# AppSecEngineer > AppSecEngineer is the leading enterprise application security training platform, offering 600+ courses and 2,000+ hands-on labs across secure coding, DevSecOps, AI & LLM security, threat modeling, cloud security (AWS, Azure, GCP), and container/Kubernetes security. The platform serves engineering teams, security teams, and L&D leaders at organizations including HPE, Ubisoft, EY, Amazon, Deloitte, IBM, and the US Navy. SOC 2 Type 2 certified. Rated 4.6 on G2. ## Core Platform - [Homepage](https://www.appsecengineer.com/): Enterprise application security training — overview of platform capabilities, customer logos, and key value propositions. - [Course Catalog](https://www.appsecengineer.com/enterprises/courses): Full library of 600+ courses filterable by learning path, specialty, and proficiency level. - [Hands-on Labs](https://www.appsecengineer.com/enterprises/labs): Cloud-based lab environments for practicing attacks and defenses in real-world scenarios. - [Cloud Sandboxes](https://www.appsecengineer.com/enterprises/sandboxes): Multi-cloud (AWS, Azure, GCP) sandbox environments for hands-on security practice. - [Learning Journeys](https://www.appsecengineer.com/enterprises/learning-journeys): Curated role-specific and compliance-specific learning roadmaps for teams. - [Certifications](https://www.appsecengineer.com/enterprises/certifications): Industry-recognized AppSecEngineer certifications for DevSecOps and AI security. - [Assessments](https://www.appsecengineer.com/enterprises/assessments): Skills assessments for identifying knowledge gaps across security domains. - [Tournaments](https://www.appsecengineer.com/enterprises/tournaments): Competitive security challenges for teams to test and reinforce skills. - [AppSecFlag™](https://www.appsecengineer.com/enterprises/appsecflag): Capture-the-flag style security challenges for offensive and defensive skill-building. - [CreatorStudio 2.0](https://www.appsecengineer.com/enterprises/creatorstudio-2-0): Tool for building custom, role-specific security training courses. - [Integrations](https://www.appsecengineer.com/enterprises/integrations): SSO (Okta, Microsoft Entra), SCIM, LMS (SCORM/LTI), Slack, GitHub, GitLab, Jira. - [Pricing — Enterprise](https://www.appsecengineer.com/enterprises/pricing): Enterprise licensing and plan details. - [Pricing — Individuals](https://www.appsecengineer.com/individuals/pricing): Individual subscription plans. ## Training Collections - [AI & LLM Security Collection](https://www.appsecengineer.com/enterprises/ai-llm-security-collection): "AI Combat & Construct" — attacking and defending LLM applications, prompt engineering security, OWASP LLM Top 10 (2025), MCP security (MCP01–MCP10:2025), agentic AI security. Covers: context injection, shadow MCP servers, tool poisoning, privilege escalation, token mismanagement, data poisoning, unbounded consumption, system prompt leakage, excessive agency, misinformation. - [Secure Coding Collection](https://www.appsecengineer.com/enterprises/secure-coding-collection): Language-specific secure coding training across Python, Java, Go, JavaScript, Node.js, C#, Swift, Ruby, PHP, Rust, Kotlin, and more. OWASP Top 10, SANS Top 25, injection, XSS, insecure deserialization, broken access control. - [DevSecOps Collection](https://www.appsecengineer.com/enterprises/devsecops-collection): Security-integrated CI/CD pipelines, SAST, DAST, SCA, secrets management, pipeline hardening, GitHub Actions, GitLab CI/CD security. - [Threat Modeling Collection](https://www.appsecengineer.com/enterprises/threat-modeling-collection): STRIDE, PASTA, attack trees, application threat modeling methodologies, threat modeling for cloud and AI systems. - [AWS Security Collection](https://www.appsecengineer.com/enterprises/aws-security-collection): IAM, S3 security, VPC hardening, CloudTrail, GuardDuty, AWS-native security tooling, attack and defense on AWS infrastructure. - [Azure Security