Newsrooms start here¶
For organizations with an editorial desk, legal counsel, and IT. What an organization can do differs from what an individual can: intake channels, material retention, and post-publication cleanup all need cross-team agreement, and no single reporter changing tools will solve them.
For the individual layer, see the independent journalist path. Every link below points at a page that already exists here.
Three things you are probably dealing with¶
The site lists a contact address that no source will use¶
Ordinary mail leaves a record at both ends, and the sender has no way to assess the risk. People with internal documents generally understand this, which is why they do not write.
See first contact for what a channel has to offer before it is worth publishing.
Material scattered across reporters' personal devices and assorted cloud accounts¶
Interview audio, photographed documents, message history, spread across personal phones, private cloud storage, and company mail. When a disclosure request arrives, the desk usually cannot say what still exists or who holds it.
See post-publication cleanup, which covers the organizational layer.
A leaked document arrives and has to be verified without exposing the source¶
Verification itself leaves traces. How you phrase a question to a third party, and which details reach print, can narrow the field to a handful of people.
See keeping multiple sources apart.
Three pages for your first twenty minutes¶
- The metadata problem comes first: the layer that content encryption does not reach, and the reason the rest of the workflow exists
- Threat model checklist: three questions producing a summary suitable for an editorial meeting. What you type stays in the browser tab and is never stored
- Post-publication cleanup: what the organization retains, and for how long, determines what it has to hand over
Building the process over a week¶
Setting up intake¶
- OnionShare: a source can send files without registering an account
- Sending us sensitive material: how the receiving end should be set up, including PGP
- Secure messaging compared: what follow-up contact runs on
Retention and cleanup¶
- Metadata, and why it matters: what a file carries beyond its contents
- File metadata stripper: clean files in the browser before publishing, nothing is uploaded
- Exchanging files: where material lives and who holds the keys
Verification and publication¶
- Invisible character detector: includes a section on verifying without burning the source, since invisible markers in a document are a common way to identify who leaked it
- Keeping multiple sources apart: which details narrow the field once published
- Interview records: how notes are kept and what to leave out
The regional angle¶
- The regional angle that changes the advice: how the workflow shifts across the region
- Taiwan's whistleblower protection act: how far the law protects an employee who speaks, as a Taiwan-specific worked example
- Posting on mainland Chinese platforms: relevant when a source or collaborator is inside Mainland China
What to take with you¶
- Press "copy summary" after the threat model checklist and paste it into the desk's shared notes
- The invisible character detector and file metadata stripper both run in the browser and upload nothing, so they can be recommended to the whole desk as-is
- Ask in the public Matrix room, or send sensitive files to whisper@anoni.net
What this path does not cover¶
- Compartmentalizing a reporter's own devices and accounts: see the independent journalist path
- Reporting trips and conferences abroad: see device minimization and border crossings in Asia
- An incident already in progress: start at emergency help