Skip to content

Civil society starts here

For staff and long-term volunteers at advocacy groups, service NGOs, research organizations, and local community groups. An organization's position differs from an individual's: what you are protecting usually belongs to someone else — donors, service users, the employee willing to speak — and they are the ones who carry the consequences.

Every link below points at a page that already exists here. The twenty-minute pass establishes a basis for deciding; the week fills in enough to actually change how the organization works.

Three things you are probably dealing with

Organizational data scattered across free services

Shared forms, group chats, files forwarded through members' personal mail. When something goes wrong it is hard to inventory what still exists, who holds it, and whose access was never revoked. Write down what you are protecting and who you are protecting it from before choosing tools.

Fill in the threat model checklist first. It produces a summary you can take into a meeting.

Someone wants to pass you information but will not use a named channel

They may be an employee, a directly affected person, or a witness who does not want to be identified. Ordinary forms and mailboxes leave correlatable records, and the sender has no way to assess the risk. They need a channel they can evaluate for themselves.

See sending us sensitive material, which covers the PGP and OnionShare approaches and the trade-off between them.

Donors do not want a record, and the organization still has to issue receipts

Charitable-solicitation rules, political-donation law, and anti-money-laundering requirements constrain each other here, and the workable space is narrower than most people expect.

See anonymous donation channels for advocacy organizations, written separately for the organization and for the donor. The legal detail is Taiwan-specific; the structure of the problem is not.

Three pages for your first twenty minutes

  1. Threat model checklist: three questions, and it flags mismatches in your answers, such as naming a state-level adversary while budgeting the lowest possible effort. What you type stays in the browser tab and is gone on reload
  2. Activists and protest digital safety: before, during, and after mobilization, usable as a shared baseline for everyone in the organization
  3. Secure messaging compared: read before deciding what the organization uses internally and externally

Building the foundation over a week

Internal collaboration

Intake and donations

Regulation, as a worked example

What to take with you

  • Press "copy summary" after the threat model checklist and paste it into the organization's notes, so the next person does not start over
  • Matrix, CryptPad, and Send at community services are open for use, with nothing to self-host
  • Ask in the public Matrix room, or send sensitive files to whisper@anoni.net

What this path does not cover