The annual secure development refresher, written to be finished rather than clicked through. It is deliberately narrow: seven habits that prevent the defect classes that actually ship, each attached to the failure it prevents and to one check you can run on Monday. Parameterised queries and untrusted input, authorisation checked on the server for every object, secrets kept out of source and the order of operations when one is committed, dependencies chosen and updated deliberately, error handling that does not leak internals, logs that capture enough without capturing credentials or personal data, and reviewing generated code as carefully as a colleague's. It is a refresher, not a substitute for the deep application security courses, and it points at them.
Nothing. Every course, exam, and certificate on the catalog is free — including retakes. All you need is a free Safeguard account.
None. The flagship course, Safeguard Certified Practitioner, is a beginner-level course — basic familiarity with how software is built helps, but every exam question is answerable from the lessons themselves.
You can retake it after a 24-hour cooldown, as many times as you need. Retakes are free, and each attempt draws a fresh random set of questions.
The Safeguard Certified Practitioner credential is valid for 24 months from issue. The expiry date is printed on the certificate and shown live on its public verification page. Renewing means passing the current exam again.