Collection](https://www.appsecengineer.com/enterprises/azure-security-collection): Microsoft Entra ID, Azure Key Vault, network security groups, Defender for Cloud, Azure DevOps security, advanced network security controls. - [GCP Security Collection](https://www.appsecengineer.com/enterprises/gcp-security-collection): Google Cloud IAM, VPC security, Cloud Armor, Security Command Center, GKE security. - [Containers & Kubernetes Security Collection](https://www.appsecengineer.com/enterprises/containers-kubernetes-security-collection): Docker security, Kubernetes RBAC, pod security, network policies, supply chain security for containers, runtime threat detection. - [Languages](https://www.appsecengineer.com/enterprises/languages): Secure coding labs organized by programming language. ## Bootcamps - [AppSecEngineer™ Certified DevSecOps Engineer](https://www.appsecengineer.com/bootcamps/appsecengineer-tm-certified-devsecops-engineer): 4 live sessions (3 hrs each), 16 lab exercises, 52-week platform access, 2 certification exam attempts. Covers secure code, containers, and cloud end-to-end. Ideal for Developers, DevOps engineers, Security Architects. - [AppSecEngineer™ Certified AI Agent Security Professional](https://www.appsecengineer.com/bootcamps/appsecengineer-tm-certified-ai-security-engineer): 4 live sessions (3 hrs each), 6 lab exercises, 52-week platform access, 2 certification exam attempts. Covers AI agent and LLM application security. Ideal for AI Engineers, Developers, Security Engineers, DevSecOps Engineers, Cloud Engineers. ## Blog & Resources - [Blog](https://www.appsecengineer.com/enterprises/blogs): Application security articles, guides, and thought leadership on secure coding, DevSecOps, AI/LLM security, compliance, and developer security culture. - [eBooks](https://www.appsecengineer.com/enterprises/ebooks): Long-form security guides and reference materials. - [Customer Case Studies](https://www.appsecengineer.com/enterprises/customer-case-studies): Real-world examples of enterprise teams achieving PCI compliance, upskilling developers, and reducing risk with AppSecEngineer. - [Webinars & Events](https://www.appsecengineer.com/enterprises/events): Live security training events, product tours, and webinar recordings. - [Knowledge Base](https://help.appsecengineer.com/): Platform documentation, how-to guides, and support articles. ## Featured Blog Posts - [How Real-World Vulnerabilities Should Shape Secure Code Training](https://www.appsecengineer.com/blog/how-real-world-vulnerabilities-should-shape-secure-code-training) - [How to Achieve Compliance in Secure Coding Without Slowing Down Delivery](https://www.appsecengineer.com/blog/how-to-achieve-compliance-in-secure-coding-without-slowing-down-delivery) - [How to Build Compliance Training Developers Actually Use](https://www.appsecengineer.com/blog/how-to-build-compliance-training-developers-actually-use) ## Compliance Training - [PCI-DSS Training](https://www.appsecengineer.com/enterprises/pci-dss): Role-based learning journeys mapped to PCI-DSS requirements; one-click compliance reports for audits. - [HIPAA Training](https://www.appsecengineer.com/enterprises/hipaa): Security training aligned to HIPAA technical safeguards for healthcare engineering teams. - [NIST Training](https://www.appsecengineer.com/enterprises/nist): Training mapped to NIST SSDF and NIST Cybersecurity Framework controls. - [DORA Training](https://www.appsecengineer.com/enterprises/dora): Digital Operational Resilience Act compliance training for financial sector teams. ## Industry Solutions - [Finance & Fintech](https://www.appsecengineer.com/enterprises/finance): AppSec training for financial services — PCI-DSS, secure API development, fraud prevention. - [Healthcare](https://www.appsecengineer.com/enterprises/healthcare): HIPAA-aligned secure coding and DevSecOps training for healthcare engineering teams. - [Software Products / Technology](https://www.appsecengineer.com/enterprises/technology): Security