What is SecureDrop?
SecureDrop is an open-source whistleblowing platform developed by the Freedom of the Press Foundation. It allows sources to submit documents and communicate with journalists entirely through Tor hidden services, ensuring that neither the news organization's servers nor network observers can identify the source. Each news organization operates its own independent SecureDrop instance.
SecureDrop relies on air-gapped servers, PGP encryption, and Tails OS to establish a multi-layered security architecture. Documents are encrypted prior to storage, and journalists access submissions only on dedicated, network-isolated machines.
Major News Organization Instances
The New York Times
The Gray Lady runs one of the most well-known SecureDrop instances, receiving leaked documents from sources around the world.
NYT SecureDrop
The Washington Post
WaPo's SecureDrop instance is a primary channel for national security and government accountability leaks.
Washington Post SecureDrop
The Guardian
The Guardian accepts confidential tips and documents through its SecureDrop instance, particularly for UK and European accountability stories.
Guardian SecureDrop
ProPublica
Nonprofit investigative journalism — one of the first outlets to adopt SecureDrop for source protection.
ProPublica SecureDrop
The Intercept
Founded by Glenn Greenwald, Laura Poitras, and Jeremy Scahill — known for publishing Edward Snowden's NSA documents.
The Intercept SecureDrop
Independent Leak Platforms
GlobaLeaks
GlobaLeaks is an open-source, self-hosted whistleblowing framework. Unlike SecureDrop, GlobaLeaks is designed to be deployed by any organization — NGOs, government agencies, corporations — to establish their own confidential reporting channels.
Distributed Denial of Secrets (DDoSecrets)
A transparency collective publishing leaked datasets for the public good. DDoSecrets functions as a WikiLeaks successor with a more robust editorial framework, redacting personally identifying information where appropriate.
Access: ddosecrets.com
OPSEC for Whistleblowers
- Use Tails OS exclusively: Boot from a USB drive on a computer you do not own. Tails leaves zero forensic trace
- Never access SecureDrop from home or work: Use public WiFi from a location not associated with your routine
- Do not tell anyone: The most common source of whistleblower exposure is confiding in colleagues, friends, or family
- Strip metadata: Remove EXIF data, authorship info, and printer tracking dots from documents before submission
- Use the source's codename: SecureDrop generates a unique codename for each source — memorize it, do not write it down digitally
Whistleblowing is protected speech in many jurisdictions. These platforms exist to protect sources who expose corruption, abuse, and threats to public safety. See our OPSEC Fundamentals for additional security guidance.