Charter
The Sentinel's Rules
Ten rules the Sentinel works and writes by. They exist so that readers can check the work — and so the Sentinel can be held to them.
-
Authorized work only
Every technique shown was used in the Sentinel's own labs, in CTFs, in bug bounties within program rules, or in engagements the Sentinel was paid and permitted to run. Nothing else.
-
Disclosure comes before publication
Findings are written up only after they are patched, published by the vendor, or released under a coordinated disclosure process in line with ISO/IEC 29147 and the CERT/CC guide — never before, and never in violation of a program's terms.
-
Composites are labeled composites
Real experience is real, but no client, employer, or colleague is ever identifiable. War stories are merged, altered accounts — and every one carries a composite notice.
-
Sources are attributed
Quotations are quoted and credited. Facts lean on primary sources: standards bodies, vendor advisories, original research. If the Sentinel can't cite it, the Sentinel says so instead of dressing a hunch as fact.
-
Labs before claims
Offensive content is demonstrated in lab recreations, with the environment and limits stated. Screenshots and traces come from the lab, not from anyone's production systems.
-
No exploit retail
No working 0-days, no weaponized payloads, no "DM me for the PoC." If a detail would mainly help an attacker and not a defender, it stays out.
-
Mistakes get corrections
Errors are corrected in place, marked with an updated date, and never silently rewritten. The archive is a record, not a brochure.
-
No fear-selling
No fake urgency, no "you'll be hacked by Friday," no CVSS theater. Risk is described in plain terms with realistic likelihoods, because fear is a tax on readers.
-
Anonymity is not impunity
The Sentinel writes anonymously, which lowers the cost of candor — it does not lower the standard. The same laws, ethics, and program rules apply; anonymity only protects a name, never a practice.
-
Reader autonomy over engagement
Monetization, when it arrives, will be disclosed on this site's Disclosures page before it appears in the feed. Sponsorship never buys a verdict.
Sources & attributions
- ISO/IEC 29147:2018, Information technology — Security techniques — Vulnerability disclosure, iso.org/standard/72311 — the standard this charter's disclosure rule follows.
- ISO/IEC 30111:2019, Vulnerability handling and disclosure processes, iso.org/standard/71729.
- Householder, Garfinkel et al., Guidelines on Vulnerability Disclosure, CERT/CC CMU/SEI-2017-SR-013 (v1.2, 2024), resources.sei.cmu.edu.
- Electronic Frontier Foundation, Defending Privacy at the U.S. Border and anonymity writing generally — eff.org/issues/anonymity — background for Rule 9.