FutureStackDev AI Agent Development

AI Security & Privacy

Prompt injection, data leakage, the lethal trifecta, PII, and controls you can show a security review — not a slide about “responsible AI”.

Created by Baljeet Dogra

Course Objectives

  • Demonstrate direct and indirect injection against a system you built.
  • Strip the lethal trifecta: private data, untrusted content, egress.
  • Write what you log and what you never log.
  • Leave with a control map a security engineer can argue with.

What you will produce

Attack

Injection pack

Reproducible cases, including a retrieved document that tries to exfiltrate.

Defence

Control map

Threats to controls to tests. Gaps named in writing.

4 weeks curriculum

Expand a part for the syllabus. Content stays searchable when closed.

01 The surface Week 1

OWASP LLM risks, data flows, where secrets live.

  • Threats
  • Data flow
  • Secrets
  • Supply chain
02 Injection Week 2

Direct, indirect, tool abuse. Prompts are not a control.

  • Direct
  • Indirect
  • Tools
  • Isolations
03 Privacy Week 3

PII, minimisation, retention, what never to log, residency.

  • PII
  • Redaction
  • Logs
  • Residency
04 Review Week 4

Red team a peer system. Capstone control map.

  • Red team
  • Gates
  • Evidence
  • Capstone

Who this is for

Engineers shipping LLM features

You will face a security review. Vibes will not pass.

Security engineers

You need LLM-shaped threats, not a copy of the web checklist.

Prerequisites

  • You have built or reviewed an LLM-backed feature
  • Comfortable reading HTTP and logs

Not a fit if

  • A policy workshop with no lab
  • People who have never seen an LLM call

Related: Becoming an AI Principal Engineer · AI Governance & Compliance

Questions

Will we hack production?

No. Labs are on systems you control. The techniques are the ones that show up in reviews.

Is this the EU AI Act course?

Security and privacy labs. Governance & Compliance covers the Act, ISO 42001 and NIST AI RMF as systems of record.

Ready to start?

Four weeks to a control map that survives a security review. Create an account to enrol.

Enrol now