AIG-300AI Governance

Securing LLM Applications

Prompt injection will succeed eventually, so design for it. Threat model an LLM application and build controls that hold even when the model is fooled.

10 lessons About 3 hours 4 ALCs Certificate on completion

What you'll be able to do

  • Threat model an LLM application, including every text source and output
  • Design so a successful prompt injection can't do much damage
  • Protect sensitive data in prompts, retrieval and logs
  • Control output handling, tool use and cost, then test and monitor it
You finish with

An LLM application security design record

What's in it. Trust boundaries with every text source and output destination, one row per applicable threat with its design control, detection, test case, owner and residual risk, the model inventory, the change rule and the switch-off plan.

You build it lesson by lesson, using your own organization, and submit it for your certificate. It's yours to keep and adapt.

Who it's for

Application security engineers, architects and developers building on LLMs.

What's inside

  1. 1Where the requirement comes from 18 min
  2. 2How small teams and enterprises meet it 16 min
  3. 3Threat modeling an LLM application 22 min
  4. 4Prompt injection: design for it to succeed 24 min
  5. 5Sensitive data, retrieval and prompts 22 min
  6. 6Output, tools and cost 22 min
  7. 7Supply chain, testing and monitoring 22 min
  8. 8Hands-on lab: small team choose one 22 min
  9. 9Hands-on lab: enterprise choose one 24 min
  10. 10Finish and submit your deliverable 20 min

Built for your size

The requirement is the same everywhere. How you meet it depends on who you have. You pick the lab that matches your organization.

Small team or early-stageOne hosted model and a retrieval layer, so a narrow design (permission-filtered retrieval, no tools, plain-text output) and a small attack file run on every change.
EnterpriseMany applications, models and agents, so tiering, a model gateway, shared controls for builders, red teaming and pinned model versions.

How you earn the certificate

Submit your finished deliverable, which is scored against a published rubric, and pass a short scenario quiz. Your certificate goes to your wallet and can be checked by anyone on the public register.

Ready to build an LLM application security design record?10 lessons, about 3 hours. Start whenever you're ready.
Join and enroll