bRRAInOps · Practitioner
v2.0

bRRAIn Certified Security Controller

Audit a bRRAIn deployment end to end: access, outside parties, AI supply chain, evidence integrity and compliance.

Level
Practitioner
Learning time
19 hours
Price
$499
Credential
Valid 3 years
What's new in v2.0

What changed in this edition.

  • Rebuilt on the real eight-zone architecture (Z1 Vault to Z8 Code Sandbox), with a full lesson on the Zone 7 Security Policy Engine's gates, classification, verdicts and policy precedence.
  • Joint-session material replaced by the Security Controller's half of a two-person-integrity procedure built from real mechanisms: per-project grants, recorded approvals, the hash-chained audit log and revocation.
  • New module on the AI supply chain: LLM Registry and commercial-model opt-in, LLMOps governance, MCP clients, Exchange MCP, Tool Registry, Data Pipe connectors, raw files, search and devices.
  • New module on evidence integrity: brrain audit verify, Robo Compliance sealed audit sessions and the auditor portal with scoped, expiring shares.
  • Compliance now covers the Residency Language Prohibition and AI-governance frameworks; reporting adds change, continuity (brrain dr) and security metrics.
  • Seven AI role-play labs and a written capstone, scored against published rubrics; a fresh LOFT exam bank replaces every v1 item.
Outcomes

What you will be able to do.

  • You will be able to read, filter and verify bRRAIn audit evidence, including the hash-chained console log and brrain audit verify on the signed control-plane log.
  • You will be able to interpret Zone 7 verdicts and policy precedence and audit changes to policy, roles and settings.
  • You will be able to audit roles, custom roles, per-project permissions, SSO mappings and tokens, and prove enforcement with negative tests.
  • You will be able to review, approve or decline, monitor and revoke outside access as the security approver in a two-person-integrity procedure.
  • You will be able to assess models, MCP servers, tools, connectors, files, search, exports and devices as parts of the AI supply chain.
  • You will be able to run SOC 2 and HIPAA evidence with Robo Compliance sealed sessions and the auditor portal, and lead GDPR erasure across every copy.
  • You will be able to test AI-memory defenses, lead incident response and forensics, and report findings and metrics to the Operations Controller.

Who it's for

  • CISSP / CISM / Security+ / CEH holders moving into AI security
  • IT security architects and internal auditors
  • Compliance leads (SOC 2, HIPAA, GDPR)
  • Security staff responsible for an organization's bRRAIn deployment

Not covered here

  • Setting security policy (see Operations Controller)
  • Day-to-day permission administration (see Access Controller)
  • Installing and operating the brain pod (see Installation and Maintenance Specialist)
Syllabus

8 modules, 66 lessons.

About 19 hours of learning. Open a module to see every lesson.

  1. AI-Memory Threat Landscape 8 lessons · 1 h 45 min

    The threat surface AI memory adds to traditional security: retrieval as an access path, prompt injection, query-shaped exfiltration, third parties inside the boundary and insider risk, tied together in a deployment threat model on the real eight zones.

    1. Pretest: AI-memory threat landscape Diagnostic pretest · 5 min
    2. How AI memory threats differ from traditional IT threats Reading · 15 min
    3. Prompt injection against retrieval Reading · 15 min
    4. Exfiltration via crafted queries Reading · 15 min
    5. Adversarial third parties inside the boundary Scenario · 15 min
    6. Insider risk in the memory context Reading · 15 min
    7. The threat model for a typical customer deployment Worked example · 15 min
    8. Retrieval: 8 questions across Module 1 Retrieval check · 10 min
  2. The Audit-Layer Architecture 7 lessons · 2 h

    The eight zones from the audit seat, the console audit log's fields, filters and hash chain, the Zone 7 Security Policy Engine's gates, classification, verdicts and precedence, and six anomaly patterns.

    1. Pretest: the audit-layer architecture Diagnostic pretest · 5 min
    2. The eight zones from the audit seat Reading · 15 min
    3. Reading the console audit log: fields, filters and integrity Reading · 15 min
    4. Zone 7 at work: the Security Policy Engine Reading · 15 min
    5. Anomaly detection patterns in audit evidence Worked example · 15 min
    6. Lab: Triage a month of audit events AI role-play lab · 45 min
    7. Retrieval: 8 questions across Module 2 Retrieval check · 10 min
  3. Identity, Access and Two-Person Integrity 10 lessons · 3 h 15 min

    Auditing roles, custom roles and scopes, SSO mapping, sign-in and tokens, per-project folder scopes, and the Security Controller's half of the two-person-integrity procedure for outside access: review, recorded approval, monitoring and revocation.

