bRRAIn Certified Security Controller
Audit a bRRAIn deployment end to end: access, outside parties, AI supply chain, evidence integrity and compliance.
- Level
- Practitioner
- Learning time
- 19 hours
- Price
- $499
- Credential
- Valid 3 years
What changed in this edition.
- Rebuilt on the real eight-zone architecture (Z1 Vault to Z8 Code Sandbox), with a full lesson on the Zone 7 Security Policy Engine's gates, classification, verdicts and policy precedence.
- Joint-session material replaced by the Security Controller's half of a two-person-integrity procedure built from real mechanisms: per-project grants, recorded approvals, the hash-chained audit log and revocation.
- New module on the AI supply chain: LLM Registry and commercial-model opt-in, LLMOps governance, MCP clients, Exchange MCP, Tool Registry, Data Pipe connectors, raw files, search and devices.
- New module on evidence integrity: brrain audit verify, Robo Compliance sealed audit sessions and the auditor portal with scoped, expiring shares.
- Compliance now covers the Residency Language Prohibition and AI-governance frameworks; reporting adds change, continuity (brrain dr) and security metrics.
- Seven AI role-play labs and a written capstone, scored against published rubrics; a fresh LOFT exam bank replaces every v1 item.
What you will be able to do.
- You will be able to read, filter and verify bRRAIn audit evidence, including the hash-chained console log and brrain audit verify on the signed control-plane log.
- You will be able to interpret Zone 7 verdicts and policy precedence and audit changes to policy, roles and settings.
- You will be able to audit roles, custom roles, per-project permissions, SSO mappings and tokens, and prove enforcement with negative tests.
- You will be able to review, approve or decline, monitor and revoke outside access as the security approver in a two-person-integrity procedure.
- You will be able to assess models, MCP servers, tools, connectors, files, search, exports and devices as parts of the AI supply chain.
- You will be able to run SOC 2 and HIPAA evidence with Robo Compliance sealed sessions and the auditor portal, and lead GDPR erasure across every copy.
- You will be able to test AI-memory defenses, lead incident response and forensics, and report findings and metrics to the Operations Controller.
Who it's for
- CISSP / CISM / Security+ / CEH holders moving into AI security
- IT security architects and internal auditors
- Compliance leads (SOC 2, HIPAA, GDPR)
- Security staff responsible for an organization's bRRAIn deployment
Not covered here
- Setting security policy (see Operations Controller)
- Day-to-day permission administration (see Access Controller)
- Installing and operating the brain pod (see Installation and Maintenance Specialist)
8 modules, 66 lessons.
About 19 hours of learning. Open a module to see every lesson.
-
AI-Memory Threat Landscape
The threat surface AI memory adds to traditional security: retrieval as an access path, prompt injection, query-shaped exfiltration, third parties inside the boundary and insider risk, tied together in a deployment threat model on the real eight zones.
- Pretest: AI-memory threat landscape
- How AI memory threats differ from traditional IT threats
- Prompt injection against retrieval
- Exfiltration via crafted queries
- Adversarial third parties inside the boundary
- Insider risk in the memory context
- The threat model for a typical customer deployment
- Retrieval: 8 questions across Module 1
-
The Audit-Layer Architecture
The eight zones from the audit seat, the console audit log's fields, filters and hash chain, the Zone 7 Security Policy Engine's gates, classification, verdicts and precedence, and six anomaly patterns.
- Pretest: the audit-layer architecture
- The eight zones from the audit seat
- Reading the console audit log: fields, filters and integrity
- Zone 7 at work: the Security Policy Engine
- Anomaly detection patterns in audit evidence
- Lab: Triage a month of audit events
- Retrieval: 8 questions across Module 2
-
Identity, Access and Two-Person Integrity
Auditing roles, custom roles and scopes, SSO mapping, sign-in and tokens, per-project folder scopes, and the Security Controller's half of the two-person-integrity procedure for outside access: review, recorded approval, monitoring and revocation.
- Pretest: identity, access and two-person integrity
- Auditing the role and scope model
- Sign-in, SSO and token review
- Per-project permissions and folder scopes as audit objects
- Two-person integrity for outside access: your half
- Reviewing a requested grant: purpose, data, duration, ceiling
- Monitoring granted access and revoking it
- Lab: Review an outside-access request
- Lab: Investigate suspected out-of-scope access
- Retrieval: 9 questions across Module 3
-
The AI Supply Chain
Which model touched which data (the Handler, LLM Registry opt-in, Zone 7 LLM policy, provenance, LLMOps), MCP clients, Exchange MCP and Tool Registry, Data Pipe connectors, ingestion and outbound flows, raw files, search and exports, and endpoint devices including the Nexus Mobile outbox.
- Pretest: the AI supply chain
- Which model touched which data: the Handler, the LLM Registry and LLMOps
- MCP clients, the Tool Registry and Exchange MCP as attack surface
- Data Pipe connectors, ingestion and outbound paths
- Raw files, search indexing and exports as exfiltration paths
- Endpoints and devices: Nexus desktop, web, mobile and MCP clients
- Lab: Approve or condition a new model, MCP server and connector
- Retrieval: 8 questions across Module 4
-
Evidence Integrity and the Governed Record
Proving the audit log with hash chains, signatures and brrain audit verify; Robo Compliance sealed audit sessions; the auditor portal with scoped, expiring shares; auditing decisions, POPE tags and corrections; and auditing changes to policy, roles and settings.
