LOUISIANA CYBER INCIDENT WATCHIndependent. Sourced. Local.
BAYOUBREACH
Menu
BAYOU BREACH · SITE POLICIES

Privacy policy

This policy describes the information used to run Bayou Breach and the choices available to visitors. It applies to this website, not to the independent sources we link.

Effective and last updated: October 9, 2026

The short version

1. Who operates this site

Bayou Breach is a personal, noncommercial Louisiana cybersecurity-awareness project operated by Wes Merriott. For privacy questions, corrections or requests about information under our control, email wmerriott@fortinet.com. Please identify the relevant page and describe your request without sending sensitive records.

2. Information we use

Conversation and correction requests

The conversation form uses the name, organization, selected topic and message you type to prepare an email draft or text you can copy. Entries are held in the page’s temporary state; the application does not submit them to a server or save them in browser storage. Your browser may separately offer autofill or retain page state according to its settings.

If you choose to send the draft through your email service, Wes receives your email address, message and any information you include. That correspondence is handled in email, outside the website, to answer your request, review a correction or continue a conversation. Do not send passwords, API keys, criminal-justice information, protected health information, evidence files or stolen data. An ordinary email is not a secure incident-reporting channel.

Public-source information

The site stores selected public incident summaries, organization names, sector and location context, source URLs, relevant dates, aggregate reported counts, and minimal provider records. Automated records are filtered to reviewed Louisiana public-sector and critical-infrastructure organizations. We do not query visitors’ email addresses for breach exposure or host underlying breached datasets.

Technical information

Hosting and security infrastructure may process IP addresses, request time, requested URL, browser or device information, referrer information, error details and related service logs. These support delivery, availability, abuse prevention and troubleshooting. Do not put sensitive information in a URL or query string. Provider API checks run on the server; your search text and contact-form message are not sent to the connected intelligence providers.

3. Cookies, analytics and technical services

Bayou Breach does not add advertising pixels, session-replay tools or behavioral advertising analytics. The current public application does not require its own visitor account or set application tracking cookies. Hosting and security providers may use essential cookies or other technical mechanisms to operate or protect their services; their behavior is separate from the application code.

The site is hosted through OpenAI Sites using Cloudflare infrastructure. Its current styles request fonts from Google Fonts, which causes your browser to contact Google’s font services and transmit the technical information needed for those requests. You can block external fonts in your browser; fallback system fonts remain available.

The subtle background responds locally to scroll and pointer position. Those coordinates are used for the visual effect and are not logged or transmitted by the application. The site honors your device’s reduced-motion preference.

Relevant provider information: OpenAI privacy policy, Cloudflare privacy policy, and Google Fonts FAQ. These providers may process information in the United States or other countries where they operate.

4. Sharing and external websites

We do not sell visitor contact information or use this website to build advertising audiences. Technical providers process information necessary for their services. Information may also be disclosed when legally required, to respond to valid legal process, or as reasonably necessary to investigate misuse and protect the service or other people.

Source articles, official notices, white papers and product pages open on independently operated websites. Their privacy practices, cookies, access rules and downloads are governed by their operators. Following a link may reveal routine browser and network information to that site. A link is not a privacy or security guarantee.

A correction submission may inform an editorial update. We do not automatically publish your private email or contact details. If attribution or publication of nonpublic material is needed, that should be agreed separately.

5. Retention and security

Public editorial records are retained as part of the historical archive and revised when appropriate. Connected-source caches are replaced or updated by scheduled checks; a last successful snapshot may be retained during an outage. Source timestamps distinguish current checks from historical incidents.

Correspondence may be retained while handling your request and as needed to document a correction, maintain project records or meet applicable obligations. The website does not impose a separate retention schedule on your email provider or hosting providers; their settings and policies also apply. This policy does not promise a fixed deletion period for infrastructure logs outside the operator’s direct control.

The site uses HTTPS, keeps provider credentials on the server, and limits published data to relevant summaries. No internet service, email system or security measure can guarantee absolute confidentiality, availability or protection against unauthorized access.

6. Your choices and requests

You may browse without contacting us, leave the form blank, close the page to discard unsent entries, or use browser controls for cookies, external resources and motion. No email is sent merely by viewing the conversation page or preparing a draft.

To request access to, correction of or deletion of information you supplied directly, contact wmerriott@fortinet.com. Provide enough context to locate the information. We may need reasonable verification before acting. Requests will be considered under applicable law and the need to preserve legitimate records, security information and accurate public-interest reporting. No particular statutory right or exemption is assumed solely because you visited this site.

If a public incident record is inaccurate, provide its URL, the disputed statement and an authoritative public source. We can review material under our control, but cannot edit the originating publisher’s website, search-engine caches or third-party copies. Removal of an accurate public record is not automatic.

7. Children and future changes

The resource is intended for adult professionals and general public awareness. It is not directed to children under 13, and we do not knowingly solicit their personal information. If you believe a child supplied personal information, contact us so the matter can be reviewed.

This policy may change when the site’s features or practices change. The updated policy and effective date will be posted here. Material new collection or sharing practices should be explained before they apply. The terms and conditions explain the limits on using aggregated information.