An open-source whistleblower submission system for media organizations to securely accept documents from anonymous sources.
SecureDrop is an open-source whistleblower submission system that media organizations deploy to securely accept documents from and communicate with anonymous sources. It solves the critical problem of protecting source identity and document confidentiality in investigative journalism. The system was originally created by Aaron Swartz and is now managed by the Freedom of the Press Foundation.
Media organizations, newsrooms, and investigative journalism teams that need to securely receive sensitive information from anonymous sources. Also relevant to organizations focused on transparency and secure communication.
Developers choose SecureDrop because it's a mature, battle-tested open-source solution specifically designed for whistleblower submissions with strong security guarantees. Unlike proprietary alternatives, it offers full transparency, can be self-hosted, and is developed with input from security experts and journalists.
GitHub repository for the SecureDrop whistleblower platform. Do not submit tips here!
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.
Designed specifically for whistleblower protection with features like two-factor authentication and EFF Diceware passphrase generation, as highlighted in the README's key features and philosophy.
The README states it's a stable, mature project actively used in global newsrooms, with ongoing security and bug fixes ensuring reliability.
Released under GNU AGPL v3, allowing full code audit and self-hosting, which aligns with its philosophy of minimal trust and community-driven development.
Translated into many languages by volunteers via Weblate, and contributions are welcomed with a clear Code of Conduct, fostering a collaborative ecosystem.
Installation requires Docker and make commands, with a separate Installation Guide, making it resource-intensive for teams without DevOps expertise.
Documentation is split across multiple repositories (e.g., securedrop-docs, securedrop-dev-docs), which can hinder onboarding and troubleshooting efficiency.
Tailored exclusively for secure whistleblower submissions, so it lacks features for general-purpose communication or integration with common media workflows.