🛡️ The Defender Package
Defend your devices, your accounts and the people you are responsible for.
4 live sessions. 7 tools. Recordings of everything. Work outward from the router in your house to the stranger on the phone who sounds exactly like your bank. You finish each one having done the thing on your own hardware.
Start with the free Identity Defense Worksheet — find out what is broken. Then decide about the classes. $100/mo or $400 one-time.
Next session: Home Network Defense · Wednesday 30 September
Out from the middle is how far it reaches. Around the dial is when it runs, clockwise from the next one at the top.
- 01 Home Network Defense — the wire in your own house
- 02 Consumer Device Rescue and Defense — the devices on it
- 03 Scam and Fraud Home Defense — whoever rings you
- 04 Digital Identity Defense — the companies holding your accounts
- 05 Field Opsec
- 06 AI Security: Governance, Standards and Safety Cases
Free · runs in your browser · nothing is sent anywhere
Do this now. Find out what is actually broken.
The Identity Defense Worksheet walks you through 7 steps — map your accounts, audit your passwords, test your recovery paths, and find out which ones fold before somebody else does. By step 3 you will know exactly how much work you are looking at.
The Identity Defense Worksheet
7 steps. Your own accounts, your own passwords, your own recovery paths. Everything stays in your browser — nothing is sent, nothing is stored on a server, and the results are saved on this device for your dashboard if you join later.
The worksheet is the free version. The Digital Identity Defense class teaches you how to read your own screens for signs of compromise and detect accounts that have already been accessed.
🎮 Prefer a game?
Reclaim City teaches the same ideas as the worksheet — account security, password hygiene, recovery paths — but as a game instead of a checklist. If the worksheet feels overwhelming, start here.
Start here
Security advice is worthless until it knows who you are hiding from.
Four questions, thirty seconds. You get a short list: which free guide to read tonight, and which class to be in. Your answers stay here: this runs in your browser, and the first step it names is saved in it. Clear answers wipes that too.
Pick an answer above and your short list appears here. If you would rather just read, the five guides are below and every one of them is free.
What you get good at
Spot the threat, map it, then break it yourself.
Every line below is something you will have done on your own hardware rather than read about. The rungs run outward the same way the classes do: what you can notice, what you can harden, and what you can attack on purpose to find out whether it holds. Say what you can honestly give it in a week and watch how far out the hours reach.
Spend it. Each class costs what it really takes.
- follow a device hardening checklist
- locate a substitute part when the named one is unavailable
- execute a security playbook in a drill
- locate a claim in its primary source
- locate every device on your own network
- locate the standard that governs a system you are building
- repurpose a retired device into a working server
- configure recovery that survives losing the device
- migrate your work off a subscription without losing it
- operate a callback rule against incoming contact
- produce a list of where untrusted input enters a system
- produce a threat model for your own situation
- produce a working script from a worked example
- produce an inventory of what you pay for and what it holds
- transform an incoming message into ask deadline and claimed sender
- characterise a models failure modes
- characterise an applications injection surface
- characterise how an AI assisted attack unfolded
- characterise the legal boundary of an engagement before you touch anything
- characterise what a publication reveals about its source
- characterise what breaks when you cut the connection
- classify a situation into the playbook it calls for
- classify an incoming contact as genuine or pretext
- classify the personal data a system holds and when it is deleted
2 more on this rung
- classify which framework applies where you are in the lifecycle
- generalise several sources into a position you can defend
- falsify a networks access control from outside it
- falsify a physical sites access controls
- falsify an applications defences against a named attack class
- falsify your own account recovery by attempting it
- justify a safety case for a system that acts without you
- justify a vulnerability order by what each would cost you
- measure a models value alignment against a stated standard
- verify an incident timeline against the evidence that remains
- verify model written code against its specification
3 more on this rung
- verify separate identities do not leak into each other
- verify what can be found about you is actually gone
- verify you would know your system broke before a user tells you
- design a containment that preserves the evidence
- design a control for what an insider could do unseen
- design a device posture for a border crossing
- design a household security posture for people who did not choose it
- design a pretext that gets you past a human gate
- design a scheme for acting together when the channel is gone
- govern a source relationship from first contact to its end
- govern your own decisions under coercion by a rule set in advance
- reconcile security with what people will actually do
- synthesise an accountability regime for an unattended agent
5 of these 10 classes fit in 15 hours, and they open 25 of the 48 things above, as far up as govern the policy.
That opens the recordings, the exercises and the written curriculum on this path, and the standups every week. $500 a month adds a seat in every class on it that runs this month.
What a point is. Ten hours of your time — the recordings you watch, the exercises you work through, and the session itself. Move either slider, or pick the classes yourself and see what the hours come to.
Free, public, no account
Somebody is typing one of these into a search bar at 2am.
Five situations, five guides. No sign-up, no email capture, no paywall, no account. If one of these is your situation, go and read it now and decide about the classes afterwards.
Digital Security Reset
The full reset, in phases, starting with the ten minutes before you touch anything. Ground yourself, work out what actually happened, cut the access, then clean up in an order that does not destroy the evidence.
