The Multiverse School
Secure · 7 classes scheduled
Find your class

🛡 Secure · 10 capabilities you can learn between now and November

Nothing you own fails on its own.

Secure is the verb for keeping yourself, your people and your work out of harm. It is the practice of making one bad afternoon stay one bad afternoon: recovery that survives losing the device, a call you break off and ring back, a network you can name every machine on. 7 classes teach it between now and November.

On the calendar 7 sessions
Solarpunk Automation
Aug 22
Digital Identity Defense
Aug 26
Agentic SDLC
Sep 7
Critical Thinking and Creativity with AI
Sep 11
Home Network Defense
Sep 30
Consumer Device Rescue and Defense
Oct 28
Scam and Fraud Home Defense
Nov 25

Every one of these can be taken on its own, pay what you can, and none of them needs another. Take the one that matches the thing you are worried about.

What you need to begin

The devices you already own.

A phone, a laptop or the router that is already in your house, and an evening you can sit with it. No terminal, no command line, nothing to buy and nothing to install before you arrive. You bring your own inbox and your own accounts because those are the ones you are going to change.

The dependency chain

The phone is gone. Walk what goes with it.

Security advice is a list until it is a chain. Five questions about your own setup, thirty seconds, and the chain gets drawn as yours: which links hold, which snap, and what is left standing at the far end. Each break names the class that closes it.

  1. 01 · given The phone Left in a taxi, taken off a table, does not matter which. Lost
  2. 02 Your second factor The codes, the prompt, the thing that proves it is you. ?
  3. 03 Your email Not a mailbox. A key ring. ?
  4. 04 Everything it recovers Bank, domain, cloud, the group chat your family trusts. ?
  5. 05 · far end The account your customers pay through The one you would have to ring people about. ?
Chain walk 5 questions

Answer these about your own setup. With scripting off you get the whole list at once, with every remedy under it — the same information, in a less theatrical order.

  1. Question 1 · the second factor

    Was the only copy of your second factor on the phone that just went? Authenticator app with no export, push prompts to that handset, codes you never printed.

    Digital Identity Defense $100 · Aug 26

    configure recovery that survives losing the device

    What you have to showRecovery codes printed and stored off any device, a password manager on every device, SMS removed as a recovery method, and a written account of what happens if the phone is gone.

  2. Question 2 · the number

    Can a text message to that number still reset the password on your main email? Check rather than guess. Most people who say no have an old fallback switched on.

    Digital Identity Defense $100 · Aug 26

    configure recovery that survives losing the device

    What you have to showRecovery codes printed and stored off any device, a password manager on every device, SMS removed as a recovery method, and a written account of what happens if the phone is gone.

  3. Question 3 · the phone call

    Somebody rings claiming to be your carrier, confirming the replacement SIM. Does your household have a way to check that does not involve trusting the caller? A number you ring back on. A code phrase. Anything that is not the caller's own word.

    Scam and Fraud Home Defense $100 · Nov 25

    operate a callback rule against incoming contact

    What you have to showA household agreement in writing including a code phrase, and one real incoming contact you broke off and called back.

  4. Question 4 · the blast radius

    Could you name every device on your home network right now, without looking? The phone knew your wifi. So does the handset you handed down, and the tablet in the kitchen.

    Home Network Defense $100 · Sep 30

    locate every device on your own network

    What you have to showA device inventory taken from the router, with each entry identified or explicitly listed as unidentified.

    Consumer Device Rescue and Defense $100 · Oct 28

    follow a device hardening checklist

    What you have to showThe router or device admin pages before and after — default password changed, remote administration off, automatic updates on — with one line per item on what it closes.

  5. Question 5 · the one that settles it

    Have you ever tried to take over your own accounts from the outside — the recovery flow, the help desk, the lot? Every answer above is a claim about a system you have not tested. This is the question that turns them into evidence.

    Digital Identity Defense $100 · Aug 26

    falsify your own account recovery by attempting it

    What you have to showA written attempt log against your own accounts, the furthest step reached, and the control you added because of it.

    Trace log · every answer prints here, including the questions your earlier answers make pointless. Nothing is sent anywhere; the walk runs in this tab and is forgotten when you close it.

    Free and public

    Five guides, for five specific bad nights.

    Each one was written for somebody typing a single question into a search bar at 2am. Free, no account, no email address. Read the one that is yours.

    On the calendar

    Four home defense classes, in an order that is argued.

    Your network, then the devices on it, then the people who ring them, then the accounts those people are after. Take all four or take the one you need. You leave each evening with a thing that exists: a device inventory, a hardened router, a household code phrase, a printed recovery kit.

    Home Network Defense

    $100
    • locate every device on your own network

    Sep 30 · two hours, live

    Consumer Device Rescue and Defense

    $100
    • follow a device hardening checklist

    Oct 28 · two hours, live

    Scam and Fraud Home Defense

    $100
    • operate a callback rule against incoming contact
    • classify an incoming contact as genuine or pretext

    Nov 25 · two hours, live

    Digital Identity Defense

    $100
    • configure recovery that survives losing the device
    • falsify your own account recovery by attempting it
    • classify an incoming contact as genuine or pretext
    • operate a callback rule against incoming contact

    Aug 26 · two hours, live

    Also on the calendar

    Secure work inside classes that are about something else.

