Each citation below identifies the original document and the exact provision or passage supporting a published claim. A primary document does not automatically earn the strongest evidence tier. Official records resolve to third-party reporting, provider publications remain self-reported, audits require an independent audit report, and directly tested evidence requires a Cunicula test record.
Machine-readable records are available from /api/v1/primary-sources and the site feed.
Releases: GrapheneOS 2026091000, 2026091700 and 2026091900
- Issuing body
- GrapheneOS
- Publication date
- Retrieved
- Document type
- transparency-report
- Evidence tier
- SELF-REPORTED
- Content hash
sha256:91e8f131994ffa05 17c761d6 38abb92f 5bcc09f2 bcbd1147 67a403c1 51b6a2d8 - Copies
- Official document · Archived copy
Supported claims
GrapheneOS release 2026091000 reports the full 2026-09-01 security patch level.
full 2026-09-01 security patch level
Attached to: Article: grapheneos-privacy-phone-guide
GrapheneOS release 2026091700 reports a Pixel cellular modem firmware backport from Android 17 QPR1.
Location: 2026091700: Changes since the 2026091000 release, PDF page 1
Pixels: backport cellular modem firmware from Android 17 QPR1
Attached to: Article: grapheneos-privacy-phone-guide
License Plate Reader Policy
- Issuing body
- Flock Safety
- Publication date
- Retrieved
- Document type
- transparency-report
- Evidence tier
- SELF-REPORTED
- Content hash
sha256:c92398d62608b2c2 49021bbf 86484959 b6f0191c 26b215f6 cc83d26a 114d3182 - Copies
- Official document · Archived copy
Supported claims
Flock's LPR policy says queries are stored for auditing with user, date, time, purpose and search elements; this is not verification of OS Investigate logging.
Location: Authorized Users and Access, PDF page 1
All queries of the LPR system are stored for auditing purposes, including: Username Date Time Purpose of query License plate and other elements used to query the system
Attached to: Article: license-plate-readers-traffic-enforcement
Flock states a seven-day default deletion period with customer law or policy exceptions; the policy expressly governs its LPR system, not every investigative record.
Location: Data Retention and Privacy (page labelled June 30; wording retrieved September 21), PDF page 1
LPR data is hard deleted on a rolling 7-day basis by default; this may be increased or decreased on a case-by-case basis if a different schedule is required by a customer’s law or policy. Privacy: This policy governs the LPR system provided by Flock Safety.
Attached to: Article: license-plate-readers-traffic-enforcement
Security incident at Brevo, our third-party email provider
- Issuing body
- Trezor
- Publication date
- Retrieved
- Document type
- transparency-report
- Evidence tier
- SELF-REPORTED
- Content hash
sha256:e174a3abc49460f2 4aea0ff0 48e281a6 d6b9fe79 49cf5b00 b7b550cc dc369bb4 - Copies
- Official document · Archived copy
Supported claims
Trezor's September 17 update reports 347,149 marketing email contacts exported through Brevo's API.
Location: Updated September 17, 2026, PDF page 1
Brevo has confirmed that 347,149 marketing email contacts were exported from our list through the API during this incident.
Attached to: Service: trezor, field incidents
Trezor says its product, wallet and account systems were not affected by the Brevo incident.
Location: Was Trezor itself hacked?, PDF page 1
No Trezor product, wallet, or account system was affected.
Attached to: Service: trezor, field incidents
Trezor describes a phishing email linking to an app that asked for a wallet backup, not a verified hardware repair.
Location: Phishing email description, PDF page 1
The phishing email sent from our account contained a malicious link that prompted users to download an app that asked users to enter their wallet backup.
Attached to: Service: trezor, field incidents
Recent customer data exposed in shipping provider incident
- Issuing body
- Trezor
- Publication date
- Retrieved
- Document type
- transparency-report
- Evidence tier
- SELF-REPORTED
- Content hash
sha256:53efa089aabc2bf3 bea34d06 df8eb646 a961acc8 1560c98d a1a8d38d 621d568f - Copies
- Official document · Archived copy
Supported claims
Trezor's updated ShipMonk disclosure states that 80,689 customers are affected by that incident.
