Skip to main content
Get Started

Frequently Asked Questions

Answers to common questions about appsec-forge, cases, access, updates, and learning workflow.

Is appsec-forge a course?

No. appsec-forge is not an online course, video course, or structured training program.

appsec-forge consists of a free Public GitHub repository (also mirrored on GitLab) and a Private GitHub "Pro" repository.

After purchasing Pro, you immediately receive access to the Private Pro repository containing the same cases, each expanded with additional security content. You can clone the entire library and study it locally.

There are no chapters, predefined learning paths, or hours of video lessons to complete before getting to real engineering work.

appsec-forge follows an example-driven learning approach. Instead of learning from isolated examples or simplified tutorials, you work directly with engineering cases based on real mistakes made by developers, DevOps engineers, and AppSec engineers in production environments.

Every case is self-contained and can be studied independently. Start with the technologies you use today and explore the rest of the library as your career grows.

Is appsec-forge interactive?

No. appsec-forge is not an interactive lab, browser-based training platform, or hands-on cybersecurity playground.

appsec-forge is a GitHub-based case library — not an interactive or hands-on learning platform.

Every case recreates a realistic production scenario, from vulnerable code through remediation, detection, verification, and hardening, so you understand the complete engineering workflow. Everything is studied directly on GitHub, with no environment setup required.

The goal is to build the understanding and intuition you can apply to your own projects, not to memorize or copy-paste solutions.

Can I preview a case?

Yes. You can review both the Public and Pro versions of the same case before purchasing.

One complete case is available for free so you can evaluate the structure, depth, teaching approach, and engineering quality before purchasing.

Public version:
https://github.com/vik/appsec-forge/super-case-public

Pro version:
https://github.com/vik/appsec-forge/super-case-pro

The free case is representative of the overall structure and learning approach used throughout the library.

Purchase decisions should be based on the repository as it exists today. Every future case released within your purchased major version is included automatically, but future content and release order are not published as a public roadmap.

How do I access Pro?

Access is delivered immediately after purchase.

The Public repository is available for free on GitHub (and mirrored on GitLab).

After purchasing Pro, you immediately receive access to the Private Pro repository, which contains expanded versions of the same cases, additional production-oriented content, and all updates released within your purchased major version.

Can I use the included artifacts as-is?

No. The included scripts, configurations, policies, and remediation examples demonstrate production-oriented engineering approaches for the presented scenarios.

They are designed for learning, not direct deployment. Review, adapt, and validate everything before using it in a production environment.

Do I need prior experience?

appsec-forge assumes you already understand the fundamentals of the technology used in the case you're studying.

* **Developers:** basic knowledge of the language and framework.
* **DevOps / DevSecOps:** basic familiarity with the relevant infrastructure or tooling.
* **AppSec:** basic understanding of how modern applications are built.

The security concepts are taught through the cases themselves.

Basic Bash knowledge is recommended for understanding the verification and detection scripts.

Why isn't appsec-forge suitable for beginners?

appsec-forge is designed for strong junior, mid-level, and senior engineers.

If you're still learning programming fundamentals, appsec-forge will likely feel overwhelming.

The library assumes you're already comfortable writing code, working with frameworks or infrastructure, and navigating a development environment.

It focuses on secure engineering practices rather than teaching programming from scratch.

Why should developers learn infrastructure?

You don't need to learn everything at once.

Every case is categorized, allowing you to focus on the technologies most relevant to your current role.

However, engineering careers rarely stay the same. Today's backend developer may become tomorrow's Senior Engineer, Tech Lead, AppSec, DevOps, or DevSecOps engineer. Teams adopt new languages, migrate to Kubernetes, redesign CI/CD pipelines, introduce AI, and move workloads to the cloud.

Instead of buying a new course every time your responsibilities change, you'll already have a growing library of production-inspired engineering cases waiting for you.

You're not only investing in appsec-forge for the engineer you are today — you're building a knowledge base for the engineer you'll become over the next several years.

Do I need the Pro version?

The Public repository demonstrates the vulnerability, exploitation process, and a basic remediation.

The Private Pro repository is designed for engineers who want to learn how experienced teams solve the same problem in production through layered defenses, hardening, threat modeling, detection engineering, verification, and operational best practices.

If your goal is professional growth rather than simply recognizing vulnerabilities, Pro is the recommended edition.

Do I get lifetime access?

Yes. You receive lifetime access to the major version you purchased.

Every update and every new case released within that major version is included automatically.

Future major versions are sold separately.

How do versions work?

The library continuously grows with new production-inspired cases.

Every major version grows continuously until the next major release.

The exact mix of technologies, programming languages, frameworks, cloud platforms, and security topics varies between major versions. The presence of a particular technology does not guarantee that additional cases for it will be added.

How do Pro upgrades work?

Every new case permanently increases the value of the library, so the price gradually increases over time.

Each major version includes all future cases released within that version.

Each major version is expected to grow to around 100 cases before the next major version begins.

If you own a previous major version, you receive upgrade credit equal to the final purchase price of that version.

Example:

- You purchased v1 for $29.
- v1 eventually grows to around 100 cases, and its final purchase price becomes $100.
- v2 launches at $101.

Your upgrade credit is $100, so upgrading to v2 costs only $1.

Upgrade credit never expires and can be applied toward any future major version.

For example, if you own v1 and upgrade directly to v3, the final purchase price of v1 is still applied as upgrade credit toward the current price of v3.

Previous major versions are never sold again but remain permanently available to everyone who purchased them.

Buying earlier means paying less for the same version while locking in the maximum upgrade credit available for that version.

Will I receive future updates automatically?

Yes. Every new case and every update released within your purchased major version is added automatically at no additional cost.

Why does the price increase?

The price reflects the amount of engineering content available at the time of purchase.

The library continuously expands with new cases, technologies, and engineering content.

As the library grows, so does its practical value. Early supporters always receive the lowest entry price.

Can I use appsec-forge for team training?

Yes. The repository can also be used during code reviews, brown-bag sessions, and internal security education.

The cases are well suited for onboarding, secure coding workshops, internal security training, and engineering knowledge sharing across Development, AppSec, DevOps, and DevSecOps teams.

How are new cases selected?

New cases are selected based on the educational goals of the library, current engineering trends, production incidents, and upcoming YouTube content.

The technologies already included in the repository do not guarantee that additional cases for the same language, framework, or tool will be added in the future.

Purchase decisions should be based on the repository as it exists today. Every future case released within your purchased major version is included automatically at no additional cost.