    1. Pretest: identity, access and two-person integrity Diagnostic pretest · 5 min
    2. Auditing the role and scope model Reading · 15 min
    3. Sign-in, SSO and token review Reading · 15 min
    4. Per-project permissions and folder scopes as audit objects Reading · 15 min
    5. Two-person integrity for outside access: your half Reading · 15 min
    6. Reviewing a requested grant: purpose, data, duration, ceiling Worked example · 15 min
    7. Monitoring granted access and revoking it Scenario · 15 min
    8. Lab: Review an outside-access request AI role-play lab · 45 min
    9. Lab: Investigate suspected out-of-scope access AI role-play lab · 45 min
    10. Retrieval: 9 questions across Module 3 Retrieval check · 10 min
  4. The AI Supply Chain 8 lessons · 2 h 15 min

    Which model touched which data (the Handler, LLM Registry opt-in, Zone 7 LLM policy, provenance, LLMOps), MCP clients, Exchange MCP and Tool Registry, Data Pipe connectors, ingestion and outbound flows, raw files, search and exports, and endpoint devices including the Nexus Mobile outbox.

    1. Pretest: the AI supply chain Diagnostic pretest · 5 min
    2. Which model touched which data: the Handler, the LLM Registry and LLMOps Reading · 15 min
    3. MCP clients, the Tool Registry and Exchange MCP as attack surface Reading · 15 min
    4. Data Pipe connectors, ingestion and outbound paths Reading · 15 min
    5. Raw files, search indexing and exports as exfiltration paths Scenario · 15 min
    6. Endpoints and devices: Nexus desktop, web, mobile and MCP clients Reading · 15 min
    7. Lab: Approve or condition a new model, MCP server and connector AI role-play lab · 45 min
    8. Retrieval: 8 questions across Module 4 Retrieval check · 10 min
  5. Evidence Integrity and the Governed Record 8 lessons · 2 h 15 min

    Proving the audit log with hash chains, signatures and brrain audit verify; Robo Compliance sealed audit sessions; the auditor portal with scoped, expiring shares; auditing decisions, POPE tags and corrections; and auditing changes to policy, roles and settings.

    1. Pretest: evidence integrity and the governed record Diagnostic pretest · 5 min
    2. Proving the audit log: hash chains, signatures and brrain audit verify Reading · 15 min
    3. Robo Compliance sealed audit sessions as evidence Reading · 15 min
    4. The auditor portal: shares, findings and evidence requests Reading · 15 min
    5. Auditing the governed record: decisions, sessions, tags and corrections Worked example · 15 min
    6. Auditing changes to policy, roles and configuration Worked example · 15 min
    7. Lab: Open an evidence room for an external auditor AI role-play lab · 45 min
    8. Retrieval: 8 questions across Module 5 Retrieval check · 10 min
  6. Compliance Audit Leadership 8 lessons · 1 h 45 min

    SOC 2 Trust Services Criteria and HIPAA rules mapped to bRRAIn mechanisms and Robo Compliance evidence, GDPR principles and rights, right-to-erasure across every copy, external-auditor engagements, and the Residency Language Prohibition with AI-governance frameworks.

    1. Pretest: compliance audit leadership Diagnostic pretest · 5 min
    2. SOC 2 Trust Services Criteria applied to a bRRAIn deployment Reading · 15 min
    3. HIPAA audit touchpoints Reading · 15 min
    4. GDPR audit touchpoints Reading · 15 min
    5. Right-to-erasure execution on persistent memory Worked example · 15 min
    6. Working with external auditors Scenario · 15 min
    7. Residency language, hosting options and AI-governance frameworks Reading · 15 min
    8. Retrieval: 8 questions across Module 6 Retrieval check · 10 min
  7. Testing, Incident Response and Forensics 8 lessons · 2 h 15 min

    Authorized penetration testing of AI-memory surfaces, prompt-injection and exfiltration test suites scored for detection, incident response with the right bRRAIn levers, and defensible forensic analysis of audit evidence.

    1. Pretest: testing, incident response and forensics Diagnostic pretest · 5 min
    2. Penetration-testing methodology for AI memory Reading · 15 min
    3. Prompt-injection testing Worked example · 15 min
    4. Retrieval-exfiltration testing Worked example · 15 min
    5. Incident response for AI memory Reading · 15 min
    6. Forensic analysis with the audit log Worked example · 15 min
    7. Lab: Plan and report an AI-memory penetration test AI role-play lab · 45 min
    8. Retrieval: 8 questions across Module 7 Retrieval check · 10 min
  8. Reporting, Change and Continuity 9 lessons · 3 h

    Audit reports that serve the Operations Controller and the auditor, audit-evidence retention and access, auditing upgrades, extensions and pod recreation, auditing disaster recovery with brrain dr, security metrics, and the capstone.

