EDITORIAL POLICY · VERSION 1.0

Accountability behind the guidance

How LR InfoSec Lab handles authorship, sources, review status, corrections, AI-assisted tools, and the limits of general security guidance.

Authorship and accountability

Articles, playbooks, and field guides are authored and reviewed by Leandro Rocha, who remains accountable for technical claims, recommendations, references, corrections, and publication decisions. A resource will not claim independent peer review unless an identified review process has occurred.

AI-assistance disclosure

Disclosure: AI-assisted tools may be used during research, outlining, drafting, editing, or quality checks. Technical claims, cited sources, operational recommendations, and final publication decisions remain the author's responsibility. AI output is not treated as an authoritative source.

Assistance does not replace source review, technical judgment, testing, or accountability. Sensitive incident data, credentials, customer information, or confidential organizational material should not be submitted to external AI systems without explicit authorization and appropriate controls.

Sources and standards

Operational resources identify a reference basis, assumptions, and limitations. Preference is given to primary standards, official vendor documentation, security advisories, and established practitioner frameworks. Standards mapping provides context; it does not imply certification or endorsement.

Review and versioning

Operational guides carry a version, publication/review date, author, and review status. Material changes should increment the version and be visible in repository history. Guidance is re-evaluated when standards, threats, platforms, or field experience materially change the recommendation.

Corrections

Technical errors, unsafe recommendations, broken sources, and unclear assumptions are corrected openly. Report an issue through GitHub Issues or email. Significant corrections should update the affected resource's version and review date.

Limitations

The site provides educational field guidance, not organization-specific legal, privacy, regulatory, safety, insurance, crisis-communications, or business-continuity advice. Responders must adapt actions to their authority, architecture, evidence, business impact, contracts, jurisdiction, and applicable obligations.

Security and privacy posture

The public site is statically generated and intentionally avoids unnecessary client-side scripts, analytics, trackers, forms, and third-party browser code. Do not submit secrets or sensitive incident data through public repository issues or email.

Policy published and reviewed: 18 August 2026 · Accountable editor: Leandro Rocha · Version 1.0