classes against LLM applications: direct and indirect prompt injection, tool and agent abuse.

  2. 2

    Build automated red-team harnesses that generate attacks, fuzz prompts and tools, and score harm.

  3. 3

    Build defences: guardrails, permission design for agents, isolation and sandboxing, and measure the reduction.

  4. 4

    Audit the data and model supply chain: poisoning, extraction, theft, provenance.

  5. 5

    Run an AI red-team engagement and report to leadership against standards.

  6. 6

    Defend a finding and its fix, on camera.

Roles this prepares you for

  • AI security engineer
  • AI red-teamer
  • Security engineer (ML)
  • Trust and safety engineer

No placement rate is shown, because there are no graduates to count yet. The roles above are what the projects are built for.

Your record at week 12.

Every exercise and project is graded by Nova against a rubric you can read, and every grade is kept on one page an employer can open and run. This is what the programme writes to it.

Graded, line by line
Nova reads every submission against the brief and the rubric and returns a score, what you did well and what to fix.
Six gates
A block does not open until the previous project passes its gate. You always know where you are and what is next.
A weekly 1-1
Thirty minutes with your instructor, who has already read your code before the call.
One page an employer can run
Every grade, project and the viva recording at /verify. An employer opens it, runs the code and watches you defend it.

Record, AI Security and Red-Teaming Bootcamp

Example

  1. Week 2

    The attack log

    Five distinct attack classes demonstrated

    Graded, gate signed
  2. Week 4

    The harness

    The harness finds the seeded vulnerabilities

    Graded, gate signed
  3. Week 6

    Defended

    Attack success drops below a stated rate

    Graded, gate signed
  4. Week 8

    The audit

    Findings are reproduced

    Graded, gate signed
  5. Week 10

    The engagement

    A viva: defend a finding and its fix

    Graded, gate signed
  6. Week 12

    Employer brief

    The brief's owner accepts the result

    Graded, gate signed
  7. Weeks 1 to 12

    Twelve 1-1 notes

    What your instructor saw in your work each week, and what you agreed to do next.

    Kept
  8. Week 12

    Your hiring plan and its outcome

    Target roles, the gap map, applications, interviews and where you landed.

    Kept

The entries, not the grades: those are yours to earn. The page lives at /verify and an employer needs no account to open it.

8 entries, twelve weeks. One email when applications open.

No account, no card. One email when it opens; we never sell before it exists.

How we help you find a job.

The last block is not curriculum. It is the hiring sprint, and the proof you built in the ten weeks before it.

  1. 1

    Your hiring plan, from week 1

    Six parts you and your instructor keep: target roles, the gap map from real postings, the proof to send, weekly actions, an interview log, the outcome. Read before every 1-1.

  2. 2

    The hiring sprint

    Weeks 11 and 12: CV, portfolio, applications, mock interviews, and demo day in front of hiring partners.

  3. 3

    A record an employer can run

    Your six deployed projects and the recorded viva on /verify. An employer opens it, runs the code and watches you defend it.

  4. 4

    The career agent

    Paste a real job posting at /career and it maps the role to your graded work and what to do next.

  5. 5

    The roles directory

    Every role we prepare people for, what it pays and what it asks, at /roles.

One email when applications open.

Fifty seats, one instructor, twelve weeks. The waitlist hears the date and the price first, and nothing is charged before the cohort exists.

No account, no card. One email when it opens; we never sell before it exists.