Free, self-paced courses on software supply chain security — from fundamentals to working fluency with the Safeguard platform. Levels run beginner to advanced; every course lists its modules and lessons up front, and courses that end in a certification say so on the card.
Modern applications are mostly assembled from open-source code, and attackers know it. This course takes you from supply-chain fundamentals to working fluency with the Safeguard platform: connecting repositories, running scan engines, triaging findings with VEX, generating SBOMs, proving compliance, and using Gold, the CLI, and the MCP server. Complete all lessons and pass a timed 30-question exam to earn the Safeguard Certified Practitioner credential.
Leads to Safeguard Certified Practitioner
View course →Learn what a software supply chain is, why attacks against it are rising, and how SBOMs, the four supply-chain roles (Producer, Distributor, Reseller, Consumer), and Safeguard's ESSCM, Portal, TPRM, and OSM products fit together into one platform.
View course →Learn how Safeguard finds vulnerabilities, scores component risk with Risk Score and SCAL, prioritizes what actually matters with reachability analysis, and fixes issues autonomously with Griffin, enforced by policies, gates, and guardrails.
View course →Learn how to generate and read SBOMs for compliance, manage license risk, work with Safeguard's GRC and VEX capabilities, and shift security left by scanning and gating releases directly inside CI/CD pipelines.
View course →A working tour of Safeguard's flagship ESSCM product: what it scans, how Risk Score and SCAL turn raw findings into a prioritized worklist, and the connect-to-fix loop that takes a repo from unknown risk to a gated, remediated release.
View course →How Safeguard's Portal product turns an internal SBOM into an externally shareable, audit-grade artifact — Publish vs Share, the Product/Project vocabulary split, and the Trust Center's public posture page.
View course →The consumer-side mirror image of ESSCM: how to request, validate, and continuously monitor the software your suppliers ship you, using TPRM's vendor management, SBOM request lifecycle, and risk scoring.
View course →The shared open-source intelligence layer beneath every Safeguard product: OSM's per-package scoring, and Gold's free directory plus its paid hardened-artifact registry.
View course →How Safeguard secures AI as a first-class object — model scanning, AI-BOM discovery, the AI Gateway firewall, MCP Guardrail — and how the platform's own purpose-built models (Griffin, Eagle, Lion/Lino) and agent-native design fit together.
View course →A full walk through Safeguard's governance, risk, and compliance suite: the eleven app tabs, continuous evidence mapping, and how the platform maps to EO 14028, NIST SSDF, SLSA, and VEX.
View course →How Safeguard proves what a software artifact actually is: SLSA build levels, Sigstore keyless signing, in-toto provenance, and the SCAL/LCAL scores that turn all of it into a single number you can gate a release on.
View course →Two of Safeguard's sharpest-edged detection engines: secrets scanning that verifies credentials are actually live before you panic, and Eagle, the malware classifier that watches package registries and container images for intentionally malicious code.
View course →The three-layer governance model that turns Safeguard from a reporting tool into an enforcement platform: Policies decide what's a problem, Gates decide when to stop a release, and Guardrails decide what's allowed to happen at runtime.
View course →How Safeguard finds vulnerabilities before they reach public CVE feeds, the SGZ advisory format that carries those findings, and why a research pipeline changes what 'being protected' actually means.
View course →Three ways Safeguard tests application security by actually exercising it rather than just reading dependency manifests: static dataflow analysis, safe scoped dynamic testing, and defensive adversary emulation under a strict safety kernel.
View course →Two enforcement points at the edges of the supply chain: Runtime Protection watching what a workload actually does once it's live, and Package Firewall stopping a bad dependency before it's ever installed.
View course →Learn how Safeguard extends supply-chain security into data-at-rest: classifying PII/PHI/PCI and secrets across S3 and RDS, the redaction mandate that keeps raw sensitive values out of the findings store, and how DSPM findings map onto GDPR, HIPAA, PCI DSS, and CCPA obligations.
View course →Understand Safeguard's SecOps/SIEM capability: OCSF-normalized ingestion from CloudTrail, Azure, GCP, syslog/CEF and webhook sources; detection via Sigma rules and IOC matching; alert deduplication; and how it relates to AutoTriage's cross-scanner noise reduction inside the same unified findings model.
