securityportal
Sign in

Sources & method

Transparency on what feeds the assistant and the editorial corpus, and how we verify what it tells you.

How answers are built

The assistant does not answer from general knowledge: every question is matched by semantic similarity (embeddings) against a base of indexed passages, and the model is instructed to answer only from the retrieved passages, citing them as [Source N]. If nothing relevant is found, it says so instead of guessing.

The knowledge base is built from three streams: original editorial content (guides, glossaries, checklists) written and reviewed by us; an automated nightly crawl limited to the whitelisted official sources below; and editorial spin-offs (e.g. the CyberWatch digest) that go through the same editorial review before being published.

Whitelisted official sources

Only these domains are crawled automatically, and only under an open licence or as public-domain institutional content — never behind a paywall or a restrictive licence.

Cyber security

  • cert-agid.gov.it
  • agid.gov.it
  • enisa.europa.eu
  • cisa.gov
  • nist.gov
  • attack.mitre.org
  • owasp.org

Physical security

  • protezionecivile.gov.it

Travel security

  • gov.uk
  • smartraveller.gov.au

Information security

  • garanteprivacy.it
  • edpb.europa.eu
  • eur-lex.europa.eu
  • gazzettaufficiale.it
  • europarl.europa.eu

Attribution & licences

Some sources require a specific attribution notice, shown next to the cited passage in chat and in the audit log:

What we deliberately leave out

Sources cited but never crawled. Some authoritative sources are never crawled automatically: we only use them as references in our editorial content, respecting each one’s conditions. Today they are:

This list only changes with a documented decision: if a source enters or leaves the whitelist, this page is updated.

Every crawl request respects the target site’s robots.txt (crawl-delay included) and a static safety list of disallowed paths, even when robots.txt itself cannot be fetched.

The limits of this method

Source grounding reduces errors, it does not eliminate them: the model can misunderstand a passage, combine sources incorrectly or translate imprecisely. The assistant only knows what has been indexed: the absence of an answer does not mean the information does not exist. That is why answers always cite their sources — the correct way to use them is to verify them — and answer quality is periodically checked on samples with human review. How the system works, what it records and what responsibilities remain with its users is described in the AI notice.

Reports & corrections

If you believe that Portal content improperly reproduces material you hold rights to, contains an error or a missing attribution, or concerns you inaccurately, write to compliance@securityportal.it. To help us act quickly, include: who you are and how to reach you, the address (URL) of the content, what you contest and — for rights violations — on what basis. We confirm receipt within 5 working days and give a reasoned reply normally within 10 working days; in clear-cut cases the content is suspended immediately, pending assessment. For requests about personal data, the privacy notice applies.

General questions about a source or the method: info@securityportal.it