The Multiverse School
Secure · 14 classes scheduled
Find your class

🛡 Secure · 34 capabilities you can learn between now and January

Nothing you own fails on its own.

Secure is the verb for keeping yourself, your people and your work out of harm. It is the practice of making one bad afternoon stay one bad afternoon: recovery that survives losing the device, a call you break off and ring back, a network you can name every machine on. 14 classes teach it between now and January.

On the calendar 14 sessions
Context Engineering
Sep 16
Production Agent Engineering
Sep 17
Practical Propaganda
Sep 19
AI Alignment
Sep 25
Home Network Defense
Sep 30
Solarpunk Automation
Oct 10
Critical Thinking and Creativity with AI
Oct 12
Automate Your Email: No Code AI Automation
Oct 16
Consumer Device Rescue and Defense
Oct 28
AI Security: Governance, Standards and Safety Cases
Oct 30
Agentic SDLC
Nov 9
Field Opsec
Nov 16
Scam and Fraud Home Defense
Nov 18
Digital Identity Defense
Jan 6

Every one of these can be taken on its own, pay what you can, and none of them needs another. Take the one that matches the thing you are worried about.

What you need to begin

The devices you already own.

A phone, a laptop or the router that is already in your house, and an evening you can sit with it. No terminal, no command line, nothing to buy and nothing to install before you arrive. You bring your own inbox and your own accounts because those are the ones you are going to change.

The dependency chain

The phone is gone. Walk what goes with it.

Security advice is a list until it is a chain. Five questions about your own setup, thirty seconds, and the chain gets drawn as yours: which links hold, which snap, and what is left standing at the far end. Each break names the class that closes it.

  1. 01 · given The phone Left in a taxi, taken off a table, does not matter which. Lost
  2. 02 Your second factor The codes, the prompt, the thing that proves it is you. ?
  3. 03 Your email Not a mailbox. A key ring. ?
  4. 04 Everything it recovers Bank, domain, cloud, the group chat your family trusts. ?
  5. 05 · far end The account your customers pay through The one you would have to ring people about. ?
Chain walk 5 questions

Answer these about your own setup. With scripting off you get the whole list at once, with every remedy under it — the same information, in a less theatrical order.

  1. Question 1 · the second factor

    Was the only copy of your second factor on the phone that just went? Authenticator app with no export, push prompts to that handset, codes you never printed.

    Digital Identity Defense $750 · Jan 6

    configure recovery that survives losing the device

    What you have to showRecovery codes printed and stored off any device, a password manager on every device, SMS removed as a recovery method, and a written account of what happens if the phone is gone.

  2. Question 2 · the number

    Can a text message to that number still reset the password on your main email? Check rather than guess. Most people who say no have an old fallback switched on.

    Digital Identity Defense $750 · Jan 6

    configure recovery that survives losing the device

    What you have to showRecovery codes printed and stored off any device, a password manager on every device, SMS removed as a recovery method, and a written account of what happens if the phone is gone.

  3. Question 3 · the phone call

    Somebody rings claiming to be your carrier, confirming the replacement SIM. Does your household have a way to check that does not involve trusting the caller? A number you ring back on. A code phrase. Anything that is not the caller's own word.

    Scam and Fraud Home Defense $750 · Nov 18

    operate a callback rule against incoming contact

    What you have to showA household agreement in writing including a code phrase, and one real incoming contact you broke off and called back.

  4. Question 4 · the blast radius

    Could you name every device on your home network right now, without looking? The phone knew your wifi. So does the handset you handed down, and the tablet in the kitchen.

    Home Network Defense $750 · Sep 30

    locate every device on your own network

    What you have to showA device inventory taken from the router, with each entry identified or explicitly listed as unidentified.

    Consumer Device Rescue and Defense $750 · Oct 28

    follow a device hardening checklist

    What you have to showThe router or device admin pages before and after — default password changed, remote administration off, automatic updates on — with one line per item on what it closes.

