Courses / Live bootcamps
AI Security and Red-Teaming Bootcamp
Attack and defend LLM applications: prompt injection, data exfiltration, model abuse.
- weeks, live on Zoom
- 12
- hours a week
- 15
- deployed projects
- 6
- minutes 1-1, every week
- 30
Who it is for, and what you receive.
Engineers who have built or tested an LLM application, ideally with some security background, who want to attack and defend AI systems for a living.
Before you start
You have built or tested an LLM application; some security background helps.
Skills
- Python
- LLM security
- prompt injection
- guardrails
- sandboxing
- reporting
A week, about 15 hours
- Live on Zoom
- 4h
- Recorded lessons and exercises
- 6h
- The project
- 5h
- 1
Six deployed projects
Each graded by Nova against a published rubric and signed off by the instructor at the gate.
- 2
The recorded lessons
The track's lessons and exercises, graded line by line, open for twelve months after the cohort ends.
- 3
Live on Zoom every week
A 90-minute live code review, a 60-minute squad lab, 60 minutes of office hours, and a 30-minute 1-1 with your instructor.
- 4
Your hiring plan
Opened in week 1 and reviewed in every 1-1: target roles, the gap map, the proof list, weekly actions, an interview log, the outcome.
- 5
The record
Every grade and every project with its repository at square1ai.com/u/{handle}, and the recording of your viva, verifiable by any employer.
- 6
The certificate
A credential ID that resolves at square1ai.com/verify to the real completion.
- 7
The hiring sprint
Weeks 11 and 12: CV and portfolio from graded work, applications, mock interviews scored against the role, demo day.
- 8
Nova for twelve weeks
A tutor with every submission of yours in its memory, at 2am as well as in class.
Twelve weeks in six blocks.
Each block teaches for a week, then you build and deploy a project, then a gate checks it before the next block opens. The project and its gate are the block's record entry.
Live time each week on Zoom: a 90-minute class where the instructor reviews real submissions, a 60-minute squad lab, 60 minutes of office hours, and your own 30-minute 1-1. Nothing is lectured live; the recorded lessons do that.
- 1
The attack surface
Weeks 1 to 2Week 1
The attack surface
- How LLM applications fail
- Prompt injection, direct and indirect
- Tool and agent abuse
You build: A vulnerable lab app
Week 2
Project 1: the attack log
- Attack taxonomies
- Reproducible attacks
You build: A vulnerable app and an attack log covering five classes
Project 1, the gate at week 2
The attack log
Build a deliberately vulnerable LLM application and break it five ways.
You hand in
- Lab app
- Attack log
- Reproductions
The gate
Five distinct attack classes demonstrated.
- 2
Automated red-teaming
Weeks 3 to 4Week 3
Automated red-teaming
- Attack generation
- Fuzzing prompts and tools
- Scoring harm
You build: A red-team harness
Week 4
Project 2: the harness
- Seeded vulnerabilities
- Coverage
You build: An automated harness that finds the seeded vulnerabilities
Project 2, the gate at week 4
The harness
Automate the attacks.
You hand in
- Attack generator
- Fuzzer
- Harm scoring
- Coverage report
The gate
The harness finds the seeded vulnerabilities.
- 3
Defences
Weeks 5 to 6Week 5
Defences
- Input and output guardrails
- Permission design for agents
- Isolation and sandboxing
You build: A defended app; squads form
Week 6
Project 3: defended
- Measuring attack reduction
- Not hurting the good cases
You build: A defended version with measured attack reduction
Project 3, the gate at week 6
Defended
Cut the attack success rate without breaking the app.
You hand in
- Guardrails
- Permission model
- Sandboxing
- Before-and-after measurement
The gate
Attack success drops below a stated rate.
- 4
Data and models
Weeks 7 to 8Week 7
Data and models
- Training-data poisoning and extraction
- Model theft and watermarking
- Supply chain for models
You build: A supply-chain audit
Week 8
Project 4: the audit
- Reproducing findings
- Provenance
You build: A model supply-chain audit with findings
Project 4, the gate at week 8
The audit
Audit a model's data and supply chain.
You hand in
- Audit
- Findings
- Reproductions
- Provenance report
The gate
Findings are reproduced.
