What is the difference between the core and applied secure coding modules?
The core module builds recognition of common vulnerabilities, intended as a baseline for all developers. Applied asks multi-part questions on comprehensive code examples, intended for senior developers and architects.
Who should take the applied module?
Experienced developers, senior engineers, technical leads and security architects — the people who sign off designs.
Does this satisfy ISO/IEC 27001 or SOC 2 secure development requirements?
Completions are recorded as audit evidence for secure development practice requirements, alongside compliance training such as PCI DSS and HIPAA.
Will developers actually do it?
Yes, but you need to ensure it becomes part of the way your teams work. It lives in Teams or Slack, takes minutes, and skill tests let the strongest engineers test out instead of sitting through content they know. We've done everything we can to lower the barrier and make the training useful for different skill levels.
Does it cover AI and LLM use in development?
Yes — an evolving developer AI path covering LLM basics, development workflows, prompting for code quality, and responsible and safe use, which also evidences the EU AI Act Article 4 literacy duty.
What language is developer content in?
English.
What programming languages are the secure coding exercises in?
Python, C#, Java and JavaScript.