View course →Learn how Safeguard detects, classifies, enforces, and remediates open-source license risk: SPDX license expressions, the permissive/weak/strong/network-copyleft categories, policy-as-code enforcement through Gates, automatic NOTICE/attribution generation, and the License category inside Autonomous Remediation.
View course →A deep dive into Griffin Remediate's five-stage pipeline (analysis, solution, impact assessment, PR creation, validation), its single/bulk/page-level modes, breaking-change detection, ecosystem coverage, and the full eight-category Autonomous Remediation matrix — including the critical off-by-default master toggle.
View course →Understand Safeguard's Tenant -> Organization -> Project -> Version hierarchy, the role model with SSO group mapping, the Product-vs-Project vocabulary split across the four supply-chain actor roles, and why this structure is what makes the platform's one-findings-model consolidation story actually true.
View course →A hands-on first week with ESSCM for developers who are new to Safeguard. Connect a repository, read the SBOM and scores it produces, triage vulnerabilities with reachability, let Griffin open your first fix pull request, and learn how gates, the CLI and the IDE extensions fit into your daily workflow.
View course →For practitioners who already run ESSCM and now have to make it work across an enterprise: multi-organization tenancy and identity, bulk onboarding, regulated deployment and AI-mode choices, policy and gate engineering with graduated rollout, and Autonomous Remediation at scale. Every lesson is grounded in the shipping product, with early-access and roadmap capabilities named as such.
View course →A task-oriented first week with Safeguard Portal for anyone who has been asked to "send us your SBOM". Learn what a publishable SBOM contains, turn a scanned Project into a catalog Product, publish an immutable copy, run compliance checks, and share it through a direct link, a branded customer portal or an NDA-gated tracked link.
View course →Pass a proctored-style timed exam and earn a publicly verifiable credential.
Validates working knowledge of software supply-chain security and the Safeguard platform: the scan engines and findings-triage workflow, SBOM and VEX, compliance and the Trust Center, and the Gold / CLI / MCP ecosystem. Earned by completing the Safeguard Certified Practitioner course and passing a timed exam of 30 questions drawn from a 60-question pool, 45 minutes, 70% to pass (21 of 30), with a 24-hour retake cooldown; multi-select questions are graded exact-match with no partial credit. Valid for 24 months from issue; certificates are anonymously verifiable at learn.safeguard.sh/cert/(id).
Validates working knowledge of Safeguard's secrets scanning (200+ issuer patterns, entropy analysis, live verification, git-history purge, pre-push hooks, custom patterns) and Eagle malware detection (cross-ecosystem classification and inline/registry/CI/admission enforcement).
Awarded for completing the Software Supply Chain Security Fundamentals course and passing its certification exam.
Awarded for completing the Vulnerability Management and Remediation with Safeguard course and passing its certification exam.
Awarded for completing the SBOM Compliance and Secure CI/CD course and passing its certification exam.
Validates working knowledge of Safeguard's ESSCM product: its scan inputs, the Risk Score and SCAL scoring model, reachability-based vulnerability prioritization, Griffin AI remediation, and the Policies/Gates/Guardrails governance model. Earned by completing the ESSCM course and passing a 30-question timed exam drawn from a 65+ question pool, 30 minutes, 70% to pass, 24-hour retake cooldown.
Validates working knowledge of Safeguard's Portal product: the free entry tier vs the Publish/Share product, the Publish vs Share distinction, Product vs Project vocabulary, Portal's sub-modules, compliance verification (EO 14028/FedRAMP/NTIA), and the Trust Center. Earned by completing the Portal course and passing a 30-question timed exam drawn from a 65+ question pool, 30 minutes, 70% to pass, 24-hour retake cooldown.
Validates working knowledge of software attestation: SLSA build levels, Sigstore keyless signing (Fulcio/Rekor), in-toto attestation chains, X.509/package signatures, and Safeguard's SCAL/LCAL scoring used to gate releases on build integrity rather than just known vulnerabilities.
Validates working knowledge of Safeguard's Data Security Posture Management capability: data classification (PII/PHI/PCI/secrets), the redaction mandate, S3/RDS connector scope, and mapping findings to GDPR/HIPAA/PCI DSS/CCPA.
