An application security course on provenance as an engineering question rather than a philosophical one. It starts from the four requests that actually arrive, from counsel, from engineering, from an incident and from a regulator, and shows that each needs a different record. It then works through the signals that genuinely exist, editor and assistant telemetry, commit metadata, review records, session transcripts, gateway logs and build records, and how each one degrades under rebases, reorganisations, tool changes and human adaptation. The central limit is faced directly: a developer who accepts a suggestion and then edits it has produced something with no clean authorship boundary, so any policy that demands a label manufactures false records. The course closes on what to capture at the moment of authorship, how to record confidence rather than labels, retention and the surveillance question, incident forensics with partial evidence, and a policy whose most valuable section is the list of things it refuses to require.
Nothing. Every course, exam, and certificate on the catalog is free — including retakes. All you need is a free Safeguard account.
None. The flagship course, Safeguard Certified Practitioner, is a beginner-level course — basic familiarity with how software is built helps, but every exam question is answerable from the lessons themselves.
You can retake it after a 24-hour cooldown, as many times as you need. Retakes are free, and each attempt draws a fresh random set of questions.
The Safeguard Certified Practitioner credential is valid for 24 months from issue. The expiry date is printed on the certificate and shown live on its public verification page. Renewing means passing the current exam again.