> Editorial Policy
Fact-checking process
Every article is checked against its own source material before publication — the same text the article was drafted from — for claims, quotes, numbers, or links that don't trace back to it. This runs automatically on every story, including a deterministic check on numeric facts (CVE IDs, dollar amounts, percentages) that doesn't rely solely on AI judgment. See our AI Policy for what this catches and what it doesn't.
Confidence levels
Every article displays one of three confidence labels, derived automatically from its sourcing:
- Confirmed — the story is corroborated by a second, independent outlet, or comes from an authoritative primary source (an official advisory, a government feed like CISA/NVD, or a vendor's own security bulletin).
- Developing — reported by a single reputable outlet, not yet independently corroborated.
- Unverified — thin, single-source material with little confirmed substance behind it (this maps to our "Trending" category — a topic being discussed, not a fully-reported story).
A story's label can change: if a second outlet independently reports the same event, we upgrade it to Confirmed and mark it as breaking news.
Sourcing standards
Where a claim in a source article is single-sourced and not yet corroborated, our writing avoids stating it as flat, established fact — you'll see attributive phrasing ("X reported that...", "according to Y...") rather than a bare assertion. Every article lists its sources, with official advisories, government feeds, and vendor statements favored over secondhand summaries when both are available.
Anonymous sources
Xploitwire's pipeline draws from published reporting and structured public data (CVE records, security advisories), not from direct anonymous tips. Where an underlying source article itself relies on an anonymous source, we preserve that sourcing transparently rather than presenting the claim as independently confirmed.
High-risk stories
Stories involving named individuals, accusations, or legal action are flagged for a human follow-up checklist — requesting comment from the affected party and, where appropriate, legal review. This follow-up happens after publication (see our AI Policy for why), and any response received is added to the story.
Headline standards
Headlines are written to be precise rather than dramatic — no unearned superlatives, no implied urgency the underlying reporting doesn't support.
Corrections
See our dedicated Corrections Policy for how and when we log corrections publicly.