Verification Standard & Philosophy
A neutral, high-signal index of security incident statuses and verifiable milestone timelines, powered by open weights correlation and community-driven GitHub PR editing.
1. Neutral Intelligence Through Open Curation
Modern security incident reporting is plagued by corporate PR ambiguity, premature categorization, and recycled claims. We provide a reliable and neutral source of cybersecurity intelligence by curating security data across its entire lifecycle, ranging from early dark web rumors to formal regulatory disclosures.
To deliver maximum clarity, we establish clear levels of confidence and correlate diverse data sources using open weights. Built entirely on open editing through GitHub pull requests, securityincident.net empowers security professionals, researchers, and organizations to maintain a transparent, verifiable, and high-signal record of security incidents without corporate bias or editorial filler.
2. Granular Open Weights Correlation Model (v2.0)
Unlike opaque black-box AI scores or proprietary vendor risk ratings, our confidence scoring is 100% deterministic, auditable, and open-source. Defined in sources/weights.json and executed in scripts/weights.js, confidence is evaluated continuously across four orthogonal dimensions rather than clumping into coarse tiers:
| Verification Tier | Primary Authority Baseline | Primary Sources |
|---|---|---|
| CONFIRMED BY REGULATOR | 0.65 (65%) | SEC Form 8-K Item 1.05, State AG breach portals, HHS OCR, CISA KEV advisory. |
| CONFIRMED BY TARGET | 0.50 (50%) | Official corporate press release, company security blog, direct target status bulletin. |
| INDEPENDENT VERIFICATION | 0.32 (32%) | Reputable cybersecurity researcher analysis, HaveIBeenPwned audit, forensic investigative reporting. |
| ACKNOWLEDGED | 0.18 (18%) | Target publicly confirms operational disruption or active investigation without confirming data compromise. |
| UNVERIFIED CLAIM | 0.06 (6%) | Threat actor leak blog, dark web forum listing, unverified community chatter (low baseline floor). |
| REFUTED | 0.00 (0%) | Proven false alarm, recycled historical data, or web scrape mislabeled as a breach. |
Multi-Dimensional Scoring Dimensions:
- 1. Primary Authority Base: 6% baseline for raw unverified claims up to 65% for statutory regulatory disclosures.
- 2. Evidence Specificity & Data Quality (+0% to +23%): Statutory regulatory filings (+12%), verified primary domain (+3%), disclosed compromised data classes (+4%), and quantified affected records (+4%).
- 3. Corroboration & Multi-Source Curve (+0% to +25%): Logarithmic curve for independent source domains (2 domains: +7%, 3 domains: +12%, 4 domains: +16%, 5+ domains: +20%), plus a +5% cross-tier correlation boost when threat telemetry is corroborated by target or regulatory disclosure.
- 4. Temporal Dynamics & Unverified Staleness Decay (-10% to +5%): Milestone timeline depth (+3% for ≥3 milestones, +5% for ≥5 milestones). Dormant uncorroborated darkweb claims decay over time (-3% at 14 days, -5% at 30 days) to prevent adversary bluffs from retaining confidence.
3. The 5 Observable Statuses
Highest assurance: Officially verified by the target or government regulator (e.g. SEC Form 8-K Item 1.05, State AG breach portals, formal press releases).
Target publicly confirms an "IT disruption" or active investigation, but has not yet confirmed a breach or data loss.
Corroborated intelligence: independent researchers verify samples or observable outages align with claims before target response.
Early threat actor claims, dark web forum leaks, or unverified community chatter before target comment.
Proven false alarm, recycled historical leak, or public web scrape mislabeled as a breach.
4. 100% Git-Native & Transparent
Every incident is stored as an open Markdown document in our GitHub repository. We use GitHub Actions to automate indexing from regulatory RSS and infosec feeds, with zero complex databases. Anyone can audit our sources, examine historical revisions in Git, or submit updates via Pull Request.
5. How to Contribute via GitHub PR
Because all incidents are stored as flat Markdown files in Git, you don't need special permissions or database access to contribute. You can propose updates in two easy ways:
- In-Browser (Zero Setup): On any incident detail page, click the "Propose Update via GitHub" button at the bottom of the timeline. Use GitHub's web editor to add your milestone with a verified primary source link and click "Propose changes" to automatically submit a Pull Request.
- Local PR Workflow: Fork the repository, create a new incident in
incidents/YYYY-MM-<slug>.md, and open a Pull Request.
For detailed schema requirements and verification standards, read our Contributing Guidelines on GitHub.