  5. Question 5 · the one that settles it

    Have you ever tried to take over your own accounts from the outside — the recovery flow, the help desk, the lot? Every answer above is a claim about a system you have not tested. This is the question that turns them into evidence.

    Digital Identity Defense $750 · Jan 6

    falsify your own account recovery by attempting it

    What you have to showA written attempt log against your own accounts, the furthest step reached, and the control you added because of it.

    Trace log · every answer prints here, including the questions your earlier answers make pointless. Nothing is sent anywhere; the walk runs in this tab and is forgotten when you close it.

    Free and public

    Five guides, for five specific bad nights.

    Each one was written for somebody typing a single question into a search bar at 2am. Free, no account, no email address. Read the one that is yours.

    On the calendar

    Four home defense classes, in an order that is argued.

    Your network, then the devices on it, then the people who ring them, then the accounts those people are after. Take all four or take the one you need. You leave each evening with a thing that exists: a device inventory, a hardened router, a household code phrase, a printed recovery kit.

    Home Network Defense

    $750
    • follow a device hardening checklist
    • locate every device on your own network
    • produce a threat model for your own situation
    • design a household security posture for people who did not choose it
    • reconcile security with what people will actually do

    Sep 30 · two hours, live

    Consumer Device Rescue and Defense

    $750
    • follow a device hardening checklist
    • locate a substitute part when the named one is unavailable
    • repurpose a retired device into a working server
    • migrate your work off a subscription without losing it
    • design a household security posture for people who did not choose it

    Oct 28 · two hours, live

    Scam and Fraud Home Defense

    $750
    • operate a callback rule against incoming contact
    • produce a threat model for your own situation
    • transform an incoming message into ask deadline and claimed sender
    • classify an incoming contact as genuine or pretext
    • design a household security posture for people who did not choose it
    • reconcile security with what people will actually do

    Nov 18 · two hours, live

    Digital Identity Defense

    $750
    • configure recovery that survives losing the device
    • operate a callback rule against incoming contact
    • classify an incoming contact as genuine or pretext
    • falsify your own account recovery by attempting it
    • verify what can be found about you is actually gone
    • design a household security posture for people who did not choose it
    • reconcile security with what people will actually do

    Jan 6 · two hours, live

    Also on the calendar

    Secure work inside classes that are about something else.

    An AI class that teaches you where untrusted input enters a system, and an off-grid automation class that teaches you to run a mesh network with the internet down. They are about their own subjects, and they are on the calendar too.

    Context Engineering

    $400
    • produce a refusal boundary that fires on cases you did not list

    Sep 16 · live · 35.7 h recorded · 329 exercises

    Production Agent Engineering

    $200
    • justify a safety case for a system that acts without you

    Sep 17 · live · 22.3 h recorded

    Practical Propaganda

    $100
    • verify separate identities do not leak into each other

    Sep 19 · live · 21 exercises

    AI Alignment

    $300
    • characterise how an ai assisted attack unfolded
    • justify a safety case for a system that acts without you
    • select among operating boundaries for inputs a system was not built for

    Sep 25 · live · 1 exercises

    Solarpunk Automation

    $100
    • operate a mesh network that carries messages without infrastructure
    • classify your channels by what removes them
    • verify a community system survives a cut you did not choose
    • design a community information system that survives losing the internet

    Oct 10 · live · 3.9 h recorded · 13 exercises

    Critical Thinking and Creativity with AI

    $100
    • configure an assistants memory and outside connections

    Oct 12 · live · 22.4 h recorded · 21 exercises

    Automate Your Email: No Code AI Automation

    $200
    • transform an incoming message into ask deadline and claimed sender

    Oct 16 · live · 10.8 h recorded · 34 exercises

    AI Security: Governance, Standards and Safety Cases

    $350
    • locate the standard that governs a system you are building
    • classify the personal data a system holds and when it is deleted
    • classify which framework applies where you are in the lifecycle
    • justify a safety case for a system that acts without you

