Awarded for completing Secure File Upload Handling and passing its exam, demonstrating the ability to identify the four distinct risk categories a file upload feature introduces, validate file type by content signature rather than extension or declared type alone, store uploaded files outside any executable location, replace an untrusted original filename with a generated identifier, apply size and quantity limits proportionate to a feature's legitimate use case, scan uploaded content before it reaches other users while understanding scanning's honest limits, serve files back with accurate content type and disposition settings, and enforce explicit, per-retrieval access control on uploaded content.
Certificates are designed to be checked, not just displayed.
The credential is valid for 12 months from issue. Its public page states the expiry date, and renewing means passing the current exam again — so the credential always reflects the current material.