LOUISIANA CYBER INCIDENT WATCHIndependent. Sourced. Local.
BAYOUBREACH
Menu
BAYOU BREACH · SITE POLICIES

Terms & conditions

Bayou Breach consolidates public information to support cybersecurity awareness. These terms explain how to use that information responsibly and what the service does not establish.

Effective and last updated: October 9, 2026

The short version

1. Purpose and operator

These terms apply to Bayou Breach, a personal, noncommercial awareness project operated by Wes Merriott. By using the site, you agree to these conditions to the extent they are enforceable under applicable law. If you do not agree, discontinue use. The site is not a government agency, law-enforcement reporting portal, data-breach notification authority or official Fortinet website.

The focus is cyber incidents and relevant public information concerning Louisiana public agencies, law enforcement and critical infrastructure. Inclusion does not imply wrongdoing, negligence, endorsement, criminal responsibility or a statement about an organization’s current security posture.

2. Evidence, accuracy and source limitations

Information comes from public statements, official records, journalism, research and third-party intelligence services. We summarize and classify it, but do not control the original sources or guarantee their accuracy, completeness, continuing availability or timeliness. Sources may conflict, be corrected, use different definitions or become unavailable.

An attacker claim remains an allegation unless the specific fact is independently established. An organization can acknowledge disruption without confirming theft, a ransom demand, a named attacker or a particular entry point. Confirmation of an event does not confirm every associated claim. Read the evidence labels and original source before repeating a claim.

Occurrence, discovery, disclosure, publication, indexing and provider-observation dates are different. Automated notices are separate from curated incident briefs. An organization match does not prove two records concern the same event. Aggregate counts may cover multiple states, accounts or reporting populations; they are not automatically Louisiana resident counts. A blank parish, absent record or empty source result does not establish that no incident occurred.

Feeds can be delayed, incomplete, rate-limited or interrupted. The last successful snapshot may remain visible during a failed refresh. Vulnerability scores describe a CVE or broader exploitation context, not a verified weakness or probability of compromise at a named agency. The methodology explains these distinctions.

3. No professional advice or emergency service

The material supports education and discussion. It is not legal advice, a forensic opinion, an audit, an individualized security design, a compliance certification, an insurance determination or a substitute for qualified incident-response assistance. No consulting, fiduciary, attorney-client or other professional relationship arises merely from browsing, preparing an email or requesting a conversation.

Do not use the site as your sole basis for operational, purchasing, investigative or public-safety decisions. Verify current information with the organization, original publisher and your qualified advisers. In an active incident, use established emergency, incident-response, insurer and law-enforcement channels. This site and its contact mailbox are not continuously monitored for emergencies.

This resource is not a consumer-reporting service. Do not use it to make employment, credit, housing, insurance eligibility or other regulated decisions about an individual, or to identify or target people whose information may have been exposed.

4. Security gaps, products and affiliation

A “security gap” is an area to evaluate, not a finding that a named victim lacked a product or failed to exercise reasonable care. Recommendations describe how a present-day control could help under stated conditions. They do not guarantee that any product would have prevented a historical incident, blocked an unknown exploit or recovered particular data.

Wes Merriott works in local-government sales at Fortinet. That professional relationship is relevant to the Fortinet examples featured on the Security Gaps page. Bayou Breach is his personal project; views and assessments presented here are not official statements from Fortinet or the affected organizations.

Capabilities, models, support, licensing and documentation may change. Validate compatibility, staffing, traffic visibility, capacity, policy configuration and operational safety before selecting or deploying a control. A publicly accessible vendor white paper is vendor-authored material, not an independent comparative test. Other vendors or approaches may provide suitable controls. No purchase or professional service is offered or contracted through this website.

5. Original-source rights and attribution

Bayou Breach’s original text and visual presentation and third-party material remain subject to their respective owners’ rights. Organization names and trademarks identify their owners and do not imply sponsorship. Source links and concise summaries are provided for reference; the site does not confer ownership of linked articles, documents, data or logos.

You may link to the site and share short attributed excerpts for lawful awareness purposes, subject to applicable copyright rules and any source-specific license. Preserve source attribution, uncertainty labels, dates and relevant qualifications. Do not remove an unverified label, misrepresent an excerpt as an official finding, or imply endorsement.

Public access to a source or white paper is not the same as a public-domain or open-source license. Obtain any necessary permission before reproducing full content, bulk republishing provider data, reselling it, or using it outside its permitted license. Provider access granted to Bayou Breach is not transferred to visitors. HIBP public catalog material is attributed under its applicable Creative Commons license; other sources have their own terms. See Sources & reports and each linked publisher.

The site does not host or offer stolen files, exposed passwords, ransomware samples or direct links for downloading stolen datasets. Links to independent websites do not warrant the accuracy, security or availability of those websites.

6. Acceptable use

Use the resource for lawful research, awareness and discussion. Do not disrupt availability, evade access restrictions or rate limits, harvest contact information for unsolicited messages, impersonate the operator or an affected agency, upload or send malware or stolen records, or use this material to harass, threaten, extort or facilitate unauthorized access.

Automated access must respect technical controls, source rights and service availability. The site does not grant access to its provider credentials or a bulk redistribution API. We may limit abusive traffic or discontinue features as reasonably needed to protect the service and its users.

7. Corrections and submissions

To suggest a correction, provide the page URL, the exact statement you dispute and a supporting public source through Request conversation or wmerriott@fortinet.com. We review credible evidence but do not promise an outcome or a response deadline. Corrections to our summary do not alter the original publisher’s record.

Only send information you have the right to share. Do not send confidential evidence, sensitive personal records, credentials or illegally obtained material. By submitting a nonconfidential correction or source suggestion, you permit us to review it and use the relevant facts to maintain the site. This is not an automatic license to publish your private correspondence or identifying contact details.

The conversation form prepares a draft for your own email service. You review and send it. The website does not itself transmit the message or guarantee email delivery. Information handling is described in the privacy policy.

8. Availability, warranties and liability

To the extent permitted by applicable law, the website and its content are provided “as is” and “as available,” without warranties of accuracy, completeness, continuous availability, fitness for a particular purpose, noninfringement or freedom from errors. No statement here promises that a security product or the site itself will prevent all attacks.

To the extent permitted by applicable law, the operator is not liable for indirect, incidental, special or consequential loss, lost profits, business interruption or loss of data resulting from reliance on aggregated content, unavailable feeds or linked third-party resources. You remain responsible for independently verifying information and deciding how to use it.

These limitations do not exclude or limit liability for intentional or gross fault, physical injury, fraud, or any liability or rights that cannot lawfully be excluded or limited. Applicable protections prevail over conflicting language. No clause should be read as waiving a right that the law makes nonwaivable.

9. Changes, governing law and contact

The site, source coverage and these terms may change. Revised terms will be posted with an updated date and apply prospectively, subject to applicable law. Changes do not retroactively remove accrued rights. If a provision is unenforceable, the remaining provisions continue to apply to the extent allowed by law.

Louisiana law and applicable United States federal law govern these terms, subject to any mandatory protections that apply to you. These terms do not impose mandatory arbitration or a waiver of class, jury or other nonwaivable rights. Questions about use, source rights, privacy or corrections may be sent to wmerriott@fortinet.com.