    Oct 30 · live

    Agentic SDLC

    $350
    • produce a list of where untrusted input enters a system
    • characterise an applications injection surface

    Nov 9 · live · 26.5 h recorded · 46 exercises

    Field Opsec

    $350
    • follow a device hardening checklist
    • execute a security playbook in a drill
    • locate the standard that governs a system you are building
    • configure recovery that survives losing the device
    • operate a callback rule against incoming contact
    • produce a threat model for your own situation
    • characterise what a publication reveals about its source
    • characterise what breaks when you cut the connection
    • classify a situation into the playbook it calls for
    • verify separate identities do not leak into each other
    • verify what can be found about you is actually gone
    • design a device posture for a border crossing
    • design a scheme for acting together when the channel is gone
    • govern a source relationship from first contact to its end
    • govern your own decisions under coercion by a rule set in advance
    • reconcile security with what people will actually do

    Nov 16 · live · 20 exercises

    Find your class Take the whole Defender route →

    What is in the box

    A live room, a thing you build, and the material to keep.

    Live teaching
    14

    sessions on the calendar between September and January, pay what you can. You bring your own router, your own inbox and your own accounts, and you change them in the room while somebody is there to ask.

    Proof, not attendance
    34

    capabilities you can learn from these classes, and every one of them names the artifact you have to produce before it counts — a printed set of recovery codes, a device inventory, an attempt log against your own accounts. They are printed on this page, below, before you pay for anything.

    Material you keep
    485

    exercises across these 14 classes, plus 121.6 hours of recording and the reference material each class ships with — the Six Roses handbook for the household classes, a working companion for the AI ones. Yours after, not just during.

    The work itself

    What you can walk out able to do, and what proves it.

    Written as verbs, easiest first, each one dated and each one with the artifact that settles it printed underneath. Read them before you decide whether an evening is worth its own price.

    1. Sep 30next taught

      follow a device hardening checklist

      Consumer Device Rescue and Defense Oct 28 · Field Opsec Nov 16 · Home Network Defense Sep 30

      The router or device admin pages before and after — default password changed, remote administration off, automatic updates on — with one line per item on what it closes.

    2. Nov 16next taught

      execute a security playbook in a drill

      Field Opsec

      A completed drill — a cold-phone bring-up, a dead-drop site selection, a doxx scrub of yourself — with the steps that did not survive contact and what you did instead.

    3. Sep 30next taught

      locate every device on your own network

      Home Network Defense

      A device inventory taken from the router, with each entry identified or explicitly listed as unidentified.

    4. Oct 30next taught

      locate the standard that governs a system you are building

      AI Security: Governance, Standards and Safety Cases Oct 30 · Field Opsec Nov 16

      One system, the governing instrument named, and the specific requirement it places on you.

    5. Oct 12next taught

      configure an assistants memory and outside connections

      Critical Thinking and Creativity with AI

      Memory on with one fact it retained across a fresh conversation, one connector enabled with the scopes it was granted written out, and one source you deliberately did not connect with the reason.

    6. Nov 16next taught

      configure recovery that survives losing the device

      Digital Identity Defense Jan 6 · Field Opsec Nov 16

      Recovery codes printed and stored off any device, a password manager on every device, SMS removed as a recovery method, and a written account of what happens if the phone is gone.

    7. Nov 16next taught

      operate a callback rule against incoming contact

      Digital Identity Defense Jan 6 · Field Opsec Nov 16 · Scam and Fraud Home Defense Nov 18

      A household agreement in writing including a code phrase, and one real incoming contact you broke off and called back.

    8. Oct 10next taught

      operate a mesh network that carries messages without infrastructure

      Solarpunk Automation

      A message delivered node to node with the internet off, reporting the distance covered and the number of hops it took.