Read the reset → Cyberstalked by an ex or a partner?The Story of Six Roses
Written for the case where the person tracking you already knows your passcode, your security questions and your habits. Safety planning first, then breaking their digital access without tipping them off.
Read Six Roses → Activist?Activist Security: Tails OS and Beyond
If your threat model is the state, this is the guide you want. Threat modeling, then Tails as a digital panic room, then the operational discipline that makes it mean anything. This is not an easy path.
Read the activist guide → Journalist?Journalist Digital Security
The threat landscape you are actually in, anti-doxxing and identity protection, and a device architecture that keeps a source's safety from depending on your worst day.
Read the journalist guide → Home for the holidays?Cybersecurity for Grandma
A visit-length checklist for the relative who keeps nearly falling for it. Pull her off the people-finder sites, set up a password manager she will actually use, and agree a family password before you leave.
Read the holiday guide →Read all five. Then do it for real.
The guides give you the whole method in writing. The Defender package gives you four live classes, seven tools, and recordings of everything — plus the skills to read your own screens for signs of compromise.
Get Defender · $400The order
Outward from your own house.
Your network, then your hardware, then the people who contact you, then the accounts that live somewhere else. Every one of them runs live and is recorded, and every one ends with something changed on your actual devices rather than something noted down for later.
-
01 Home Network Defense Wed 30 Sep
Find out what is actually on your network, including the things you did not put there, and which account really owns the router.
-
02 Consumer Device Rescue and Defense Wed 28 Oct
Take a phone or a laptop that somebody else has had their hands on and make it yours again — checklist first, guesswork never.
-
03 Scam and Fraud Home Defense Wed 18 Nov
Read a pretext for what it is, and hold a callback rule that survives being rushed by somebody who sounds official.
-
04 Digital Identity Defense Wed 6 Jan
Attack your own account recovery, find where it folds, and rebuild it so that losing the device is not the same as losing the account.
-
05 Field Opsec Mon 16 Nov
Threat model your own situation, work out which playbook it calls for, and drill it — then reconcile all of that with what the people around you will actually do.
-
06 AI Security: Governance, Standards and Safety Cases Fri 30 Oct
Find the standard that governs the system you are building, and write a safety case for something that acts when nobody is watching it.
Why identity defense sits at the end. Falsifying your own account recovery means pretexting yourself: ringing the help desk, answering the security questions, seeing how far a plausible stranger gets. That exercise only tells you the truth once you can already read a pretext, which is what the class before it teaches. Run it the other way round and you will grade your own attack far too kindly.
What the Defender package includes
The whole package.
The devices you already own
A phone, a laptop or the router that is already in your house, and two hours where you can sit with it. No terminal, no command line, nothing to buy and nothing to install before you arrive. If you can read this page, you have the equipment.
4 live classes and their recordings
Home Network Defense, Digital Identity Defense, Consumer Device Rescue, and Scam and Fraud Defense. Each class is recorded — a session you miss is still a session you get.
7 security tools, yours to keep
Threat Model, Device Rescue, Ad Surface Audit, Attack Surface Map, Password Health Check, and more. Each one writes to your profile so your security posture is tracked over time.
Done, not noted down for later
You work on your own hardware — the router in your house, the phone in your pocket, the accounts with your name on them — and you leave with something changed on the device rather than a list of jobs for the weekend.
Classes update — your access stays current
When a Defender class is re-recorded or expanded, the new version replaces the old one in your library. You bought the package once; the material keeps improving.
The five guides, free either way
Public before you pay, public afterwards. Nothing has been held back for a paying version — the reset guide opens with what to do in the next ten minutes, and it opens that way for everybody.
Four doors down the hall
If this is not the one you need, here is the one that is.
You want to own the whole stack, not just defend it
If the motivation is that you are tired of renting your tools — your own server, your own network, your own model on your own hardware — two of these classes are on that route as well, and it keeps going into hardware rather than into opsec. Take Digital Independence →
You are defending a group, not a household
If the people you are responsible for are a mutual aid network, an organizing crew or a small org that has to keep running when things fail, the resilience route starts from the same field opsec and heads toward continuity. Take The Independence Path →
You cannot make a fixed Wednesday
Every class is recorded with its written curriculum, and the five guides are free. Work through it on your own schedule — a class you finish is yours to keep.
Someone is in your accounts right now
That is an incident, not a curriculum, and a class next Wednesday is the wrong instrument. Go and work through the Digital Security Reset tonight — it is free and it opens with the next ten minutes. Come back afterwards and make the second time harder.
One thing this package will not do: tell you that you are safe. You finish it able to say what you are exposed to, what you have closed, and what you decided to live with.
The Defender
You already know what you are worried about.
The guides are free and you can start one in the next minute. The classes are the part where you stop reading about it and change something on the device in your hand, starting Wednesday 30 September with Home Network Defense.
$100/mo subscription or $400 one-time — 4 classes, 7 tools, monthly meetup, recordings, yours to keep. Everyone who joins this year gets lifetime access to the Defender track, including everything added later. This is an add-on path — it covers Defender content only, not other paths. Want the full stack? Independence ($150/mo) includes all of Defender plus self-hosting, open source, and mesh networking. Full scholarships exist — if the number is the thing stopping you, ask.