Editorial policy
The methodology explains how the system works, step by step. This page explains under what criteria and commitments it operates. They're separate documents on purpose: the first can be verified by watching the site's behavior; the second is a set of rules we've taken on, and that you can hold us to.
1. What we cover
Cybersecurity news relevant to whoever is responsible for an organization's technology: vulnerabilities and patches, ransomware, data breaches, phishing and fraud, threat-group intelligence, tools, and regulation. Explicit priority is given to what's relevant to Mexico and Latin America — this is still the site's original audience, even as this English edition grows.
What we don't cover:
- Instructions for exploiting vulnerabilities, attack code, or reproducible steps for an offensive technique. We report that a flaw exists and its impact, never how to take advantage of it.
- Personal data from breaches, even if it's circulating publicly.
- Links to illegal marketplaces, cybercrime forums, or leak sites.
- Rumors without an identifiable source.
2. How what gets published is selected
Selection is automatic and algorithmic: the system reads the public feeds of six specialized outlets and processes what it finds, with no one choosing story by story. This has an important, verifiable consequence: no person can decide that a specific story gets published, featured, or left out. The list of sources and the processing rules are published in the methodology.
There is after-the-fact oversight. If a report is found with a serious error, inappropriate content, or a summary that misrepresents the source, it's removed or corrected — per section 6 of this page. That authority is used to fix mistakes, never to favor or harm anyone.
3. Use of artificial intelligence
All the content on this site is written by a language model. It's not support or assistance: it's the actual author of the summaries, the headlines, and the Defense Paths. That's why there are no bylines on the reports, and there won't be as long as this stays true.
The limits placed on the system, which you can verify by reading the site:
- It doesn't invent facts that aren't in the source. If the original story doesn't give a detail, the summary doesn't supply one.
- It doesn't reproduce the original text: it writes its own, shorter summary, with attribution and a link.
- Severity scores (CVSS) are taken from the NVD's official catalog when they exist; when estimated, they're marked with an asterisk.
- Threat groups are named against a closed catalog, not from memory.
The AI gets things wrong. We're not asking you to trust that it won't: that's why we publish the full methodology, mark what's estimated, always link to the original source, and keep the corrections policy in section 6.
4. Independence and conflicts of interest
InfoSecDash is published by FIXTEAM, S.A. de C.V., a technology consulting and engineering firm that provides IT security services to companies. The site reports on the same market that company operates in, and also serves as a demonstration of what FixiTeam can build. That relationship is explained in About.
How that conflict is governed:
- Story selection is automatic. There's no mechanism by which a commercial interest could promote or suppress coverage.
- No vendor, product, or service gets preferential treatment for being a FixiTeam partner, client, or competitor.
- If content is ever published in which FixiTeam has a direct interest, it will be disclosed within the report itself.
- The site doesn't sell security services. When a report suggests checking or updating something, it's not a disguised sales pitch.
5. Advertising
InfoSecDash sells advertising. It's one of the ways this site sustains itself, and the spaces are open to any company that wants to advertise — just write to us. Whether a space is paid changes nothing about what follows: the rules below apply always, to every ad, whether it belongs to a client or to us.
- Every ad is visibly labeled with the word "Advertisement" and kept separate from editorial content.
- Payment for coverage is not accepted. No advertiser can buy a story, influence what gets published, or get something removed because it's inconvenient for them. Paying for a space buys exactly that: a space.
- Advertisers don't get early access to content or any right of review.
- If paid content ever exists, it will be unambiguously labeled as such, never disguised as a story.
- When the advertiser is FixiTeam, a partner of ours, or one of our own products, it's named as such below — never left to look like an outside client.
Current status of the ad spaces
Updated August 2, 2026. Today the three occupied spaces are not paid and none corresponds to an outside advertiser: they belong to FixiTeam (this site's publisher), Servelco (a company we collaborate with on AI development), and SIGIA (the product both companies are developing together). They're there to verify that the ad system works correctly. We say this because a reader who sees an ad from the publisher itself has a right to know it isn't a paying client — it's us. This paragraph gets updated whenever the occupancy of these spaces changes.
6. Corrections policy
An automated site is going to make mistakes, and the commitment isn't to never make them — it's to fix them fast and in plain sight.
What we correct. Incorrect facts, summaries that misrepresent the original source, wrong attributions, mis-assigned severity scores, wrong classifications, and broken links.
How to report an error. Write to us from the contact page with the story's link and what the problem is. If you're the organization or person mentioned in the report, say so — those reports get handled first.
How long it takes. We commit to reviewing any report within a maximum of five business days. A serious error — false information that could lead someone to make a bad security decision — is handled as soon as it's found.
How it gets corrected. This is the part that matters:
- Substantive corrections are made visible on the story itself, with the date and a description of what was corrected. Nothing is edited silently.
- If an error is serious enough that the whole story is no longer trustworthy, the story is taken down, and that removal is explained rather than made to disappear.
- Minor corrections — a typo, a broken link — are fixed without a note, because they don't change what the story says.
- When the error comes from the original source and not from our summary, we flag it and point back to the outlet.
7. Sources and attribution
Every report always links to the original article and names the outlet. We don't republish anyone's text: what's published is our own, shorter summary. The full list of sources, and an explanation of what we take from them and what we don't, is in the methodology. If you run an outlet and would rather we didn't include your stories, write to us and we'll remove them, no questions asked.
8. Changes to this policy
When this policy changes substantively, the date in the header will be updated. It is not modified retroactively to justify something that was already published.