- Pretest: evidence integrity and the governed record
- Proving the audit log: hash chains, signatures and brrain audit verify
- Robo Compliance sealed audit sessions as evidence
- The auditor portal: shares, findings and evidence requests
- Auditing the governed record: decisions, sessions, tags and corrections
- Auditing changes to policy, roles and configuration
- Lab: Open an evidence room for an external auditor
- Retrieval: 8 questions across Module 5
-
Compliance Audit Leadership
SOC 2 Trust Services Criteria and HIPAA rules mapped to bRRAIn mechanisms and Robo Compliance evidence, GDPR principles and rights, right-to-erasure across every copy, external-auditor engagements, and the Residency Language Prohibition with AI-governance frameworks.
- Pretest: compliance audit leadership
- SOC 2 Trust Services Criteria applied to a bRRAIn deployment
- HIPAA audit touchpoints
- GDPR audit touchpoints
- Right-to-erasure execution on persistent memory
- Working with external auditors
- Residency language, hosting options and AI-governance frameworks
- Retrieval: 8 questions across Module 6
-
Testing, Incident Response and Forensics
Authorized penetration testing of AI-memory surfaces, prompt-injection and exfiltration test suites scored for detection, incident response with the right bRRAIn levers, and defensible forensic analysis of audit evidence.
- Pretest: testing, incident response and forensics
- Penetration-testing methodology for AI memory
- Prompt-injection testing
- Retrieval-exfiltration testing
- Incident response for AI memory
- Forensic analysis with the audit log
- Lab: Plan and report an AI-memory penetration test
- Retrieval: 8 questions across Module 7
-
Reporting, Change and Continuity
Audit reports that serve the Operations Controller and the auditor, audit-evidence retention and access, auditing upgrades, extensions and pod recreation, auditing disaster recovery with brrain dr, security metrics, and the capstone.
- Pretest: reporting, change and continuity
- Audit report format
- Audit evidence retention and access governance
- Auditing platform change: upgrades, extensions and pod recreation
- Auditing backup, recovery and failover with brrain dr
- Security metrics that drive decisions
- Lab: Present the monthly audit report
- Retrieval: 8 questions across Module 8
- Capstone: Quarterly security audit of Calder Ridge Health
Practice against someone who pushes back.
Labs run in your browser as AI role-plays. An AI plays the person on the other side of the scenario — with their own goals and objections — and your work is scored against the published rubric. There is nothing to install.
-
Lab 1 · The Audit-Layer Architecture
AI role-play: briefing an Operations Controller on 30 days of audit evidence
-
Lab 2 · Identity, Access and Two-Person Integrity
AI role-play: reviewing an outside-access request with the engagement owner
-
Lab 3 · Identity, Access and Two-Person Integrity
AI role-play: investigating out-of-scope access with a managing partner
-
Lab 4 · The AI Supply Chain
AI role-play: supply-chain review of a model, an MCP server and a connector
-
Lab 5 · Evidence Integrity and the Governed Record
AI role-play: planning a sealed-evidence engagement with an external auditor
-
Lab 6 · Testing, Incident Response and Forensics
AI role-play: scoping and reporting an AI-memory penetration test
-
Lab 7 · Reporting, Change and Continuity
AI role-play: presenting the monthly audit report to the Operations Controller
-
Lab 8 · Reporting, Change and Continuity
Written quarterly security audit report from an evidence package
Quarterly security audit of Calder Ridge Health
Artefact submitted in the capstone lab, AI-scored against the published rubric
Pass mark: 72%
Scored on
- Finding detection and evidence25%
- Access and two-person-integrity assessment15%
- AI supply-chain and exfiltration-path assessment15%
- Evidence integrity and auditor readiness15%
- Remediation and escalation judgment15%
- Report quality for the Operations Controller15%
One exam. A credential anyone can verify.
The exam
- Items per form
- 59
- Time allowed
- 120 min
- Pass mark
- 72%
- Performance tasks
- 4
- Attempts included
- 2
- Wait between attempts
- 7 days
- Online and timed, taken on learn.brrain.io.
- Your form is assembled for you from the course's item bank, so no two candidates sit the same paper.
- Performance tasks are conducted by an AI examiner: you work through a realistic scenario and are scored against a published rubric.
The credential
- A verifiable digital badge in your name.
- A public verification page at learn.brrain.io/verify, so an employer or client can confirm it.
- Valid for 3 years.
- Renewal: Renewal at 3 years by passing the then-current exam
Where this course sits.
Stacks well with
Frequently asked.
Do I need to install anything for the labs?
No. Labs and the capstone run in your browser on learn.brrain.io as AI role-plays: an AI plays the person on the other side of the scenario, and your work is scored against the rubric published with the course.
How is the exam delivered?
Online and timed: 59 items in 120 minutes, on a form assembled for you from the course's item bank. 4 of the items are performance tasks conducted by an AI examiner: you do the work rather than pick an answer. The pass mark is 72%.
What if I don't pass first time?
You have 2 attempts, with a 7-day wait after an unsuccessful attempt. Further exam attempts can be bought for $299 each.
How long is the credential valid?
3 years. You receive a verifiable digital badge with a public verification page at learn.brrain.io/verify, so anyone can confirm it is genuine.
I hold the v1 credential. Is it still valid?
Yes. Credentials earned on v1 remain valid and verifiable at learn.brrain.io/verify. When you renew, you sit the then-current version of the exam.
Can my company enroll a team?
Yes. Firms can buy a certification bundle for $2,999 per firm per year — see the pricing page — or contact us to arrange enrollment for a larger group.
bRRAIn Certified Security Controller
Audit a bRRAIn deployment end to end: access, outside parties, AI supply chain, evidence integrity and compliance.