- 5
Programmes
Weeks 9 to 10Week 9
Programmes
- Running an AI red-team programme
- Reporting to leadership
- Regulation and standards
You build: Engagement plan
Week 10
Project 5 and the viva
- A full engagement
- Defending a finding and its fix
You build: A red-team engagement on a real application with a report; the viva
Project 5, the gate at week 10
The engagement
Run a full red-team engagement on a real application and report to leadership.
You hand in
- Scope
- Findings
- Fixes
- Leadership report
The gate
The viva: defend a finding and its fix.
- 6
Employer brief and hiring sprint
Weeks 11 to 12Week 11
Employer brief
- A real problem from a hiring partner, in squads
- A partner's AI security problem
- Working to someone else's definition of done
You build: The employer brief in progress
Week 12
Hiring sprint
- CV and portfolio built from graded work
- Applications and follow-ups in the hiring plan
- Mock interviews scored against the role
- Demo day
You build: Project 6 delivered; demo day
Project 6, the gate at week 12
Employer brief
A partner's AI security problem.
You hand in
- The brief delivered
- Demo day
The gate
The brief's owner accepts the result.
What you can do by week 12.
Six red-team and defence projects and a reusable harness, in a field where the number of people who can do this is far smaller than the number of companies who need it.
- 1
Demonstrate the attack classes against LLM applications: direct and indirect prompt injection, tool and agent abuse.
- 2
Build automated red-team harnesses that generate attacks, fuzz prompts and tools, and score harm.
- 3
Build defences: guardrails, permission design for agents, isolation and sandboxing, and measure the reduction.
- 4
Audit the data and model supply chain: poisoning, extraction, theft, provenance.
- 5
Run an AI red-team engagement and report to leadership against standards.
- 6
Defend a finding and its fix, on camera.
Roles this prepares you for
- AI security engineer
- AI red-teamer
- Security engineer (ML)
- Trust and safety engineer
No placement rate is shown, because there are no graduates to count yet. The roles above are what the projects are built for.
Your record at week 12.
Every exercise and project is graded by Nova against a rubric you can read, and every grade is kept on one page an employer can open and run. This is what the programme writes to it.
- Graded, line by line
- Nova reads every submission against the brief and the rubric and returns a score, what you did well and what to fix.
- Six gates
- A block does not open until the previous project passes its gate. You always know where you are and what is next.
- A weekly 1-1
- Thirty minutes with your instructor, who has already read your code before the call.
- One page an employer can run
- Every grade, project and the viva recording at /verify. An employer opens it, runs the code and watches you defend it.
Record, AI Security and Red-Teaming Bootcamp
Example
- Week 2Graded, gate signed
The attack log
Five distinct attack classes demonstrated
- Week 4Graded, gate signed
The harness
The harness finds the seeded vulnerabilities
- Week 6Graded, gate signed
Defended
Attack success drops below a stated rate
- Week 8Graded, gate signed
The audit
Findings are reproduced
- Week 10Graded, gate signed
The engagement
A viva: defend a finding and its fix
- Week 12Graded, gate signed
Employer brief
The brief's owner accepts the result
- Weeks 1 to 12Kept
Twelve 1-1 notes
What your instructor saw in your work each week, and what you agreed to do next.
- Week 12Kept
Your hiring plan and its outcome
Target roles, the gap map, applications, interviews and where you landed.
The entries, not the grades: those are yours to earn. The page lives at /verify and an employer needs no account to open it.
8 entries, twelve weeks. One email when applications open.
How we help you find a job.
The last block is not curriculum. It is the hiring sprint, and the proof you built in the ten weeks before it.
- 1
Your hiring plan, from week 1
Six parts you and your instructor keep: target roles, the gap map from real postings, the proof to send, weekly actions, an interview log, the outcome. Read before every 1-1.
- 2
The hiring sprint
Weeks 11 and 12: CV, portfolio, applications, mock interviews, and demo day in front of hiring partners.
- 3
A record an employer can run
Your six deployed projects and the recorded viva on /verify. An employer opens it, runs the code and watches you defend it.
- 4
The career agent
Paste a real job posting at /career and it maps the role to your graded work and what to do next.
- 5
The roles directory
Every role we prepare people for, what it pays and what it asks, at /roles.
One email when applications open.
Fifty seats, one instructor, twelve weeks. The waitlist hears the date and the price first, and nothing is charged before the cohort exists.
