If I was their security team, I would be fine with them publishing articles about our security set up - as long as it wasn't 100% accurate.
Possibly mention a specific virtualization system, and then run a honeypot version of the above to try and catch directed attacks at it while actually relying on a totally different system...