    9. Nov 9next taught

      produce a list of where untrusted input enters a system

      Agentic SDLC

      An enumerated list against a real codebase or system, including one entry point that is not an obvious form field.

    10. Sep 16next taught

      produce a refusal boundary that fires on cases you did not list

      Context Engineering

      Three declines on cases absent from the boundary text, three accepts on near neighbours you did want, and the near miss that made you rewrite it.

    11. Sep 30next taught

      produce a threat model for your own situation

      Field Opsec Nov 16 · Home Network Defense Sep 30 · Scam and Fraud Home Defense Nov 18

      Your own tier model, naming the adversary and capability at each tier, with the specific practice each tier changes.

    12. Oct 16next taught

      transform an incoming message into ask deadline and claimed sender

      Automate Your Email: No Code AI Automation Oct 16 · Scam and Fraud Home Defense Nov 18

      Three real messages from your own inbox split into the three parts, with the ask restated in your own words and the deadline named as invented or genuine.

    13. Nov 9next taught

      characterise an applications injection surface

      Agentic SDLC

      A written surface map for a real application naming the query, template or shell interpreter behind each entry point.

    14. Sep 25next taught

      characterise how an ai assisted attack unfolded

      AI Alignment

      One documented incident traced end to end, with the model's contribution distinguished from what conventional tooling could already do.

    15. Nov 16next taught

      characterise what a publication reveals about its source

      Field Opsec

      A draft publication with the identifying details enumerated — including the ones only an insider would notice — and the redactions made, reviewed by someone who did not write it.

    16. Nov 16next taught

      characterise what breaks when you cut the connection

      Field Opsec

      A planned outage exercise with what was predicted beforehand, what actually failed, and the gap between the two.

    17. Nov 16next taught

      classify a situation into the playbook it calls for

      Field Opsec

      Three situations routed to playbooks with the deciding tier named for each, including one where the alarming option was the wrong one.

    18. Nov 18next taught

      classify an incoming contact as genuine or pretext

      Digital Identity Defense Jan 6 · Scam and Fraud Home Defense Nov 18

      Five real examples classified with the tell named for each, including one genuine message that looked like a pretext.

    19. Oct 30next taught

      classify the personal data a system holds and when it is deleted

      AI Security: Governance, Standards and Safety Cases

      The inventory with a governing law and a deletion rule per row, and one deletion actually executed against the running system.

    20. Oct 30next taught

      classify which framework applies where you are in the lifecycle

      AI Security: Governance, Standards and Safety Cases

      Three systems at different lifecycle stages, each routed to the framework that governs it, with the stage that decided it named.

    21. Oct 10next taught

      classify your channels by what removes them

      Solarpunk Automation

      Your group's channel list with the actor who can remove each — carrier, platform, state, power company — and the fallback tested at least once.

    22. Jan 6next taught

      falsify your own account recovery by attempting it

      Digital Identity Defense

      A written attempt log against your own accounts, the furthest step reached, and the control you added because of it.

    23. Sep 17next taught

      justify a safety case for a system that acts without you

      Production Agent Engineering Sep 17 · AI Alignment Sep 25 · AI Security: Governance, Standards and Safety Cases Oct 30

      A written safety case for one autonomous system, with its falsifying condition stated and the evidence that would settle it.

    24. Oct 10next taught

      verify a community system survives a cut you did not choose

      Solarpunk Automation

      An unannounced cut chosen by someone else — uplink pulled, battery disconnected, a node removed — with what the community could still do counted in messages delivered and decisions made rather than in uptime, and the thing you had believed was resilient that was not.

    25. Sep 19next taught

      verify separate identities do not leak into each other

      Field Opsec Nov 16 · Practical Propaganda Sep 19

      The compartments with what may cross between them, and a self-audit that found at least one crossing you had not intended.

    26. Nov 16next taught

      verify what can be found about you is actually gone

      Digital Identity Defense Jan 6 · Field Opsec Nov 16

      The before-and-after search record, the brokers contacted, and the items that did not come down with what you did instead.

