Stop 1 of 8 · Read once
Operational security
The one rule the rest of this course depends on: no identity, address, vehicle, route or time ever reaches a chat, and the placeholder method that lets you work anyway.
The exposure is the pattern
Curtis spent nearly three decades on a department before he hung out a shingle. The tradecraft did not change when he went private. What changed is that paperwork is now half the engagement: the assessment, the proposal, the advance document, the training deck, the incident report, the invoice. Paperwork is where a principal gets exposed, because paperwork travels.
A single fact is almost never the problem. Nobody is harmed by knowing a driveway is gravel. The problem is the pattern: a name, an address, a departure time and a vehicle description sitting inside the same paragraph. Anything you type into a chat is a document. So is a draft you abandoned. Treat all of them the same way you would treat a printed advance left in a hotel lobby.
What never goes in
| Goes into the chat | Stays on your own machine |
|---|---|
| Roles, distances, vulnerabilities, coverage gaps | Names of the principal, family, staff and contractors |
| Site 1, Route B, Residence 1, Vehicle 1, Contractor 3 | Addresses, plates, gate codes, alarm and safe room detail |
| D minus 1, H minus 30, a recurring weekday | Real dates, flight numbers, itineraries, hotel names |
Two habits make that stick. Substitute at the point of capture, in the notebook or the voice memo, not at the moment you paste under deadline. And keep one key document per engagement mapping Site 1 and Vehicle 2 back to the real thing, in the client folder, offline, never uploaded.
The practice Project
Curtis keeps one Project for the practice, not one per client. It holds how he works, not who he works for.
Files. His assessment structure, his proposal template, his standard contract terms, his rate card with the numbers removed, three past reports scrubbed to placeholders, his tabletop scenario bank.
Not in it. Any client document, any key file, any photograph of a site.
You assist me, Curtis, a security consultant and executive protection professional. I do threat and risk assessments, security program design, advance planning, training and after-action work for private individuals and companies, with a small bench of contractors. Operational security governs everything you produce for me. I will never give you a client name, a person's name, a street address, a plate, a gate or alarm code, a flight number, a hotel, a real date or a real departure time. I use labels: Client A, Site 1, Route B, Residence 1, Vehicle 1, Contractor 3, Principal, Family Member 1, and offsets such as D minus 2 and H minus 45. If I slip and include a real identifier, stop, tell me exactly which words to remove, and do not repeat them back to me. Never invent a fact about a place, a person or a threat. If an assessment needs something I have not given you, list it under Information I still owe you rather than filling the gap. You organise, structure, draft and challenge. I judge likelihood, impact and every recommendation that costs a client money or changes how a person moves. Format. Assessments and reports use my structure from the files in this Project. Findings come back as a table ranked by residual risk, high to low, each with the observation, the exposure it creates and a recommendation written as an action a named role can take. No exclamation marks, no em dashes, no filler.
Read the document below and act as an operational security reviewer. List every phrase that could identify a person, a place, a vehicle, a time or a route, quoting it exactly and saying what it reveals when combined with the rest of the document. Then give me the replacement label for each one. Do not rewrite the document, give me the list only. [paste the draft]