Secure TheCloud

Secure TheCloud Labs

Cloud security learning paths for real enterprise decisions.

Guided LABs for identity, authorization, workload risk, detection reasoning, AI governance, executive readiness, and architecture validation.

Guided learning paths

Start with a track, not a scroll.

intermediate

AI Governance Command Center Track

Guided course for enterprise AI governance command center design.

Open Track →

Searchable catalog

Find the right LAB quickly.

AI-SECURITY-ENGINEERING · ai-security · intermediate

Tool Permission Engineering

intermediate

Intermediate LAB teaching scoped AI tool permissions, action classification, read-only vs mutating tool boundaries, approval gates, self-approval prevention, and evidence capture.

Track: ai-security-engineering

Open Lab →

AI-SECURITY-ENGINEERING · ai-security · intermediate

Prompt Boundary Engineering

intermediate

Intermediate LAB teaching how to engineer prompt boundaries by separating trusted instructions from untrusted user input, retrieved content, tool output, and model-generated recommendations.

Track: ai-security-engineering

Open Lab →

AI-SECURITY-ENGINEERING · ai-security · intermediate

Secure AI Application Architecture

intermediate

Intermediate LAB teaching secure AI application architecture patterns across frontend, backend/API, model, retrieval, tool, policy, approval, evidence, observability, and runtime boundaries.

Track: ai-security-engineering

Open Lab →

AI-SECURITY-ENGINEERING · ai-security · intermediate

AI Security Engineering Overview

intermediate

Intermediate LAB introducing secure AI system engineering, AI threat surfaces, control boundaries, prompt/model/retrieval/tool/policy/evidence layers, and the relationship between AI governance and AI security engineering.

Track: ai-security-engineering

Open Lab →

AI-GOVERNANCE · governance · intermediate

AI Cost, Token, and Rate Limit Governance

intermediate

Intermediate LAB teaching how to govern AI cost, token usage, runaway agent loops, repeated tool attempts, expensive retrieval calls, rate limits, budget thresholds, and operational evidence.

Track: ai-governance-command-center

Open Lab →

AI-GOVERNANCE · governance · intermediate

AI Audit Evidence and Traceability

intermediate

Intermediate LAB teaching how to build audit-ready evidence trails for AI decisions, prompts, retrieved context, tool attempts, policy decisions, human approvals, blocked actions, and executive summaries.

Track: ai-governance-command-center

Open Lab →

AI-GOVERNANCE · governance · intermediate

Human Approval Gate Design

intermediate

Intermediate LAB teaching how human approval gates prevent AI agents, tool-use, prompt injection, and retrieval risk from becoming ungoverned enterprise execution.

Track: ai-governance-command-center

Open Lab →

AI-GOVERNANCE · governance · intermediate

RAG Data Boundary and Retrieval Risk

intermediate

Intermediate LAB teaching how RAG and retrieval systems create AI governance risk when trusted, untrusted, sensitive, stale, or poisoned context is retrieved and treated as authority.

Track: ai-governance-command-center

Open Lab →

AI-GOVERNANCE · governance · intermediate

Prompt Injection and Tool Hijacking

intermediate

Intermediate LAB teaching how prompt injection can manipulate AI agent instructions, tool selection, policy bypass attempts, and approval-gated execution paths.

Track: ai-governance-command-center

Open Lab →

AI-GOVERNANCE · governance · intermediate

AI Agent Tool-Use Risk

intermediate

Intermediate LAB teaching how AI agent tool-use becomes enterprise risk when recommendations, API calls, human approvals, and autonomous execution boundaries are not clearly governed.

Track: ai-governance-command-center

Open Lab →

AI-GOVERNANCE · governance · intermediate

AI Governance Command Center Overview

intermediate

Learn how an enterprise AI governance command center connects intake, risk, policy, approvals, evidence, observability, and operational handoff.

Track: ai-governance-command-center

Open Lab →

AI-GOVERNANCE · governance · intermediate

Governance Intake and Risk Tiering

intermediate

Learn how intake questions and risk tiers create consistent AI governance triage before a workflow reaches production.

Track: ai-governance-command-center

Open Lab →

AI-GOVERNANCE · governance · intermediate

Policy Gates and Human Approval

intermediate

Learn how policy gates convert AI governance rules into deterministic allow, deny, or approval-required decisions.

Track: ai-governance-command-center

Open Lab →

AI-GOVERNANCE · governance · intermediate

Agent Workflow Governance

intermediate

Learn how governed agent workflows separate recommendation, approval, and execution boundaries.

