For any correction, the desk asks the reader to send a short note with the URL of the brief, the original statement, the proposed correction and a link to a canonical source that supports the correction. The desk does not publish a correction based on the reader's memory alone — the canonical source is the only signal that earns the correction a stand-alone note.
For any security report, the desk asks for the URL of the third-party surface, the date the reader first saw the surface, the device and browser used and a screenshot if possible. The desk treats security reports as a priority and replies within a working day.