Skip to content
Kyna Book a 30-minute call

Your people ship AI-written code.
Can anyone say it is safe?

Kyna teaches software teams to build with AI coding agents and ship the result safely to production. Three days, in your office, up to 12 people. In Dutch or in English.

You said yes to AI. Now someone has to answer for it.

Your organisation did the right thing. People use AI coding agents, and they are faster than they were. Work that took a quarter takes a fortnight.

Then the questions start.

  • A colleague built a working app in a week. It now holds customer data. Nobody reviewed it.
  • A pull request arrives with 2,000 lines in it. Your reviewer approves it, because reading it properly would take two days.
  • Someone asks where the API keys are. The honest answer is "in the repository".
  • An auditor asks how you check AI-written code before it goes live. There is no answer to give.

None of this is an argument for slowing down. It is an argument for teaching the people who already build this way how to finish the job.

Who this is for

  • The person who is accountable. You are a CTO, an engineering manager, a head of product, or you own IT and security. Your name is on it when something leaks.
  • The people who attend. Up to 12 of them. Developers, yes — but also the product managers, analysts, marketers and operations people who now build real things with AI and did not come up through engineering. The course assumes no prior programming knowledge and does not slow down for it either.
  • Organisations that already build this way. If your people are not using AI coding agents yet, this is the wrong course. Come back when they are.

What your team can do on the Monday after

Not "will understand". Can do.

The programme

Four modules. Every session runs the same way: the trainer shows it, your people do it in pairs on their own machines, and there is a check that it worked. Across the three days that is more than three hours of hands-on work for every hour of listening. Your team builds and breaks real things. They do not watch slides, and there are no quizzes.

1. First Steps: Build Your First App with AI

For the people on your team who build with AI but never came up through engineering. From an idea to a live app that real people use: writing a brief the AI can follow, building in small safe steps, reading what it made, working from their own machine with Git, and shipping it.

Topics: from idea to spec · build in small steps · look under the hood · your own machine: terminal & Git · ship it and share it.

2. Security Foundations for Vibe Coders

The security failures that actually turn up in AI-written code, taught with vibe-coded examples rather than textbook ones. In the room your team finds and fixes four of them in their own application: secrets and credentials, authentication and authorisation including row-level security, input validation and injection, and what your data does when an AI tool touches it.

The fifth is the code you did not write. Between day 2 and day 3 every participant audits the dependency tree of their own project and records a decision, with a reason, for every flagged package. We check that work at the start of day 3. It is part of the course and it is assessed — it just does not need a trainer standing over it.

The module closes with threat-modelling an MVP. Each participant leaves with their own pre-deploy security checklist.

Topics: secrets & credentials · authentication & authorisation · input validation & injection · data, privacy & AI workflows · dependencies & supply chain (assessed, between the days) · security testing & pentesting · threat modelling your MVP.

3. The Open Internet: What the World Sees of Your App

HTTPS and TLS, open ports, rate limiting, web application firewalls and the edge, and how to buy a pentest that actually finds things. Your team sees their deployed app the way the internet does, then puts the cheap, high-impact defences in front of it.

Topics: HTTPS & TLS · port scanning · rate limiting & abuse protection · WAF & the edge · getting tested for real.

4. You Are the Attack Surface: Security Posture & Hygiene

Your code can be perfect and you can still be breached through a reused password, a phished account, or a laptop full of .env files. Finding the weakest link, the right kind of MFA, hardening a development machine, and deciding on purpose whether your organisation needs endpoint detection.

Topics: security posture · accounts & MFA · the dev machine · EDR & endpoint protection.

The part that is tailored is the part that matters: your people work on their own application for all three days. Their brief, their repository, their deployment, their threat model. The three day themes and their order are fixed, because day 2 works on what your team built on day 1 and day 3 hardens what day 2 produced.

Two reasons to believe this

Your team leaves with artefacts, not notes.

Every topic ends in a challenge with no instructions — only an end state. By the end of three days each participant has produced, for your organisation:

  • a pre-deploy security checklist they wrote themselves
  • a threat model of one of your own applications
  • an exposure baseline of one of your own deployments
  • a dependency audit of one of your own projects, with a recorded decision and a reason for every flagged package
  • a posture review another person on the team could re-run
  • a written recommendation on whether you need endpoint detection

These are documents you keep. They outlast the course.

Two trainers who have shipped and who have taught.

Emile Bosch — over 25 years building software, and team lead at organisations including Funda, IKEA and Europol.

