Greybook
+ NewSign in

Security.

Greybook hosts postmortems of real production incidents and will sit inside real toolchains. Both only work if the defaults protect the people contributing.

Failure reports

Anonymous by default
Failure reports publish without attribution. Putting your name on one is opt-in, never the price of contributing.
Scrubbing checklist
Submission requires acknowledging a scrubbing checklist: no company names, no bucket/host/repository names, no internal URLs, no dates precise enough to correlate with a public outage.
Automated scan
An automated scan flags AWS ARNs, bucket-name patterns, internal TLDs, IP addresses, and email addresses before anything publishes. The scan surfaces findings to the author; it does not silently rewrite.

What the MCP server sends

The planned Greybook MCP server transmits normalized error signatures and environment versions — never source code, prompts, file paths, repository names, secrets, or terminal history. Reporting is opt-in, the schema is shown verbatim at consent time, and every payload the install has ever sent is inspectable locally. Content returned to an agent is wrapped as untrusted reference data, not instructions.

Takedown requests

If a page identifies you, your employer, or your infrastructure — directly or by correlation — email takedown@greybook.io with the page URL and what it exposes. Requests from affected parties are honored quickly: identifying details are removed or the page is unpublished while it is reviewed. Every failure report links this path from the page itself.

Security vulnerabilities in Greybook itself: security@greybook.io.