    27. Oct 10next taught

      design a community information system that survives losing the internet

      Solarpunk Automation

      A system serving a real group through at least one unplanned failure, the absorbed failure named per component with the cost of each choice stated, the features it shed rather than the minutes it was down, and the written rule for reconciling work done while disconnected.

    28. Nov 16next taught

      design a device posture for a border crossing

      Field Opsec

      The pre-trip minimisation record, what the device carried at the border, and the post-trip restoration with what you chose not to restore.

    29. Sep 30next taught

      design a household security posture for people who did not choose it

      Consumer Device Rescue and Defense Oct 28 · Digital Identity Defense Jan 6 · Home Network Defense Sep 30 · Scam and Fraud Home Defense Nov 18

      A posture in place across at least three people who did not set it up, and one protection that held when someone did the wrong thing anyway.

    30. Nov 16next taught

      design a scheme for acting together when the channel is gone

      Field Opsec

      The pre-agreed scheme, a run where communication was cut, and whether both parties ended up where the scheme said they would.

    31. Nov 16next taught

      govern a source relationship from first contact to its end

      Field Opsec

      The lifecycle as run in a drill, including the off-boarding step, and the record of what the source was told they were accepting.

    32. Nov 16next taught

      govern your own decisions under coercion by a rule set in advance

      Field Opsec

      The rule written in advance, a drill in which it was tested under pressure, and what you changed about the rule afterwards.

    33. Sep 30next taught

      reconcile security with what people will actually do

      Digital Identity Defense Jan 6 · Field Opsec Nov 16 · Home Network Defense Sep 30 · Scam and Fraud Home Defense Nov 18

      A requirement people were bypassing, the revised version they follow, and evidence the revision still closes the original threat.

    34. Sep 25next taught

      select among operating boundaries for inputs a system was not built for

      AI Alignment

      Scores across a deliberate shift in the inputs, the point at which they fall, and the operating boundary you wrote from it.

    One evening, in detail

    You have to read a pretext before you can write one.

    Ring your own provider. Run your own recovery flow. Answer the security questions as a stranger would and find out how far that stranger gets before somebody stops them. Almost nobody has done this to themselves, and everybody has an opinion about how it would go.

    Doing it means pretexting yourself — inventing a plausible story, in a plausible voice, and watching which part of it the help desk believes. So you learn to read one first: five real messages, the tell named in each, including the genuine one that looked like a trap. Both halves happen in the same room on the same evening, and you leave with the log of what you got away with.

    Digital Identity Defense

    $750
    • classify an incoming contact as genuine or pretext
    • falsify your own account recovery by attempting it

    What you have to showA written attempt log against your own accounts, the furthest step reached, and the control you added because of it.

    Jan 6 · two hours, live · pay what you can

    Where else it turns up

    Most people who need this did not come here for security.

    They came to build something, run something or hold a group together, and the security work arrived attached to it. These are the routes where that happens.

    A solo founder is the company's single point of failure. “configure recovery that survives losing the device” is filed under security, but for one person carrying a business it is business continuity: the difference between a bad afternoon and telling your customers why nobody can bill them.

    People who build things that provoke draw attention they did not plan for. A project that gets noticed brings an audience you did not choose. That is a threat model arriving after the fact, which is the worst time to write one.

    Before you pick a class

    What Secure asks of you, and where to go if it is not the ask.

    Or take all of them

    What a month buys, if one evening is not the shape of it.

    One class needs nothing else. Two monthly subscriptions cover the whole school instead, and they are different products.

    Start anywhere

    Read one guide tonight. Book one class this month.

    The guides cost nothing and need no account. A class can be taken on its own, pay what you can, and needs no other class. If you want every Secure class rather than one evening of them, the Defender path is the door for that.

    Secure Each class has its own price
    Find your class