Wouter de Vos — founder of the Codaisseur coding academy, where more than 1,500 developers were trained. Background in psychology, which is why the course is about habits and not only about tools.

What it costs

In-company — the main way we work

We come to you. Your team, your code, your deployment. All prices exclude VAT.

The Kyna three-day programme

€24,000

Up to 12 people. All four modules. Your team works on your own application for all three days. At your office or online. Dutch or English.

That is €2,000 per person, or €667 per person per day.

Every participant also gets:

  • a certificate of completion
  • three months of access to the course material

Our day-one guarantee. If at the end of the first day you decide this is not right for your team, say so and we stop. You pay nothing.

The Kyna one-day intensive

€9,500

Up to 12 people. The security essentials, condensed into one day: secrets, authentication, what the internet sees, and the pre-deploy checklist. The right starting point if three days out is more than you can take right now.

Open seats — for individuals

For people who want the skill for themselves rather than for their employer. You attend with people from other organisations.

Three-day open seat

€2,900 per person

One-day open seat

€1,450 per person

We open the first open-seat dates after the first in-company programmes run in November 2026. Put your name down and we will tell you the dates first.

One email when the dates are set. Nothing else.

Fair questions

"We already have a security team."

Good. They are not the problem. The problem is the eleven people shipping code who do not work for them and do not know what to ask. This course puts the floor under those eleven so your security team is reviewing work that is already mostly right.

"Our people are not developers."

Most of them no longer need to be, and that is the point. The first module assumes no programming knowledge at all. The security modules teach judgment you can apply to code an AI wrote for you — which is exactly the situation your non-developers are in.

"€24,000 is a lot of money."

It is €667 per person per day, and the comparison is not another course. It is one remediation project, one emergency consultant, or one incident. You are buying the version of this that happens on a calendar instead of at 2am. And you do not have to take our word for any of it for more than a day — see the day-one guarantee above.

"Can't we just put together something internally?"

You can. Many organisations have, and most of what they produce is a guidelines document that nobody reads, because it has no practice attached. The reason this works is three days of your team breaking and fixing their own applications, with two people in the room who have done it before.

"Three days out of delivery is expensive."

It is. Take the one-day intensive instead — it is designed for exactly this answer. It will not get you the threat models and the posture review, and you should know that going in.

"Is this not just going to be out of date in six months?"

The tools will be. Secrets, authorisation, input validation, dependencies, what the internet can reach, and who has your passwords will not be. That is why three of the four modules are about those, and only one is about the tooling.

Practical questions

How many people can attend?

Up to 12. Beyond that the hands-on parts stop working, so we do not do it.

Dutch or English?

Either. You choose when you book. The written material is in English.

Where?

At your office, anywhere in the Netherlands. Online also works, though the exercises are better in a room.

What do participants need?

A laptop they can install software on, and an account they can use for an AI coding agent. We send a short setup note a week in advance. No prior programming knowledge is required.

Do you use our own code?

Yes, where you want us to. The threat model, the exposure baseline and the posture review are most useful when they are about your real systems. If you would rather we did not touch production, we use the course applications instead.

Is there work between the days?

Some, and one piece of it is assessed. Between day 2 and day 3 every participant audits the dependency tree of their own project and records a decision, with a reason, for every flagged package. We check it at the start of day 3. It is designed to take about an hour. Each session also sets short follow-up work; that part is not assessed.

Can we split the three days across weeks?

Yes. Three consecutive days works best. Three separate days over three weeks is the most common alternative, and it gives people more room for the work between the days.

When can you start?

The first programmes run in November 2026. Book a call and we will tell you what is still open.

What does the team keep afterwards?

Their own artefacts — the checklist, the threat model, the exposure baseline, the dependency audit, the posture review, and the endpoint-detection recommendation. On top of that, every participant on the three-day programme gets a certificate of completion and three months of access to the course material.

What does the day-one guarantee cover?

The three-day in-company programme. If at the end of day 1 you tell us it is not right for your team, we stop there and you pay nothing. Not part of it — nothing.

How does invoicing work?

All prices exclude VAT. We invoice the organisation after we agree the dates.

What if we need to move the dates?

Tell us and we move them. We will agree the notice period in writing before you sign.

Talk to us for half an hour

No sales deck. We ask what your team builds, what already worries you, and whether three days is the right shape. If it is not, we will say so.

Book a 30-minute call

We reply within one working day. We do not add you to a mailing list and we do not share your details with anyone.