    An AI class that teaches you where untrusted input enters a system, and an off-grid automation class that teaches you to run a mesh network with the internet down. They are about their own subjects, and they are on the calendar too.

    Solarpunk Automation

    $100
    • operate a mesh network that carries messages without infrastructure

    Aug 22 · live · 3.9 h recorded · 13 exercises

    Agentic SDLC

    $500
    • produce a list of where untrusted input enters a system
    • characterise an applications injection surface

    Sep 7 · live · 26.5 h recorded · 46 exercises

    Critical Thinking and Creativity with AI

    $100
    • configure an assistants memory and outside connections

    Sep 11 · live · 22.4 h recorded · 21 exercises

    Find your class Take the whole Defender route →

    What is in the box

    A live room, a thing you build, and the material to keep.

    Live teaching
    7

    sessions on the calendar between August and November, pay what you can. You bring your own router, your own inbox and your own accounts, and you change them in the room while somebody is there to ask.

    Proof, not attendance
    10

    capabilities you can learn from these classes, and every one of them names the artifact you have to produce before it counts — a printed set of recovery codes, a device inventory, an attempt log against your own accounts. They are printed on this page, below, before you pay for anything.

    Material you keep
    80

    exercises across these 7 classes, plus 52.8 hours of recording and the reference material each class ships with — the Six Roses handbook for the household classes, a working companion for the AI ones. Yours after, not just during.

    The work itself

    What you can walk out able to do, and what proves it.

    Written as verbs, easiest first, each one dated and each one with the artifact that settles it printed underneath. Read them before you decide whether an evening is worth its own price.

    1. Oct 28next taught

      follow a device hardening checklist

      Consumer Device Rescue and Defense

      The router or device admin pages before and after — default password changed, remote administration off, automatic updates on — with one line per item on what it closes.

    2. Sep 30next taught

      locate every device on your own network

      Home Network Defense

      A device inventory taken from the router, with each entry identified or explicitly listed as unidentified.

    3. Sep 11next taught

      configure an assistants memory and outside connections

      Critical Thinking and Creativity with AI

      Memory on with one fact it retained across a fresh conversation, one connector enabled with the scopes it was granted written out, and one source you deliberately did not connect with the reason.

    4. Aug 26next taught

      configure recovery that survives losing the device

      Digital Identity Defense

      Recovery codes printed and stored off any device, a password manager on every device, SMS removed as a recovery method, and a written account of what happens if the phone is gone.

    5. Aug 26next taught

      operate a callback rule against incoming contact

      Scam and Fraud Home Defense Nov 25 · Digital Identity Defense Aug 26

      A household agreement in writing including a code phrase, and one real incoming contact you broke off and called back.

    6. Aug 22next taught

      operate a mesh network that carries messages without infrastructure

      Solarpunk Automation

      A message delivered node to node with the internet off, reporting the distance covered and the number of hops it took.

    7. Sep 7next taught

      produce a list of where untrusted input enters a system

      Agentic SDLC

      An enumerated list against a real codebase or system, including one entry point that is not an obvious form field.

    8. Sep 7next taught

      characterise an applications injection surface

      Agentic SDLC

      A written surface map for a real application naming the query, template or shell interpreter behind each entry point.

    9. Aug 26next taught

      classify an incoming contact as genuine or pretext

      Digital Identity Defense Aug 26 · Scam and Fraud Home Defense Nov 25

      Five real examples classified with the tell named for each, including one genuine message that looked like a pretext.

    10. Aug 26next taught

      falsify your own account recovery by attempting it

      Digital Identity Defense

      A written attempt log against your own accounts, the furthest step reached, and the control you added because of it.

    One evening, in detail

    You have to read a pretext before you can write one.

    Ring your own provider. Run your own recovery flow. Answer the security questions as a stranger would and find out how far that stranger gets before somebody stops them. Almost nobody has done this to themselves, and everybody has an opinion about how it would go.

    Doing it means pretexting yourself — inventing a plausible story, in a plausible voice, and watching which part of it the help desk believes. So you learn to read one first: five real messages, the tell named in each, including the genuine one that looked like a trap. Both halves happen in the same room on the same evening, and you leave with the log of what you got away with.

    Digital Identity Defense

    $100
    • classify an incoming contact as genuine or pretext
    • falsify your own account recovery by attempting it

    What you have to showA written attempt log against your own accounts, the furthest step reached, and the control you added because of it.

    Aug 26 · two hours, live · pay what you can

    Where else it turns up

    Most people who need this did not come here for security.

    They came to build something, run something or hold a group together, and the security work arrived attached to it. These are the routes where that happens.

    A solo founder is the company's single point of failure. “configure recovery that survives losing the device” is filed under security, but for one person carrying a business it is business continuity: the difference between a bad afternoon and telling your customers why nobody can bill them.

    People who build things that provoke draw attention they did not plan for. A project that gets noticed brings an audience you did not choose. That is a threat model arriving after the fact, which is the worst time to write one.

    Disqualifiers

    Who should not buy this.

    Or take all of them

    What a month buys, if one evening is not the shape of it.

    One class needs nothing else. Two monthly subscriptions cover the whole school instead, and they are different products.

    Start anywhere

    Read one guide tonight. Book one class this month.

    The guides cost nothing and need no account. A class can be taken on its own, pay what you can, and needs no other class. If you want every Secure class rather than one evening of them, the Defender path is the door for that.

    Secure Each class has its own price
    Find your class