A foundational course for developers and application security practitioners that steps back from any single vulnerability class to teach input validation as its own discipline. It shows how allowlisting, canonicalization before validation, trust boundary placement, and baseline type, length, range and format checks form the shared principle underneath SQL injection, cross-site scripting, path traversal, command injection and insecure deserialization defenses, each already covered in its own depth elsewhere in this catalogue. The course works through allowlisting versus denylisting, why canonicalization must happen before validation rather than after, context-specific validation for the same data used in different destinations, the honest limits of client-side validation, and a worked review of a single hypothetical field that ties every principle together. It closes with practical guidance on using validation libraries correctly and a design checklist a team can apply during review.
Nothing. Every course, exam, and certificate on the catalog is free — including retakes. All you need is a free Safeguard account.
None. The flagship course, Safeguard Certified Practitioner, is a beginner-level course — basic familiarity with how software is built helps, but every exam question is answerable from the lessons themselves.
You can retake it after a 24-hour cooldown, as many times as you need. Retakes are free, and each attempt draws a fresh random set of questions.
The Safeguard Certified Practitioner credential is valid for 24 months from issue. The expiry date is printed on the certificate and shown live on its public verification page. Renewing means passing the current exam again.