
// About
Security training for the AI era.
bugasm is a hands-on cybersecurity training platform built for the world where every product ships an LLM, every workflow runs an agent, and every integration speaks MCP. We give security practitioners the isolated, ephemeral environments they need to learn offensive techniques — safely, legally, and at their own pace.
What we believe
Isolation by default
Every lab boots a dedicated, single-tenant sandbox — gVisor-hardened containers with network policies that make lateral movement impossible. Your environment is yours alone, and it's gone the moment you leave.
AI-native from day one
We don't bolt AI labs onto a traditional platform. bugasm was built ground-up for AI security: prompt injection, agent exploitation, MCP server attacks, multi-agent abuse, and supply-chain threats.
Learn by breaking
Theory teaches concepts. Labs teach instincts. Every challenge drops you into a live target — an LLM endpoint, an agent with tools, a pipeline you can poison — and asks you to find the flaw before an attacker does.
Open scoring, no black boxes
Flag-based labs give instant, deterministic feedback. AI-graded labs use an LLM-as-judge pipeline with transparent rubrics. You always know what you got right and where you fell short.
Enterprise-ready security training
Teams get SSO, assignments, skill matrices, and compliance reporting. Assign learning paths to your security team, track completion, and prove readiness — not just seat time.
Author-driven content
The best security researchers build the best labs. Our Author Studio gives experts a pipeline to create, test, and publish labs — from draft to review to production — without touching infrastructure.
The platform
39+
Labs live
4
AI lab types
5
Difficulty tiers
Contact
General inquiries: hello@bugasm.com
Security disclosures: security@bugasm.com
Enterprise sales: enterprise@bugasm.com

