FIELD GUIDEPublic field guide
Public Interface Data-Handling Guide
A field guide for deciding what must never be submitted through public websites, ordinary email, or unapproved collaboration channels.
01
Treat the interface according to what it is
A public website is an untrusted routing surface. Its appearance, domain name, or use of HTTPS does not establish authorization to transmit sensitive information.
Before sending information, confirm both the sensitivity of the material and the approved channel for that specific exchange.
02
Do not submit
Do not use a public form for classified information, Controlled Unclassified Information, export-controlled technical data, credentials, privileged client information, personal data beyond what is necessary, or operational details.
- Classified information at any level
- CUI or export-controlled technical data
- Credentials, keys, tokens, or recovery material
- Client-confidential, privileged, or operationally sensitive details
03
When the channel is unclear
Send only the minimum non-sensitive routing information through an already approved contact path. Establish the protected exchange first; provide substantive material only after the receiving party confirms the channel and authority.