By Mirror Security · SOC 2 Type 1 Certified · Free Access

AI Security Training for
Teams Building with AI

A structured knowledge base covering every layer of the AI attack surface. Four tracks from threat fundamentals to hands-on labs with VectaX, AgentIQ, and DiscoveR.

Risk Assessment →
4 tracks
39 modules
OWASP · NIST AI RMF · MITRE ATLAS
EU AI Act · ISO 42001
Jump to track:
Track 1: Fundamentals
Track 2: Attack Surface
Track 3: Defence in Depth
Track 4: Applied Labs

Four tracks. One complete picture.

Each track builds on the last. Every topic appears exactly once. Click any module to see what's inside and open it directly.

1
Orientation

AI Security Fundamentals

Threat landscape, frameworks, and threat modeling

5/5 modules available
2
Attack Surface

Three domains of AI attack surface

Pick the path relevant to your stack, or do all three

Parallel paths18/18 modules available
3
Defence in Depth

Cross-cutting concerns

Privacy, governance, and security operations

Parallel paths10/10 modules available
4
Applied

Industry scenarios with Mirror Security

The only track where Mirror products are the subject

6/6 modules available

F: Healthcare and Life Sciences

2 modules

Encrypted AI on patient data. HIPAA compliance from the stack up.

VectaX

G: Financial Services

2 modules

Secure RAG for trading and fraud detection. End-to-end red teaming with DiscoveR.

VectaXDiscoveR

H: Enterprise Agentic AI

2 modules

AgentIQ policy design for production agents. Sovereign AI deployment.

AgentIQVectaX

Built for the people closest to the problem

Three roles, different entry points, same knowledge base.

Security Engineers

Find and fix AI-specific risks

Attack surfaces unique to LLMs, agents, and RAG pipelines. Test for prompt injection, data leakage, and model manipulation before they become production incidents.

Track 1 → 2A, 2B, 2C → 3E
AI / ML Engineers

Build defensibly from the start

Security principles that fit the architecture before deployment. Secure model selection, inference endpoint hardening, agent tool permissioning, encrypted memory.

Track 1 → 2A, 2B → 3D → Track 4
Compliance and Risk Teams

Map AI systems to your frameworks

Practical guidance on GDPR, EU AI Act, ISO 42001, and NIST AI RMF with controls that actually apply to LLMs, agents, and generative AI deployments.

Track 1 → 3E (E4 especially)
Aligned with
OWASP Top 10 for LLMsMITRE ATLASNIST AI RMFEU AI ActISO / IEC 42001GDPR & HIPAA

What practitioners ask most

Do I need to complete the tracks in order?
Track 1 is the recommended starting point for everyone. Within Track 2, the three paths (RAG, Agents, Model attacks) are independent. Track 3 and 4 assume Track 2 knowledge but not a specific sequence.
Why does the same topic not appear in multiple paths?
Every topic has exactly one home. Prompt injection lives in path B, FHE fundamentals live in path D, compliance lives in Track 1 and 3E. No topic appears twice.
What is the OWASP Top 10 for LLMs?
The OWASP Top 10 for LLM Applications (2025) catalogues the ten most critical security risks in generative AI: Prompt Injection, Sensitive Information Disclosure, Supply Chain, Data Poisoning, Improper Output Handling, Excessive Agency, System Prompt Leakage, Vector Weaknesses, Misinformation, and Unbounded Consumption. Track 1 module 3 covers all ten.
Where do Mirror Security products appear?
VectaX, AgentIQ, and DiscoveR appear in Tracks 1 to 3 only where genuinely relevant. Track 4 is the only track where they are the subject of the learning.
What is MITRE ATLAS?
MITRE ATLAS (Adversarial Threat Landscape for Artificial-Intelligence Systems) is a knowledge base of adversary tactics and techniques targeting AI and ML systems. As of v5.1 (November 2025) it contains 16 tactics and 84 techniques. Track 1 module 2 introduces it; module 4 teaches you to apply it.
Is this free?
Yes. Mirror Academy is a free public knowledge base. No registration required. Track 4 applied labs reference Mirror Security product playgrounds which have free tiers at docs.mirrorsecurity.io/mirrordocs.

The threats keep moving.
Get ahead of them.

AI security cannot be an afterthought. Start with the fundamentals and build up to hands-on red teaming.

Get a Risk Assessment