    1. Pretest: reporting, change and continuity Diagnostic pretest · 5 min
    2. Audit report format Reading · 15 min
    3. Audit evidence retention and access governance Reading · 15 min
    4. Auditing platform change: upgrades, extensions and pod recreation Reading · 15 min
    5. Auditing backup, recovery and failover with brrain dr Scenario · 15 min
    6. Security metrics that drive decisions Worked example · 15 min
    7. Lab: Present the monthly audit report AI role-play lab · 45 min
    8. Retrieval: 8 questions across Module 8 Retrieval check · 10 min
    9. Capstone: Quarterly security audit of Calder Ridge Health AI role-play lab · 45 min
Labs and capstone

Practice against someone who pushes back.

Labs run in your browser as AI role-plays. An AI plays the person on the other side of the scenario — with their own goals and objections — and your work is scored against the published rubric. There is nothing to install.

  • Lab 1 · The Audit-Layer Architecture

    AI role-play: briefing an Operations Controller on 30 days of audit evidence

  • Lab 2 · Identity, Access and Two-Person Integrity

    AI role-play: reviewing an outside-access request with the engagement owner

  • Lab 3 · Identity, Access and Two-Person Integrity

    AI role-play: investigating out-of-scope access with a managing partner

  • Lab 4 · The AI Supply Chain

    AI role-play: supply-chain review of a model, an MCP server and a connector

  • Lab 5 · Evidence Integrity and the Governed Record

    AI role-play: planning a sealed-evidence engagement with an external auditor

  • Lab 6 · Testing, Incident Response and Forensics

    AI role-play: scoping and reporting an AI-memory penetration test

  • Lab 7 · Reporting, Change and Continuity

    AI role-play: presenting the monthly audit report to the Operations Controller

  • Lab 8 · Reporting, Change and Continuity

    Written quarterly security audit report from an evidence package

Capstone

Quarterly security audit of Calder Ridge Health

Artefact submitted in the capstone lab, AI-scored against the published rubric

Pass mark: 72%

Scored on

  • Finding detection and evidence25%
  • Access and two-person-integrity assessment15%
  • AI supply-chain and exfiltration-path assessment15%
  • Evidence integrity and auditor readiness15%
  • Remediation and escalation judgment15%
  • Report quality for the Operations Controller15%
Exam and credential

One exam. A credential anyone can verify.

The exam

Items per form
59
Time allowed
120 min
Pass mark
72%
Performance tasks
4
Attempts included
2
Wait between attempts
7 days
  • Online and timed, taken on learn.brrain.io.
  • Your form is assembled for you from the course's item bank, so no two candidates sit the same paper.
  • Performance tasks are conducted by an AI examiner: you work through a realistic scenario and are scored against a published rubric.

The credential

  • A verifiable digital badge in your name.
  • A public verification page at learn.brrain.io/verify, so an employer or client can confirm it.
  • Valid for 3 years.
  • Renewal: Renewal at 3 years by passing the then-current exam
Before and after

Where this course sits.

Stacks well with

Questions

Frequently asked.

Do I need to install anything for the labs?

No. Labs and the capstone run in your browser on learn.brrain.io as AI role-plays: an AI plays the person on the other side of the scenario, and your work is scored against the rubric published with the course.

How is the exam delivered?

Online and timed: 59 items in 120 minutes, on a form assembled for you from the course's item bank. 4 of the items are performance tasks conducted by an AI examiner: you do the work rather than pick an answer. The pass mark is 72%.

What if I don't pass first time?

You have 2 attempts, with a 7-day wait after an unsuccessful attempt. Further exam attempts can be bought for $299 each.

How long is the credential valid?

3 years. You receive a verifiable digital badge with a public verification page at learn.brrain.io/verify, so anyone can confirm it is genuine.

I hold the v1 credential. Is it still valid?

Yes. Credentials earned on v1 remain valid and verifiable at learn.brrain.io/verify. When you renew, you sit the then-current version of the exam.

Can my company enroll a team?

Yes. Firms can buy a certification bundle for $2,999 per firm per year — see the pricing page — or contact us to arrange enrollment for a larger group.

Enroll

bRRAIn Certified Security Controller

Audit a bRRAIn deployment end to end: access, outside parties, AI supply chain, evidence integrity and compliance.