← All courses

Course 7 · Legal & Technical Security

Legal & Tech Security Tier — AI Governance, Data Privacy & Red-Teaming

8 hours · 2 sessions × 4 hours · Max 10 participants

A defensible AI security layer: data classification → PII and secret filtering → strict schemas → privacy-aware logging → prompt-injection tests → RAG trust controls → tool authorization → output validation → automated regression → remediation register.

Who should attend

Corporate legal counsel, CISOs, risk and compliance managers, privacy teams, tech directors, and security architects.

Where and how

8 hours · 2 × 4-hour sessions · Max 10 participants · Hands-on · English · On-site or at an agreed training premises.

What we cover

Session 1 — Data Privacy & Leak Prevention — Trace web, UI, API, RAG, provider, and log data flows. Create an enterprise data destination policy. Build PII detection and de-identification controls. Reject unnecessary fields before egress. Sanitize logs and prove raw synthetic PII cannot leave unchanged.

Session 2 — Prompt Injection & Red Teaming — Test direct and indirect prompt injection safely. Protect RAG and retrieved-content trust boundaries. Keep tool authorization outside the model. Validate model output before downstream use. Run repeatable authorized red-team regression tests and turn findings into owned remediation actions.

You will learn to

  • Map AI data and action flows across the complete system.
  • Build PII filtering, de-identification, and privacy-aware logging.
  • Test direct and indirect prompt injection safely.
  • Protect RAG trust boundaries and keep tool authorization outside the model.
  • Validate outputs, automate regression tests, and track remediation.

The safety principle

A stronger system prompt is not a security architecture. The model is not an authorization boundary, and model output must be treated as untrusted input.

Investment

  • B2C / open cohort: 7,500,000 VND / participant
  • Private B2B cohort: 38,000,000–58,000,000 VND / private cohort

Authorized staging red-team engagements and production remediation are separately scoped.

Completion

Attend, complete the assessment, and finish the capstone. We will give you a course completion certificate.

For private cohorts, we can adapt the examples to a cleaned-up company use case after a short technical call.