A course for the engineering or company leader who carries security work in an organisation with one security engineer across a hundred or more developers, or none at all. It treats sequencing rather than coverage as the real question, because the reader has a few hours a week and every article on the subject gives them twenty things to do. Module one sets out the filter of four tests, namely whether the work is repeated, error prone, blocking somebody else or required to be provable to an outside party, names the two tests people apply instead, and scores a candidate list on a clearly labelled hypothetical company of 60 developers where the column usually left out is annual upkeep. Module two works the first three items in order: credential detection on every change with the four operational decisions that keep it alive, a continuous dependency inventory with the alerting mistake that turns it into a work generator, and evidence that accumulates as a side effect of the work rather than being gathered when somebody asks. Module three argues that removing the need for a task usually beats automating it, gives five ways a task disappears, then names the three categories that should stay manual, namely a judgement call where two informed people could disagree, an infrequent task that will be broken when needed, and anything whose failure is silent, and closes on the maintenance tax with a running total against a stated capacity ceiling. Module four covers the automation that becomes a single point of failure nobody understands, the day of work that removes most of that risk without a rewrite, resolving the ambiguity of silence, and retirement as the cheapest source of recovered capacity. Module five gives a seven step order of roughly thirty hours with a gate before each step, a four question check after every step, and an explicit stopping rule for when the marginal value has dropped. It cross references the published one person security team course rather than repeating it. Every figure is arithmetic on a clearly labelled hypothetical dataset.
Nothing. Every course, exam, and certificate on the catalog is free — including retakes. All you need is a free Safeguard account.
None. The flagship course, Safeguard Certified Practitioner, is a beginner-level course — basic familiarity with how software is built helps, but every exam question is answerable from the lessons themselves.
You can retake it after a 24-hour cooldown, as many times as you need. Retakes are free, and each attempt draws a fresh random set of questions.
The Safeguard Certified Practitioner credential is valid for 24 months from issue. The expiry date is printed on the certificate and shown live on its public verification page. Renewing means passing the current exam again.