80,689 customers are affected.
Attached to: Service: trezor, field incidents
Trezor's September 4 update adds approximately 67,000 US customers with full name, email, phone, shipping-address and order-number exposure.
Location: Updated September 4, 2026, PDF page 1
This leaked data affects another approximately 67,000 US customers and includes full exposure (name, email, phone number, shipping address, order number).
Attached to: Service: trezor, field incidents
Trezor says ShipMonk retained data despite confirmation of deletion; this is the customer's account, not an independent audit.
Location: Updated September 4, 2026, PDF page 1
We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.
Attached to: Service: trezor, field incidents
Attacker gained access to client accounts
- Issuing body
- Brevo
- Publication date
- Retrieved
- Document type
- transparency-report
- Evidence tier
- SELF-REPORTED
- Content hash
sha256:47425f4490e004f7 bbb073bc 6302773f 31c6271e 59f2eaca abbcb0d6 7a1fd6f9 - Copies
- Official document · Archived copy
Supported claims
Brevo's postmortem reports 138 platform accounts accessed, distinct from Trezor's exported newsletter-contact count.
Location: What happened, PDF page 1
On September 10th at 6:30 AM UTC we identified a security issue where an attacker exploited a flaw in the way Brevo handles SAML SSO to gain access to 138 Brevo accounts.
Attached to: Service: trezor, field incidents
Brevo says the phishing messages passed ordinary email authentication because they used legitimate sending infrastructure.
Location: If you have received some of these emails, PDF page 1
These messages were sent through legitimate infrastructure, so they passed the usual email authentication checks and looked genuine.
Attached to: Service: trezor, field incidents
Shutting down our public encrypted DNS servers and sponsoring Quad9 instead
- Issuing body
- Mullvad VPN
- Publication date
- Retrieved
- Document type
- transparency-report
- Evidence tier
- SELF-REPORTED
- Content hash
sha256:3a5d9c626cb8eedb a19547f3 afc90fa9 bdb09e8f 43c25f18 25f517d8 dc97a6aa - Copies
- Official document · Archived copy
Supported claims
Mullvad asks manually configured public DoH users to switch before November 2, 2026.
Location: Migrating to Quad9, PDF page 1
If you have manually configured our DoH servers, switch before November 2nd 2026.
Attached to: Service: mullvad-dns, field privacyWarning
Mullvad distinguishes its VPN internal DNS from the public encrypted DNS service being retired.
Location: Opening paragraph, PDF page 1
They are unnecessary when using Mullvad VPN — traffic is already encrypted and Mullvad VPN's internal DNS handles all queries.
Attached to: Article: private-dns-setup-guide
Mullvad Browser default and included ad-blocking DoH settings will automatically migrate to Quad9.
Location: Mullvad Browser, PDF page 1
Mullvad Browser users who have kept the default DoH settings or the included ad blocking one, will automatically be migrated to Quad9.
Attached to: Article: private-dns-setup-guide
Mullvad says customized browser DoH settings will not be changed automatically.
Location: Mullvad Browser, PDF page 1
If you have customized the DoH, we will not change them.
Attached to: Article: private-dns-setup-guide
Implementation Rules for Article 43 of the Law of the People's Republic of China on Safeguarding National Security in the Hong Kong Special Administrative Region
- Issuing body
- Chief Executive in conjunction with the Committee for Safeguarding National Security of the Hong Kong Special Administrative Region
- Hosting body
- Legislative Council of the Hong Kong Special Administrative Region
- Publication date
- Retrieved
- Document type
- regulation
- Evidence tier
- THIRD-PARTY REPORTED
- Content hash
sha256:409c3acb01c81a53 a4ffac02 9c7a63ff b40919bf 8979416f ea64864d 680b104a - Copies
- Official document · Archived copy
Supported claims
The 2026 amendments to Instrument A303 commenced on 23 March 2026.
