Security.
Greybook hosts postmortems of real production incidents and will sit inside real toolchains. Both only work if the defaults protect the people contributing.
Failure reports
- Anonymous by default
- Failure reports publish without attribution. Putting your name on one is opt-in, never the price of contributing.
- Scrubbing checklist
- Submission requires acknowledging a scrubbing checklist: no company names, no bucket/host/repository names, no internal URLs, no dates precise enough to correlate with a public outage.
- Automated scan
- An automated scan flags AWS ARNs, bucket-name patterns, internal TLDs, IP addresses, and email addresses before anything publishes. The scan surfaces findings to the author; it does not silently rewrite.
What the MCP server sends
The planned Greybook MCP server transmits normalized error signatures and environment versions — never source code, prompts, file paths, repository names, secrets, or terminal history. Reporting is opt-in, the schema is shown verbatim at consent time, and every payload the install has ever sent is inspectable locally. Content returned to an agent is wrapped as untrusted reference data, not instructions.
Takedown requests
If a page identifies you, your employer, or your infrastructure — directly or by correlation — email takedown@greybook.io with the page URL and what it exposes. Requests from affected parties are honored quickly: identifying details are removed or the page is unpublished while it is reviewed. Every failure report links this path from the page itself.
Security vulnerabilities in Greybook itself: security@greybook.io.