FIELD GUIDEPublic field guide

Public Interface Data-Handling Guide

A field guide for deciding what must never be submitted through public websites, ordinary email, or unapproved collaboration channels.

Data HandlingOPSECPublic Interfaces

01

Treat the interface according to what it is

A public website is an untrusted routing surface. Its appearance, domain name, or use of HTTPS does not establish authorization to transmit sensitive information.

Before sending information, confirm both the sensitivity of the material and the approved channel for that specific exchange.

02

Do not submit

Do not use a public form for classified information, Controlled Unclassified Information, export-controlled technical data, credentials, privileged client information, personal data beyond what is necessary, or operational details.

  • Classified information at any level
  • CUI or export-controlled technical data
  • Credentials, keys, tokens, or recovery material
  • Client-confidential, privileged, or operationally sensitive details

03

When the channel is unclear

Send only the minimum non-sensitive routing information through an already approved contact path. Establish the protected exchange first; provide substantive material only after the receiving party confirms the channel and authority.