Documentation

Docs

Publication boundary

What this public documentation can explain and what remains private for security, privacy, and evidence protection.

Transparency is important, but publishing operational detection knowledge or protected material could create security, privacy, and investigative risks. The public site therefore documents principles, contracts, limitations, and status—not sensitive internals.

Appropriate for publication

  • research purpose and current status;
  • evidence-first architecture principles;
  • distinctions between facts, calculations, analysis, and hypotheses;
  • integrity, provenance, audit, and reproducibility requirements;
  • explainability and human-review requirements;
  • known high-level limitations and external approval needs;
  • public website privacy and security information.

Not appropriate for publication

  • collector or parser implementation details;
  • platform weaknesses or source-specific operational behavior;
  • detection rules, active indicators, thresholds, weights, or signal combinations;
  • internal prompts that influence operational analysis;
  • operational datasets, evidence, source captures, or case material;
  • personal information or investigative leads;
  • internal governance, authorization, or legal working documents;
  • credentials, private infrastructure details, or repository metadata.

No approval by implication

Documentation must not describe a proposed collaboration, pilot, authorization, external review, or operational capability as if it already exists. Unknown and not assessed remain valid—and necessary—public statements.