Civil society starts here¶
For staff and long-term volunteers at advocacy groups, service NGOs, research organizations, and local community groups. An organization's position differs from an individual's: what you are protecting usually belongs to someone else — donors, service users, the employee willing to speak — and they are the ones who carry the consequences.
Every link below points at a page that already exists here. The twenty-minute pass establishes a basis for deciding; the week fills in enough to actually change how the organization works.
Three things you are probably dealing with¶
Organizational data scattered across free services¶
Shared forms, group chats, files forwarded through members' personal mail. When something goes wrong it is hard to inventory what still exists, who holds it, and whose access was never revoked. Write down what you are protecting and who you are protecting it from before choosing tools.
Fill in the threat model checklist first. It produces a summary you can take into a meeting.
Someone wants to pass you information but will not use a named channel¶
They may be an employee, a directly affected person, or a witness who does not want to be identified. Ordinary forms and mailboxes leave correlatable records, and the sender has no way to assess the risk. They need a channel they can evaluate for themselves.
See sending us sensitive material, which covers the PGP and OnionShare approaches and the trade-off between them.
Donors do not want a record, and the organization still has to issue receipts¶
Charitable-solicitation rules, political-donation law, and anti-money-laundering requirements constrain each other here, and the workable space is narrower than most people expect.
See anonymous donation channels for advocacy organizations, written separately for the organization and for the donor. The legal detail is Taiwan-specific; the structure of the problem is not.
Three pages for your first twenty minutes¶
- Threat model checklist: three questions, and it flags mismatches in your answers, such as naming a state-level adversary while budgeting the lowest possible effort. What you type stays in the browser tab and is gone on reload
- Activists and protest digital safety: before, during, and after mobilization, usable as a shared baseline for everyone in the organization
- Secure messaging compared: read before deciding what the organization uses internally and externally
Building the foundation over a week¶
Internal collaboration¶
- Threat modeling: where the three questions come from, which you need when facilitating a team discussion
- Metadata, and why it matters: who contacted whom and when, a layer content encryption does not cover
- What is CryptPad?: an alternative for shared documents and forms
- Community services: Matrix, CryptPad, Send, and forms, all community-run and open for use
Intake and donations¶
- Sending us sensitive material: how the receiving end should be set up
- File metadata stripper: clean files in the browser before publishing, nothing is uploaded
- Anonymous donation channels: the full workflow and its legal constraints
Regulation, as a worked example¶
- Taiwan's 2025 data protection overhaul: what changed for organizations holding personal data
- Taiwan's whistleblower protection act: how far the law protects an employee who speaks
- Governance charter: how this community makes decisions and handles disputes, useful as a reference when drafting your own
What to take with you¶
- Press "copy summary" after the threat model checklist and paste it into the organization's notes, so the next person does not start over
- Matrix, CryptPad, and Send at community services are open for use, with nothing to self-host
- Ask in the public Matrix room, or send sensitive files to whisper@anoni.net
What this path does not cover¶
- Individual members at a protest: covered in activists and protest digital safety; the path above lists the organizational layer
- An account already compromised or a device already lost: start at emergency help
- Jurisdictions other than Taiwan: the regulatory pages above are Taiwan-specific. Hong Kong since the 2020 National Security Law and the 2024 Safeguarding National Security Ordinance, and Mainland China throughout, put advocacy organizations at a risk level Taiwan's material does not model. See posting on mainland Chinese platforms and speaking online from Singapore and Malaysia for the regional differences