Signing and provenance for the platform engineer who has to operate them, starting from what a signature proves and what it does not. Trust roots for key based and keyless approaches and the key management burden each carries; build provenance attestations and what a consumer can actually check; why verifying at build time proves little and why admission control is the point that enforces; verification policies with exception and break glass paths that survive an incident; what to do when verification fails in production at two in the morning; and the honest limit, that a signature proves origin and integrity rather than that the contents are safe.
Nothing. Every course, exam, and certificate on the catalog is free — including retakes. All you need is a free Safeguard account.
None. The flagship course, Safeguard Certified Practitioner, is a beginner-level course — basic familiarity with how software is built helps, but every exam question is answerable from the lessons themselves.
You can retake it after a 24-hour cooldown, as many times as you need. Retakes are free, and each attempt draws a fresh random set of questions.
The Safeguard Certified Practitioner credential is valid for 24 months from issue. The expiry date is printed on the certificate and shown live on its public verification page. Renewing means passing the current exam again.