Course 7 · Legal & Technical Security
Legal & Tech Security Tier — AI Governance, Data Privacy & Red-Teaming
8 hours · 2 sessions × 4 hours · Max 10 participants
A defensible AI security layer: data classification → PII and secret filtering → strict schemas → privacy-aware logging → prompt-injection tests → RAG trust controls → tool authorization → output validation → automated regression → remediation register.
Who should attend
Corporate legal counsel, CISOs, risk and compliance managers, privacy teams, tech directors, and security architects.
Where and how
8 hours · 2 × 4-hour sessions · Max 10 participants · Hands-on · English · On-site or at an agreed training premises.
What we cover
Session 1 — Data Privacy & Leak Prevention — Trace web, UI, API, RAG, provider, and log data flows. Create an enterprise data destination policy. Build PII detection and de-identification controls. Reject unnecessary fields before egress. Sanitize logs and prove raw synthetic PII cannot leave unchanged.
Session 2 — Prompt Injection & Red Teaming — Test direct and indirect prompt injection safely. Protect RAG and retrieved-content trust boundaries. Keep tool authorization outside the model. Validate model output before downstream use. Run repeatable authorized red-team regression tests and turn findings into owned remediation actions.
You will learn to
- Map AI data and action flows across the complete system.
- Build PII filtering, de-identification, and privacy-aware logging.
- Test direct and indirect prompt injection safely.
- Protect RAG trust boundaries and keep tool authorization outside the model.
- Validate outputs, automate regression tests, and track remediation.
The safety principle
A stronger system prompt is not a security architecture. The model is not an authorization boundary, and model output must be treated as untrusted input.
Investment
- B2C / open cohort: 7,500,000 VND / participant
- Private B2B cohort: 38,000,000–58,000,000 VND / private cohort
Authorized staging red-team engagements and production remediation are separately scoped.
Completion
Attend, complete the assessment, and finish the capstone. We will give you a course completion certificate.
For private cohorts, we can adapt the examples to a cleaned-up company use case after a short technical call.