Data does not become instruction.
Retrieved content is classified and separated from system rules before generation.
CERT Learning & Research Advisor
CLARA is a hands-on learning environment for CERT professionals. Learners configure an AI capability, test it on synthetic data, use it in a bounded SOC mission, then support each decision with evidence.
See how it worksA complete chain, not a prompt demo
The curriculum covers the model and its route, prompts, RAG, agents, tools, permissions, guardrails, evals and observability. Components are handled separately before being assembled.
A model output remains a proposal. An action goes through a bounded tool; a claim cites its source; a sensitive decision waits for a human. Failures, missing evidence and disagreements stay visible.
Understand tokens, context, generation, embeddings, retrieval, agents and limits before configuring anything.
Select a model route, version a prompt, build a RAG and define tools, permissions and stopping points.
Compare variants on the same golden and adversarial cases; measure accuracy, robustness and cost.
Expose the system to hostile sources, prompt injections and invalid outputs, then correct it without hiding failure.
Use the capability in an isolated SOC lab with synthetic data, read-only actions and explicit approvals.
Connect configuration, traces, evidence, corrections and rollback in a reusable artefact subject to human review.
One AI foundation, several CERT contexts
Initial vertical · SOC
The learner queries a synthetic event set, develops competing hypotheses, cites supporting and contradicting elements, then writes a sourced escalation decision.
Planned extensions
These perspectives will reuse the same eight AI mastery families. The cyber context changes; evidence, supervision and tool-control rules remain shared.
Guardrails are part of the exercise
Retrieved content is classified and separated from system rules before generation.
It produces a structured proposal; policy, allowlist and adapter decide whether execution is possible.
Refusal, approval and disagreement are recorded before any sensitive state change.
A successful quiz, trace or model output never proves acquired competence on its own.
Position in August 2026
The twelve-unit common core and first SOC vertical run on synthetic scenarios. Learners can build an AI capability, conduct a bounded investigation and connect conclusions to evidence and a debrief.
Persistent progress, user management and the pilot experience still need to ship before opening. OffSec, DFIR, CTI and VOC perspectives will follow consolidation of the SOC path.
Pilot, partnership or technical discussion
Describe your context, the people involved and what you want to test. Your message goes directly to the CERTSKILLS team.
contact@certskills.fr