One light, three disciplines,
one mission for the public sector

Refract AI Collective is a vendor-neutral community helping public sector teams demystify, adopt, and secure artificial intelligence — bringing hackers, defenders, and builders together to stay ahead of a fast-moving revolution.

Scroll
Our Mission

Enabling and securing the public sector through community

The institutions that serve the public — agencies, municipalities, schools, hospitals, and critical infrastructure — are adopting AI faster than they can secure it. The people defending them rarely have the budget, the vendor relationships, or the time to keep pace with a technology that reinvents itself every quarter.

Refract exists to close that gap. We are a non-commercial collective that pools knowledge, tooling, and expertise from across the security vendor community and channels it toward a single goal: helping public servants understand AI, deploy it responsibly, and defend it against real adversaries.

We translate frameworks into practice, run hands-on training and open working sessions, and create a place where the people protecting our constituents can learn in the open — together, and without a sales pitch attached.

The Spectrum

Three teams. One converged community.

AI security fails when offense, defense, and engineering work in isolation. Refract is built so all three sit at the same table.

Red · Offense

The Hackers

Adversarial ML, red-teaming of LLMs, prompt injection, model extraction, and the attack techniques catalogued in MITRE ATLAS. We find the failure modes before adversaries do.

Blue · Defense

The Defenders

Monitoring, guardrails, governance, and incident response for AI systems. We turn frameworks like the NIST AI RMF into operational controls public sector teams can actually run.

Yellow · Build

The Builders

Engineers and data scientists shipping AI into mission systems. We embed security by design — so the things we build for constituents are safe from the first line of code.

What We Do

Demystify, train, and stay in front of the wave

Practical, community-driven programs designed for the realities of public sector teams.

01

Demystify AI

Plain-language briefings that cut through the hype — what generative AI, agents, and ML actually are, where they help, and where they quietly introduce risk.

02

Train & Enable

Hands-on labs, workshops, and tabletop exercises on securing AI — from prompt-injection drills to building an AI governance program from scratch.

03

Secure AI Systems

Threat modeling AI deployments against MITRE ATLAS, OWASP for LLMs, and the NIST AI RMF — mapped to controls that hold up under audit and attack.

04

Leverage the Vendor Community

We bring tooling, research, and experts from across the security vendor ecosystem to the public sector — neutrally, with no product agenda.

05

Serve the Mission

Everything maps back to one outcome: protecting the constituents and critical services that public institutions are entrusted to safeguard.

06

Stay Ahead

A standing community signal — sharing the latest techniques, incidents, and defenses so members never have to face a moving target alone.

Frameworks & References

Standing on shared foundations

The Collective organizes its work around open, authoritative frameworks — so members speak a common language with auditors, vendors, and adversaries alike.

Join the Collective

Come help us protect the public
through the AI wave

Practitioners, public servants, researchers, and curious learners are all welcome. Membership is free — bring your color to the spectrum.