Most disclosure guidance assumes a post. A caption, a hashtag, a line at the top of a video description. Security creators publish in formats that guidance never had in mind: a four hour CTF livestream, a Discord server, a tool on GitHub with a sponsor’s logo in the README, a conference talk with a vendor’s name on the closing slide.
We covered the standard formats in our earlier #ad guide. This post is about the ones that fall between the lines. None of it is legal advice; it is how we apply the principle in practice.
The principle behind every format
The FTC does not publish a rule per platform. The principle is that a material connection between a creator and a brand has to be disclosed clearly and conspicuously, in the same medium as the endorsement itself. UK and EU regulators land in roughly the same place. So the question for any new format is not “is there a rule for this” but “would a reasonable person consuming this understand that a brand paid for it, before they act on it?”
That reframing does most of the work. The rest is mechanics.
Livestreams
Nobody watches a livestream from the start. A viewer who joins at minute ninety of a sponsored CTF walkthrough has no idea what was said at minute one. A single verbal disclosure at the top fails for everyone who arrived later, which is most of the audience.
What works in practice:
- Say it out loud at the start and repeat it at natural breaks, such as every time you switch challenges.
- Keep a persistent on-screen element for the sponsored segment. A small “Sponsored by X” overlay in a corner costs nothing and covers late joiners.
- Put the disclosure in the stream title and description too, but treat those as extras. Viewers in an embedded player may never see either.
- If only part of the stream is sponsored, say when it starts and when it ends. A ten minute paid segment should not hide inside an unlabelled two hour stream.
The recording matters as much as the live event, because most of a technical stream’s views arrive after it ends. Whatever overlay you used live needs to survive into the VOD.
Discord and community servers
A creator’s Discord is where the trust lives. A sponsor message in that room reads as a personal recommendation from someone members talk to daily, which is exactly why it has to be labelled.
The common mistake is the pinned message. One announcement pinned in the general channel on the day the deal was signed does not disclose anything to a member reading a product recommendation in the tooling channel three weeks later. Each message that promotes the sponsor needs its own disclosure, in the message itself, not in a channel description that nobody opens.
If a brand gets its own channel in a creator’s server, it needs a clear name and a pinned explanation of the relationship. If brand staff post in the server, they should carry a role that says who they work for. A vendor employee answering questions under a plain username is the kind of thing that ends a community’s trust in one screenshot.
GitHub, tools, and READMEs
Security creators ship code. A sponsor’s logo in a README is a familiar sight and usually an honest disclosure of an open source sponsorship. It gets murkier when the money is tied to specific content: a tutorial that uses the sponsor’s API when a free alternative exists, or a demo repository built for the campaign.
Our reading: if a brand paid for a tutorial, a sample repo, or an integration guide, the README and any accompanying post should say so at the top, not in a footer. “This project was built as part of a paid partnership with X” is enough. A badge on the repo does not cover a separate article that recommends the product without saying why.
Commit messages, changelogs, and code comments do not count as disclosure. Nobody reads them before deciding whether to trust a recommendation.
Conference talks and workshops
A talk accepted through a CFP, where a sponsor paid for travel or the speaker works for a vendor mentioned in the talk, is a material connection worth a line on the first slide. A sponsored slot the vendor bought from the event is a paid presentation, and the audience should know that before the speaker starts, not when a logo appears on the closing slide.
If a sponsored talk is later posted as a video, the disclosure needs to be in the video itself, not only in the event programme.
What we build into a campaign
On Influous, disclosure is on by default in every campaign. The brief asks which formats the content will run in, and the disclosure requirement is written per format rather than as one generic line. We are pre-launch, so this is a design rather than a track record, but the principle is simple. A disclosure the audience cannot see is not a disclosure. The format changes where it goes, never whether it goes.
If you are a creator working across formats like these, you can apply to join Influous. If you are a brand and unsure how a format should be labelled, email info@influous.io and we will tell you what we would do.