Cases and incidents
A case explains a security principle through a sourced event, dispute, research capability, policy development, or explicitly labeled scenario. An incident is an observed event affecting an asset. The database retains event types so a capability or policy change cannot be mistaken for a confirmed attack.
Source hierarchy
- Tier 1: original research, government documents, court records, statutes, official notices, filings, and standards.
- Tier 2: institutions, investigative reporting, and established scientific publications.
- Tier 3: specialist industry reporting.
- Tier 4: commentary and blogs.
Primary means direct evidence for a claim, not automatic reliability. A company disclosure establishes what it reported; it does not independently verify every consequence. Source labels appear near summaries and in source lists.
Evidence statuses
- confirmed
- A documented event supported by sufficiently direct evidence.
- officially disclosed
- A responsible organization or authority has publicly reported the event or development.
- well sourced
- Credible sources support the described case, with stated limits.
- disputed
- Material facts or interpretations are contested.
- alleged
- A claim has been made but is not established.
- threat model
- A hypothetical scenario used to examine pathways and controls; no incident is implied.
- historical governance case
- A historical consent, custody, or governance dispute requiring context.
Assigning GER, GPR, and GPI
Identify the exact asset and event first. GER describes exposure scope, GPR describes the durability of the consequences, and GPI describes verifiability. Record the level, rationale, confidence, and limitations separately. These are proposed site concepts, not established external standards. A numerical level is optional when the public evidence is inadequate; null means unassigned, not zero.
- Genetic Exposure Radius — Scope of relational exposure
- Genetic Persistence Risk — Durability after compromise
- Genetic Provenance Integrity — Verifiability of the chain of custody
Uncertain numbers
Use null in machine-readable records and “unknown” in prose when no supported count exists. Do not add overlapping profile counts into a unique-person total. Potentially affected relatives are not automatically confirmed victims. Scenario-dependent values must never be presented as observed counts.
Review and update policy
Review source-sensitive claims when authoritative notices, policy changes, or substantive corrections appear. The displayed review date records the editorial review, not continuous monitoring. Keep modification dates tied to material changes. This first edition is dated September 19, 2026; it does not claim an earlier public publication history.
Follow one claim from source to conclusion
Suppose a notice says that an attacker viewed a profile containing a name and genetic-relative information. The supported statement is about that profile and those fields. A claim that the attacker obtained a whole genome would require additional evidence. The fact that the service performs genetic testing does not fill the gap.
Next comes analysis. Connected relative information may widen the scope of exposure beyond the account holder. That is a reason to examine GER, not permission to invent a count of exposed relatives. Keeping the observation and the interpretation in separate sentences makes the reasoning easier to challenge or improve.
Confidence and severity answer different questions
Confidence describes how well the evidence supports a statement. Severity concerns the consequences. A small, clearly documented disclosure may be supported with high confidence. A potentially serious exposure may remain uncertain because the affected data is poorly described. Neither should be made to resemble the other by adjusting the wording.
The same distinction applies to a proposed score. A GER level can be a reasonable fit while the exact reach remains unknown. The rationale should identify both the supporting relationship and the uncertainty. If important facts could move the classification substantially, leaving it unassigned is preferable to presenting a precise-looking guess.
What a case review should leave behind
A reader should be able to recover the path from source to claim to classification. Record which document supports the event summary, which details remain unresolved, and which statements are the site's own interpretation. When sources disagree, explain the disagreement instead of averaging incompatible accounts into a single story.
Review also includes the language used in headlines and summaries. A cautious paragraph cannot fully repair an exaggerated title. The short description, database row, and detailed case should describe the same event with the same limits. That consistency matters because many readers encounter only one of those views.
Corrections
Record the issue, corrected text, reason, date, source, editor, and affected page. Display substantive corrections on the article and in the central log. Typographical changes may be silent.
Corrections log