Sanitization rules
Never post CUI or client-identifying detail
Do not post Controlled Unclassified Information, company or client names, real hostnames, IP addresses, URLs, contract or CAGE numbers, personnel names, or anything else that identifies a specific environment. Describe the pattern, not the deployment.
What “sanitized” means here
- Write about controls and implementation patterns in general terms — roles, configurations, and evidence types — not your customer’s network.
- Prefer placeholders (
example.com,192.0.2.0/24,Acme Corp) over anything that could resolve to a real org. - An automated scan blocks obvious cases (hostnames, IPs, emails, and similar). It is a safety net under your judgement, not a substitute for it.
- Submitting an example requires an attestation that the content is sanitized. That attestation is stored with the submission.
Review and removal
Examples are reviewed by an administrator before they appear publicly. Review is primarily a sanitization check. An example that arguably falls below the line is not removed for being wrong — the verdict system exists precisely to say so in public. Content is removed for unsanitized detail, spam, or abuse.
If you find possible CUI or other content that should not be public, use Report with reason possible CUI, or email security@controlverdict.com. See Security.