SeaPeaEPrivate learning recordOpen the ledger

HOW IT WORKS

Your CPE record, without the spreadsheet.

If you hold a CISSP or a CISM, you already do the learning. The painful part is proving it three years later: which podcast counted, how long that course was, where the certificate went, and whether you cleared the annual minimum you forgot existed. This keeps that record as you go.

The five steps

  1. 01

    Tell it what you learned

    Say it the way you would out loud. Type "I read Threat Modeling by Adam Shostack" and it finds the book, the author, the page count, and an estimate of how long that takes to read. Paste a link to a white paper and it reads the page. For everything else there is a short form.

  2. 02

    It scores against both rule sets

    ISC2 and ISACA do not count the same activity the same way, and most people discover that at renewal. Every entry is scored twice, with the reasoning written out in plain English, so you can see why something counts for one certification and not the other.

  3. 03

    You confirm the time

    Nothing counts until you say how long you actually spent. Estimates from page counts and video lengths are starting points, never claims. Estimates are held in a separate column and excluded from every total until you decide.

  4. 04

    It files them for you

    Filing a credit normally means retyping the title, provider, date and hours into a form, then hunting down the right certificate and uploading it. The add-on fills all of that and attaches the file. You check the form and press the portal's own save button, and the next entry loads automatically.

  5. 05

    It tells you where you stand

    Not just a running total. Both certifications enforce a yearly minimum separately from the three-year requirement, and the yearly one is what catches people out. The dashboard shows each cycle year, what is still missing, and how much you need per month to finish.

WHERE THE LEARNING COMES FROM

Six ways in.

Some sources can be read automatically. Some cannot, because their terms forbid it, and we would rather tell you that than quietly risk your account.

Books
Name the title and author. The catalogue lookup runs in your browser, so what you read never passes through our server.
White papers and articles
Paste the link. The page is read for a length estimate and the subject is matched against the certification domains.
BrightTALK
The browser add-on reads your own viewing history using the session you are already signed into. No password is stored.
YouTube
Ask Google Takeout for your watch history and drop the zip in as it arrives. The app looks up how long each video is, so confirming one is a single click. YouTube forbids automated scraping, so the export is the supported route.
Spotify podcasts
Ask Spotify for your account data and drop the zip in. Their public interface leaves podcasts out entirely and their API is now closed to anything under 250,000 users, so the export is the only route. Listening is added up per episode across every sitting.
Udemy and everything else
Udemy forbids automated reading and publishes no export, so this is the one source that still needs a hand. Add the course and attach the certificate, which then gets uploaded to the portal for you automatically.

THE PART PEOPLE GET WRONG

Two certifications, two answers.

ISC2 · CISSP

120 credits over three years, 90 of them domain-related

An hour of learning is one credit. Domain-related material counts as Group A. General professional skills such as leadership or public speaking count as Group B, capped at 30. Earn 40 Group B credits and 10 of them are wasted, which the dashboard warns you about rather than letting you find out at renewal.

ISACA · CISM

120 hours, a hard annual floor, and an hour is 50 minutes

ISACA counts a CPE hour as 50 minutes of active participation, so the same activity is worth more here than for CISSP. It also enforces a 20-hour annual minimum entirely separately from the three-year total. Clearing 120 means nothing if you missed a year.

From 1 January 2027 ISACA moves to the same 90 and 30 split as ISC2 and stops awarding credit for vendor product demonstrations. Activities are scored under whichever policy applied on the day you completed them, so your older entries do not silently change value.

BUILT FOR PEOPLE WHO READ THE THREAT MODEL

We cannot read your records.

ENCRYPTED ON YOUR DEVICE

The server stores ciphertext it has no key for

Your records are encrypted in your browser before they sync, using a key derived from your password. The password never leaves your device. What reaches the server is an email address, a verifier that cannot be reversed into a password, and an unreadable blob.

NO ACCOUNT TOKENS

We never hold your logins

History is read by a browser add-on running on your machine, using sessions you are already signed into. There are no stored passwords and no access tokens, so there is nothing worth stealing from us.

DELETED ON SCHEDULE

Records expire after they are accepted

A year after a certification body accepts a submission, the entry and its evidence are deleted automatically. You can shorten that, keep the ledger line while dropping the file, or switch it off.

WHAT IT DOES NOT DO

The honest limits.

It cannot press save for you

Neither ISC2 nor ISACA offers a way for software to file on your behalf, and neither accepts a bulk upload. So this drives their form instead: it fills every field it recognizes, attaches your evidence file to the upload box, and then waits. You check it and press their save button, and the next entry loads by itself. A CPE claim is your attestation, and their forms change without warning, so a person sees every entry before it goes in.

It cannot know how long you watched

No history export records attention. A video appearing in your history proves you opened it, nothing more. So the app looks up how long the video is and asks you to confirm, rather than assuming. One click if you watched it all, a number if you did not. Nothing is claimed on your behalf.

It is not a ruling on eligibility

The scoring follows published ISC2 and ISACA policy, including the ISACA changes taking effect in January 2027. It is a well-informed starting point and an audit trail, not a guarantee. The final judgement on any credit is yours.

We cannot recover your password

Your password is the key that decrypts your records. We do not hold a copy, which is the entire point. If you lose it, the data is gone. Use a password manager.

$19.99 per year.

One price, both certifications, no add-ons. Cheaper than the coffee you drink during one webinar.

Create your account