A measurement course for the engineering manager whose commit volume rose sharply and whose application security headcount did not. It separates the throughput question from the quality question, which get collapsed into one dashboard and then answer neither, and builds a small set of measures that survive a year: what a defect escape rate genuinely reports, why a stage of discovery distribution says more than any single rate, and why a security finding count is the most quoted and least reliable number available. It then treats review as the early warning system it is, with load and depth measures and three leading indicators whose mechanisms can be stated in advance: review time falling while change size rises, approval latency collapsing, and one reviewer approving everything. A full module works the arithmetic in the open on an explicitly invented dataset, where one set of numbers produces three incompatible conclusions depending on the denominator, and where a square root test shows that the counts people argue about hardest are usually too small to argue about. It closes on the counterfactual problem, the study designs an organisation can actually run instead of a controlled trial, and how to report honestly to an executive who has already announced a productivity number in public.
Nothing. Every course, exam, and certificate on the catalog is free — including retakes. All you need is a free Safeguard account.
None. The flagship course, Safeguard Certified Practitioner, is a beginner-level course — basic familiarity with how software is built helps, but every exam question is answerable from the lessons themselves.
You can retake it after a 24-hour cooldown, as many times as you need. Retakes are free, and each attempt draws a fresh random set of questions.
The Safeguard Certified Practitioner credential is valid for 24 months from issue. The expiry date is printed on the certificate and shown live on its public verification page. Renewing means passing the current exam again.