Traffic Light Protocol (TLP)

The Traffic Light Protocol (TLP) is a set of labels for sharing sensitive information with controlled distribution. Improbus applies TLP 2.0 to every communication and deliverable. TLP classifies who may receive information — it is not a measure of urgency.

TLP is classification, not urgency. These labels control who may receive information. They are not our incident-response urgency levels (Critical / Urgent / Can wait) — for how quickly to reach us during an incident, see the DFIR Emergency page.

The five labels

  • TLP:RED
    For your eyes only. Recipients may not share with anyone outside the immediate, named participants in the originating exchange.
  • TLP:AMBER+STRICT
    Limited distribution within recipient's organisation only. No sharing with clients or external parties.
  • TLP:AMBER
    Limited distribution. Recipients may share with members of their own organisation and clients on a need-to-know basis.
  • TLP:GREEN
    Community-wide. Recipients may share within their community but not via public channels.
  • TLP:CLEAR
    Disclosure not limited. Information may be shared without restriction, subject to standard copyright and licensing rules.

Distribution matrix — who may receive it

At a glance, the audiences each label permits. Need-to-know always applies on top.

Permitted recipients by TLP level
LevelNamed participantsRecipient's orgClientsCommunityPublic
TLP:RED yes no no no no
TLP:AMBER+STRICT yes yes no no no
TLP:AMBER yes yes yes no no
TLP:GREEN yes yes yes yes no
TLP:CLEAR yes yes yes yes yes

Handling — do and don't

Practical handling per level
LevelDoDon't
TLP:REDKeep to the named individuals; share in person or over an encrypted call; store encrypted.Forward, CC others, print to shared trays, or save to shared drives.
TLP:AMBER+STRICTShare within your organisation on a need-to-know basis.Share with clients, partners, or any external party.
TLP:AMBERShare within your organisation and with affected clients, need-to-know.Post to community lists or any public channel.
TLP:GREENShare with peers and partners in your community.Publish on the web, on social media, or to the press.
TLP:CLEARShare freely, including publicly.Strip attribution, copyright, or licensing terms.

Marking and labelling

Every artefact carries its label in 12 pt minimum — at the top of the document and in the email subject — so it stays legible and unambiguous.

  • Email subject[TLP:AMBER] Q3 incident summary — Acme AS
  • Document header and footerTLP:AMBER+STRICT on every page.
  • Filenameacme-incident-2026-07-06_tlp-amber.pdf — a colon isn't filename-safe, so write tlp-amber.

Secure channels per level

How we expect classified material to travel. The bar rises with sensitivity, to protect the information in transit — this is about protection, not how urgently to contact us.

Transport channel by TLP level
LevelChannel we expect
TLP:REDIn person, Signal, or PGP — end-to-end encrypted only.
TLP:AMBER+STRICTPGP-encrypted email.
TLP:AMBERPGP-encrypted email.
TLP:GREENNormal email is acceptable — no personal data.
TLP:CLEARAny channel.

For our key and secure-messaging handles, see the PGP and encrypted-contact page.

How we apply TLP

Every artefact we produce — incident reports, advisory memoranda, technical documentation, emails — carries a TLP label in its header or subject line. We honour the strictest applicable label on anything you send us. If a label is absent, we treat the content as TLP:AMBER (need-to-know) by default, and ask you to confirm.

When you send us material, mark it with the level you require, and use a channel that matches — see the table above.

Aligned with the FIRST TLP 2.0 standard; the definitions above are summarised in our own words for context. TLP 2.0 introduced TLP:CLEAR (formerly WHITE) and TLP:AMBER+STRICT.
π