BUILT FOR PEOPLE WHO READ THE THREAT MODEL
We cannot read your records.
ON YOUR DEVICEEncrypted before it leaves the browser
Your vault is encrypted in the browser with a key derived from your password. The server receives ciphertext and a wrapped key it has no way to open. Losing your password means losing the vault, and that is the point. Book lookups go straight from your browser to the catalogue. The only thing our server ever reads in the clear is a white paper link you explicitly paste.
NO ACCOUNT TOKENSWe never hold your logins
History is read by a browser companion using the sessions you are already signed into. No passwords, no OAuth tokens, and nothing to steal from us if we are breached.
DELETED ON SCHEDULERecords expire after they are accepted
One year after a certification body accepts a submission, the entry and its evidence are deleted automatically. You can shorten that or turn it off.
Read the full explanation, including what it deliberately does not do
ELIGIBILITY IS NOT A GUESS
Two certifications, two decisions.
ISC2120 credits over three years, 90 from your domains
Domain-related webinars, podcasts, articles, and books support Group A credit. General professional skills count as Group B, capped at 30. The ledger tracks both and warns you when Group B credits are going to waste.
ISACAThe rules change on 1 January 2027
ISACA moves to the same 90 domain-aligned and 30 professional-skills split, and stops awarding credit for vendor demonstrations. Activities are scored against whichever policy applied on the day you completed them.