Most product teams publish their first security advisory under pressure, with a reporter waiting and no policy written. This course moves that work to a calmer moment. It covers when you owe the world an advisory rather than a quiet fix, with the honest argument on both sides and a decision test for when the room is split, the four sources of obligation that can override your own judgement, identifier assignment and the permanent commitments that attach to a public record, the five things a defender actually needs, version ranges and the unsupported release line, severity assigned with published reasoning and the structural disagreement that follows, coordination with a reporter and with downstream redistributors, the embargo that leaks and the plan that makes it survivable, detection guidance written without turning the document into a reproduction guide, machine readable records so consumers can automate, and the questions, adoption work and revisions that publication creates. Defensive throughout: what to publish, never how to attack anything.
Nothing. Every course, exam, and certificate on the catalog is free — including retakes. All you need is a free Safeguard account.
None. The flagship course, Safeguard Certified Practitioner, is a beginner-level course — basic familiarity with how software is built helps, but every exam question is answerable from the lessons themselves.
You can retake it after a 24-hour cooldown, as many times as you need. Retakes are free, and each attempt draws a fresh random set of questions.
The Safeguard Certified Practitioner credential is valid for 24 months from issue. The expiry date is printed on the certificate and shown live on its public verification page. Renewing means passing the current exam again.