HOW IT WORKS
Your CPE record, without the spreadsheet.
If you hold a CISSP or a CISM, you already do the learning. The painful part is proving it three years later: which podcast counted, how long that course was, where the certificate went, and whether you cleared the annual minimum you forgot existed. This keeps that record as you go.
WHERE THE LEARNING COMES FROM
Six ways in.
Some sources can be read automatically. Some cannot, because their terms forbid it, and we would rather tell you that than quietly risk your account.
- Books
- Name the title and author. The catalogue lookup runs in your browser, so what you read never passes through our server.
- White papers and articles
- Paste the link. The page is read for a length estimate and the subject is matched against the certification domains.
- BrightTALK
- The browser add-on reads your own viewing history using the session you are already signed into. No password is stored.
- YouTube
- Ask Google Takeout for your watch history and drop the zip in as it arrives. The app looks up how long each video is, so confirming one is a single click. YouTube forbids automated scraping, so the export is the supported route.
- Spotify podcasts
- Ask Spotify for your account data and drop the zip in. Their public interface leaves podcasts out entirely and their API is now closed to anything under 250,000 users, so the export is the only route. Listening is added up per episode across every sitting.
- Udemy and everything else
- Udemy forbids automated reading and publishes no export, so this is the one source that still needs a hand. Add the course and attach the certificate, which then gets uploaded to the portal for you automatically.
THE PART PEOPLE GET WRONG
Two certifications, two answers.
ISC2 · CISSP120 credits over three years, 90 of them domain-related
An hour of learning is one credit. Domain-related material counts as Group A. General professional skills such as leadership or public speaking count as Group B, capped at 30. Earn 40 Group B credits and 10 of them are wasted, which the dashboard warns you about rather than letting you find out at renewal.
ISACA · CISM120 hours, a hard annual floor, and an hour is 50 minutes
ISACA counts a CPE hour as 50 minutes of active participation, so the same activity is worth more here than for CISSP. It also enforces a 20-hour annual minimum entirely separately from the three-year total. Clearing 120 means nothing if you missed a year.
From 1 January 2027 ISACA moves to the same 90 and 30 split as ISC2 and stops awarding credit for vendor product demonstrations. Activities are scored under whichever policy applied on the day you completed them, so your older entries do not silently change value.
BUILT FOR PEOPLE WHO READ THE THREAT MODEL
We cannot read your records.
ENCRYPTED ON YOUR DEVICEThe server stores ciphertext it has no key for
Your records are encrypted in your browser before they sync, using a key derived from your password. The password never leaves your device. What reaches the server is an email address, a verifier that cannot be reversed into a password, and an unreadable blob.
NO ACCOUNT TOKENSWe never hold your logins
History is read by a browser add-on running on your machine, using sessions you are already signed into. There are no stored passwords and no access tokens, so there is nothing worth stealing from us.
DELETED ON SCHEDULERecords expire after they are accepted
A year after a certification body accepts a submission, the entry and its evidence are deleted automatically. You can shorten that, keep the ledger line while dropping the file, or switch it off.