Skip to content

Editorial Guidelines

Our standards for sourcing, bylines, corrections, disclosure and the use of AI.

Standards

  1. Source every claim with a primary document, and link it.
  2. Real authors only — real photos, real biographies, real credentials.
  3. No fabricated incidents, losses, CVEs, addresses, dates or regulator statements.
  4. No attribution without an official attribution.
  5. No financial, legal, tax or security advice. No “move your funds” instructions. No unverified recovery or revoke links.
  6. Disclose conflicts — contributor holdings, and any relationship with a covered entity or security vendor — at the top of the article.
  7. Corrections are appended, dated, and logged publicly.
  8. State plainly how AI is used. A human is accountable for every published claim.

Bylines

Every public byline on Conisec is a real, named person, or the clearly-labelled Conisec Staff newsroom byline. There is no admin account byline on this site and there never will be.

Conisec Staff is used for factual records compiled and verified by the newsroom rather than written as a single reporter’s piece: Incident Tracker entries, jurisdiction field sets and sourced timelines. Every claim under that byline cites a primary document, and a named editor is accountable for it internally. Analysis, post-mortems and opinion always carry a named individual author with a published biography and credentials.

Our AI policy

We will not claim to be “100% human-written”, because we do not think that claim is usually true where it is made. Here is what is actually true of Conisec:

  • AI tooling may be used for drafting assistance, summarisation, copy-editing and code.
  • AI is never the source of a factual claim. Every fact, figure, date, address and quotation is verified by a human against a primary document before publication.
  • No article is published without a human editor who is accountable for its accuracy.
  • We do not generate photographs of people, and we do not illustrate security stories with AI imagery.

Workflow

Draft → Edit → Source-Check → Ready → Publish. Nothing publishes without editor signoff, a source check against primary documents, at least three sourced claims with outbound links, a completed Ledger where applicable, the non-advice disclaimer, and a real byline.

Imagery

We do not illustrate security stories with hooded figures, green matrix backgrounds or AI-generated “hackers”. Our visual register is documentary: diagrams, timelines, charts, and screenshots of official notices. Where a story has no genuine image, it runs with a branded placeholder rather than a decorative stock photo.