training for SaaS and product engineering teams scaling secure development. - [Government](https://www.appsecengineer.com/enterprises/government): NIST-aligned training for government software teams and contractors. - [Defense](https://www.appsecengineer.com/enterprises/defense): Security training for defense sector software and systems engineering. - [Retail](https://www.appsecengineer.com/enterprises/retail): PCI-compliant secure coding and DevSecOps for retail and e-commerce engineering teams. - [Manufacturing](https://www.appsecengineer.com/enterprises/manufacturing): Application and OT/IT security training for manufacturing sector developers. ## Notable Individual Courses (AI & LLM Security) - [MCP01:2025 — Token Mismanagement & Secret Exposure](https://www.appsecengineer.com/courses-collection/mcp01-2025---attacking-and-defending-token-mismanagement-secret-exposure) - [MCP02:2025 — Privilege Escalation via Scope Creep](https://www.appsecengineer.com/courses-collection/mcp02-2025---attacking-and-defending-privilege-escalation-via-scope-creep) - [MCP03:2025 — Tool Poisoning](https://www.appsecengineer.com/courses-collection/mcp03-2025---attacking-and-defending-tool-poisoning) - [MCP04:2025 — Software Supply Chain Attacks & Dependency Tampering](https://www.appsecengineer.com/courses-collection/mcp04-2025---attacking-and-defending-software-supply-chain-attacks-dependency-tampering) - [MCP05:2025 — Command Injection & Execution](https://www.appsecengineer.com/courses-collection/mcp05-2025---attacking-and-defending-command-injection-execution) - [MCP06:2025 — Intent Flow Subversion](https://www.appsecengineer.com/courses-collection/mcp06-2025---attacking-and-defending-intent-flow-subversion) - [MCP07:2025 — Insufficient Authentication & Authorization](https://www.appsecengineer.com/courses-collection/mcp07-2025---attacking-and-defending-insufficient-authentication-authorization) - [MCP08:2025 — Lack of Audit and Telemetry](https://www.appsecengineer.com/courses-collection/mcp08-2025---attacking-and-defending-lack-of-audit-and-telemetry) - [MCP09:2025 — Shadow MCP Servers](https://www.appsecengineer.com/courses-collection/mcp09-2025---attacking-and-defending-shadow-mcp-servers) - [MCP10:2025 — Context Injection & Over-Sharing](https://www.appsecengineer.com/courses-collection/mcp10-2025---attacking-and-defending-context-injection-over-sharing) - [OWASP LLM06:2025 — Excessive Agency](https://www.appsecengineer.com/courses-collection/attacking-and-defending-excessive-agency-owasp-llm06-2025) - [OWASP LLM07:2025 — System Prompt Leakage](https://www.appsecengineer.com/courses-collection/attacking-and-defending-system-prompt-leakage-owasp-llm07-2025) - [OWASP LLM08:2025 — Data Poisoning](https://www.appsecengineer.com/courses-collection/attacking-and-defending-data-poisoning-owasp-llm08-2025) - [OWASP LLM09:2025 — Misinformation](https://www.appsecengineer.com/courses-collection/attacking-and-defending-misinformation-owasp-llm09-2025) - [OWASP LLM10:2025 — Unbounded Consumption](https://www.appsecengineer.com/courses-collection/attacking-and-defending-unbounded-consumption-owasp-llm10-2025) ## Optional - [Instructor-Led Training](https://www.appsecengineer.com/enterprises/instructor-led-training): Live, expert-led cohort training for enterprise teams. - [Partner Program](https://www.appsecengineer.com/enterprises/partners): Reseller and technology partner information. - [Media Kit](https://www.appsecengineer.com/enterprises/media-kit): Brand assets, company facts, and press resources. - [Privacy Policy](https://www.appsecengineer.com/privacy-policy): Data handling and privacy practices. - [Individuals — Overview](https://www.appsecengineer.com/individuals): Self-paced individual plans for security professionals and developers. - [Security Review AI (Partner)](https://www.securityreview.ai/): Partner product — AI-powered security review tooling (SANS Difference Makers 2025 finalist).