Validates working knowledge of Safeguard's SecOps/SIEM capability: OCSF ingestion sources, Sigma/IOC detection, alert deduplication, and its relationship to AutoTriage within the unified findings model.
Validates working knowledge of Safeguard's license compliance capability: SPDX-based detection, license risk categories, policy-as-code enforcement, NOTICE generation, and the License category in Autonomous Remediation.
Validates working knowledge of Griffin Remediate's pipeline and modes, and the full Autonomous Remediation category/strategy matrix, including its off-by-default master toggle.
Validates working knowledge of Safeguard's org hierarchy (Tenant/Organization/Project/Version), roles and SSO mapping, the Product-vs-Project vocabulary, and the platform's one-findings-model consolidation story.
Validates working knowledge of Safeguard's TPRM product: the Consumer supply-chain role, Vendor Management, the SBOM Request status pipeline, the 0-100 (higher-is-better) vendor Risk Score, and continuous Monitoring/alerting. Earned by completing the TPRM course and passing a 30-question timed exam drawn from a 65+ question pool, 30 minutes, 70% to pass, 24-hour retake cooldown.
Validates working knowledge of OSM's per-package intelligence (LCAL, malicious-package scanning) and Gold's two offerings: the free public directory at gold.safeguard.sh and the paid Gold Registry of hardened artifacts. Earned by completing the course and passing a 30-question timed exam drawn from a 65+ question pool, 30 minutes, 70% to pass, 24-hour retake cooldown.
Validates working knowledge of Safeguard's AI security surface: its own purpose-built models (Griffin/Eagle/Lion), configurable AI modes and privacy posture, AI-BOM/AI-SPM/model scanning, the AI Gateway and MCP Guardrail, and agent-native operation (MCP server, agent identity, autonomous agent, agentic procurement). Earned by completing the course and passing a 30-question timed exam drawn from a 65+ question pool, 30 minutes, 70% to pass, 24-hour retake cooldown.
Validates working knowledge of Safeguard's Compliance and GRC suite: its eleven app tabs, continuous evidence mapping powered by Lino, and standards coverage including EO 14028, NIST SSDF, SLSA, and VEX. Earned by completing the course and passing a 30-question timed exam drawn from a 65+ question pool, 30 minutes, 70% to pass, 24-hour retake cooldown.
Validates working knowledge of Safeguard's application security testing engines: first-party SAST (dataflow tracing, CWE/OWASP mapping), first-party DAST (safe, scoped, verified-target-only dynamic testing), and Red Team defensive adversary emulation/BAS mapped to MITRE ATT&CK under a strict safety kernel (signed rules of engagement, in-scope only, kill-switch, no weaponized payloads).
Validates working knowledge of Safeguard's three-layer governance model: Policies (which decide what's a Finding), Gates (which enforce at build/release checkpoints with block/warn/notify/require-approval actions, including CI gate actions), and Guardrails (runtime/proxy enforcement such as the AI Gateway and MCP Guardrail).
Validates working knowledge of Safeguard's Zero-Day Discovery capability: the limitation of reactive CVE-feed-only vulnerability management, the SGZ-YYYY-XXXXX advisory format with CVSS vectors, coordinated disclosure practice, and how zero-day findings integrate into prioritization and remediation.
Validates working knowledge of Safeguard's Runtime Protection (CWPP/CNAPP concepts, ATT&CK-mapped rule packs, the ~1% CPU eBPF collector, and gated response: alert/block/kill/quarantine/isolate) and Package Firewall (install-time proxy for npm/pip catching typosquatting, dependency confusion, and malware, with allow/warn/block/audit/quarantine modes).
Awarded for completing ESSCM Essentials for Developers and passing its exam, demonstrating the ability to connect, read, triage and remediate a project in ESSCM.
Validates the ability to interpret EO 14028 Section 4 and NIST SSDF practices, map them to evidence produced by Safeguard, and assemble a defensible secure software development attestation package.
Validates that the holder can read and explain SPDX and CycloneDX documents, choose the right format for an audience, and generate, export, and critically review an SBOM using Safeguard.