Track: ai-governance-command-center

Open Lab →

AI-GOVERNANCE · governance · intermediate

Observability, Cost Controls, and Support Handoff

intermediate

Learn how traces, cost controls, guardrails, SOPs, and runbooks make AI workflows operable after demo or deployment.

Track: ai-governance-command-center

Open Lab →

AI-GOVERNANCE · governance · intermediate

Executive Demo and Portfolio Boundary

intermediate

Learn how to present an AI governance command center to executives while preserving case-study, demo, and production boundaries.

Track: ai-governance-command-center

Open Lab →

AWS · identity · foundation

AWS IAM Basics

foundation

Foundational AWS IAM lab focusing on identity evaluation, least privilege, and interview-ready reasoning.

Open Lab →

AWS · identity · intermediate

AWS IAM Policy Evaluation

intermediate

Intermediate LAB teaching AWS effective-permission reasoning across identity policies, resource policies, permission boundaries, session policies, SCPs, and explicit deny.

Open Lab →

AWS · identity · intermediate

AWS Permission Boundary Basics

intermediate

Intermediate LAB teaching how AWS permission boundaries constrain maximum principal authority without granting access by themselves.

Open Lab →

AWS · identity · intermediate

AWS SCP Guardrail Reasoning

intermediate

Intermediate LAB teaching how AWS Service Control Policies define organization-level maximum permissions without granting access by themselves.

Open Lab →

AWS · identity · intermediate

AWS Resource Policy Evaluation

intermediate

Intermediate LAB teaching how AWS resource-based policies participate in authorization decisions alongside identity policies, boundaries, SCPs, and explicit deny.

Open Lab →

AWS · storage · intermediate

AWS S3 Public Access Risk

intermediate

Applied L2 LAB teaching how S3 public access risk emerges from bucket policy, Block Public Access settings, ACL history, identity permissions, resource policies, and organization guardrails.

Open Lab →

AWS · security · intermediate

AWS KMS Key Policy Evaluation

intermediate

Intermediate LAB teaching how AWS KMS key policies, IAM permissions, grants, encryption context, and organization guardrails combine to control cryptographic access.

Open Lab →

AWS · security · intermediate

AWS Secrets Manager Access Evaluation

intermediate

Intermediate LAB teaching how AWS Secrets Manager access depends on IAM permissions, resource policies, KMS decrypt authority, explicit deny, and organization guardrails.

Open Lab →

AWS · compute · intermediate

AWS Lambda Execution Role Risk

intermediate

Intermediate LAB teaching how Lambda execution roles create workload identity risk when function update authority, iam:PassRole, Secrets Manager access, KMS decrypt, and resource permissions combine.

Open Lab →

AWS · detection · intermediate

AWS CloudTrail Detection Reasoning

intermediate

Intermediate LAB teaching how CloudTrail evidence supports detection reasoning for iam:PassRole, sts:AssumeRole, Lambda updates, Secrets Manager access, KMS decrypt, and workload identity activity.

Open Lab →

AWS · identity · intermediate

AWS Cross-Account Role Escalation

intermediate

Principal LAB modeling deterministic AWS cross-account trust reachability through sts:AssumeRole, Shield finding linkage, and Aegis Runtime identity signal mapping.

Open Lab →

AWS · identity · intermediate

AWS Privilege Escalation via iam:PassRole

intermediate

Principal LAB modeling deterministic AWS privilege escalation through iam:PassRole combined with compute service creation or update capability.

Open Lab →

AWS · identity · advanced

AWS Role Chaining Escalation

advanced

Principal LAB modeling deterministic AWS privilege expansion through chained sts:AssumeRole paths across multiple IAM roles.

Open Lab →

AZURE · identity · foundation

Azure Entra ID Basics

foundation

Starter lab introducing Azure Entra ID identity flow, Conditional Access, and RBAC concepts.

Open Lab →

GCP · identity · foundation

GCP IAM Basics

foundation

Starter lab covering Google Cloud IAM principals, policy bindings, and request-time authorization.

Open Lab →
No labs match that search yet.

Planned Learning Path

AI Security Engineering L2 Track

A planned SecureTheCloud Labs intermediate track for secure AI system engineering: prompt boundaries, tool permissions, retrieval controls, runtime guardrails, abuse controls, testing harnesses, and evidence packages.

◇ AI Security Engineering Intermediate ▣ L2 Track • No backend exposure
Open AI Security Engineering Track →

Practical & Hands-On

Real-world labs and exercises that build production-ready security skills.

Structured Learning

Planned learning paths that progress from foundational to advanced.

Cloud-Native Focus

Security and governance practices for modern cloud and AI systems.

Trust & Boundaries

Education-first platform with no backend exposure and no live enforcement.