Location: Rule 1, Editorial Note, PDF page 6
For the commencement arrangements under the subsequent amendments to these Implementation Rules, please see L.N. 166 of 2023 (commencement date: 15 December 2023) and L.N. 27 of 2026 (commencement date: 23 March 2026).
Attached to: Article: hong-kong-device-password-law
A police officer exercising the electronic-equipment search power may require a specified person to provide a necessary password or decryption method.
Location: Schedule 1, Part 1, section 4(2)(a), PDF page 11
(a) require a specified person to provide the police officer with any password, or other decryption method, that is necessary;
Attached to: Article: hong-kong-device-password-law
The same power may require other reasonable and necessary information or assistance.
Location: Schedule 1, Part 1, section 4(2)(b), PDF page 11
(b) require a specified person to provide the police officer with any other reasonable and necessary information or assistance,
Attached to: Article: hong-kong-device-password-law
Failure to comply can result in a HK$100,000 fine and one year of imprisonment on conviction on indictment.
Location: Schedule 1, Part 1, section 5(1), PDF page 12
If a person fails to comply with a requirement imposed under section 4(2) of this Schedule, the person commits an offence and is liable on conviction on indictment to a fine of $100,000 and to imprisonment for 1 year.
Attached to: Article: hong-kong-device-password-law
A person charged with the noncompliance offence may establish a defence by showing a reasonable excuse for failing to comply.
Location: Schedule 1, Part 1, section 5(3), PDF page 12
It is a defence for a person charged with an offence under subsection (1) to establish that the person had a reasonable excuse for failing to comply with the requirement.
Attached to: Article: hong-kong-device-password-law
Knowingly or recklessly providing materially false or misleading information can result in a HK$500,000 fine and three years of imprisonment on conviction on indictment.
Location: Schedule 1, Part 1, section 6, PDF page 13
(a) provides any information, or makes a statement, that the person knows to be false or misleading in a material particular; or (b) recklessly provides any information, or recklessly makes a statement, that is false or misleading in a material particular, the person commits an offence and is liable on conviction on indictment to a fine of $500,000 and to imprisonment for 3 years.
Attached to: Article: hong-kong-device-password-law
The ordinary warrant route requires a police officer to apply to a magistrate by information on oath.
Location: Schedule 1, Part 1, section 2(1), PDF page 8
A police officer may, for investigation of an offence endangering national security, apply to a magistrate by information on oath for a warrant under this section.
Attached to: Article: hong-kong-device-password-law
The section 3(1) warrantless route requires satisfaction by a police officer not below the rank of Assistant Commissioner.
Location: Schedule 1, Part 1, section 3(1), PDF page 10
If a police officer not below the rank of Assistant Commissioner of Police is satisfied that
Attached to: Article: hong-kong-device-password-law
The section 3(1) warrantless route also requires that obtaining a warrant would not be reasonably practicable.
Location: Schedule 1, Part 1, section 3(1)(c), PDF page 10
for any reason it would not be reasonably practicable to obtain a warrant, the police officer, or another police officer authorized by the police officer, may exercise one or more of the powers under section 2(3) of this Schedule for investigation of an offence endangering national security without a warrant.
Attached to: Article: hong-kong-device-password-law
Rule 2(3) adds Customs and Excise Service members to the officials who may exercise Schedule 3 property freezing, restraint, confiscation, and forfeiture powers.
Location: Rule 2(3), PDF page 6
The Secretary for Justice, the Secretary for Security, a member of the Customs and Excise Service or a police officer may, in accordance with Schedule 3, exercise the power to freeze, restrain, confiscate and forfeit property relating to the commission of an offence endangering national security.
Attached to: Article: hong-kong-device-password-law