-
How to sponsor bug bounty hunters without compromising their research
Bug bounty hunters are credible because they answer to no one but the bug. What a brand can fairly buy,…
-
Affiliate links and discount codes in security creator content
An affiliate link is a paid arrangement even when no money changes hands up front, and a security audience treats…
-
Embargoes and NDAs: what a creator can say about your product, and when
Most security campaigns involve information that is not public yet, and most of them handle it with one line in…
-
Disclosure when the format is not a post: livestreams, Discord, and GitHub
Most disclosure guidance assumes a post, and security creators publish in livestreams, Discord servers, GitHub READMEs, and conference talks. Where…
-
Equity, advisory seats, and free access: the conflicts nobody discloses
Payment is the easiest conflict to disclose and the least interesting one. Advisory seats, equity, permanent licences, and paid travel…
-
If a sponsored post was written with AI, does the audience need to know?
Every brand and creator is now using AI somewhere in the drafting process, and almost nobody has agreed on what…
-
Sponsorships when you have a day job in security
Most security creators are practitioners first, and the day job is exactly what makes them worth sponsoring. It is also…
-
Who is accountable when a sponsored security claim is wrong
A sponsored post makes a specific claim about what a product blocks, and the claim turns out to be wrong.…
-
The ethics of sponsored vulnerability content
Vulnerability research earns trust because it appears to answer to no one, which is exactly what a sponsorship can compromise.…
-
Disclosure beyond the FTC: what EU and UK rules mean for security creators
The FTC is only one regulator, and your security audience is global. A plain guide to UK ASA expectations, EU…