Skip to main content

Secure File Sharing for UK Journalists

Sharing sensitive documents via cloud links can expose sources. This guide covers the tools that protect the file and the identity of the person who sent it.

General guidance, not professional security advice. For high-risk threat models involving state actors or organised crime targeting, consult a qualified security professional or the Access Now Digital Security Helpline.

Last reviewed: Next review due:

Why secure file sharing matters

When a source shares a document with you, or you share unpublished material with a colleague, the method of transfer creates a digital trail. A standard email attachment goes through your email provider’s servers. A Google Drive link is stored on Google’s infrastructure. A WhatsApp file passes through Meta’s servers. All of these can be compelled by a court order or government request — and metadata (who accessed the file, from what IP, at what time) can be enough to identify a source even if the file content itself is not sensitive.

The goal of secure file sharing is to transfer documents without creating a metadata trail that links the source to the file. The best tools do this by using the Tor network, temporary storage, or physical encrypted media — eliminating or minimising server-side logging.

When this matters most

  • 1Receiving documents from a source who could face serious consequences if identified.
  • 2Sharing unpublished investigation materials between journalists on different networks.
  • 3Transferring documents that contain embedded metadata (see the metadata guide).
  • 4Any situation where cloud storage could be compelled by a court or production order.
  • 5Cross-border work where file transfers may pass through adversarial networks.

Tool comparison

SecureDropNewsroom standard

Operated by the Freedom of the Press Foundation. Air-gapped server, Tor-only access, dedicated hardware. Gold standard for newsrooms receiving sensitive documents at scale. Requires significant setup and ongoing maintenance.

OnionShareIndividual journalists

Free, open-source. Creates a temporary .onion address for one-time file transfer over Tor. No server in the middle. Recipient must use Tor Browser. Excellent for individual journalists doing one-off secure transfers.

Magic WormholeTechnical users

Encrypted peer-to-peer file transfer using a short code. Easier to use than OnionShare but uses a relay server (not Tor) which logs some metadata. Suitable for lower-risk transfers where Tor is not required.

Hardware-encrypted USBIn-person transfers

Devices like iStorage datAshur or Apricorn Aegis use hardware encryption with a PIN. If seized without the PIN, data is inaccessible. Practical for in-person source meetings. Creates a physical evidence trail.

Red flags

  • Asking a sensitive source to share documents via Google Drive, Dropbox, or WeTransfer.
  • Emailing unencrypted documents to or from a source.
  • Using Slack, Teams, or a work messaging platform to transfer sensitive files.
  • Not removing metadata from received documents before sharing them further.
  • A source uploading documents from a work device or work network.

Secure file sharing checklist

  • I have assessed which tool is proportionate to my threat model for this transfer.
  • I have briefed the source on how to use OnionShare or the newsroom's SecureDrop before they need it.
  • The source understands they should not upload documents from a work device or work network.
  • I have stripped metadata from received documents before working with them further.
  • I am not storing received documents in a cloud service that could be compelled.
  • For in-person transfers: I am using a hardware-encrypted USB stick.
  • I have confirmed the .onion address with the source through a separate secure channel (Signal).

Source protection tools

Assess whether your file sharing setup is adequate for your next sensitive story.

Source Protection Checklist

Common mistakes

  • Using cloud storage because it is convenient — convenience and source protection are often in conflict.
  • Not briefing the source before they have a document to share — by then it may be too late.
  • Using OnionShare without both parties using Tor Browser — the security breaks down on the recipient side.
  • Neglecting to strip metadata from received files before sharing or publishing.
  • Storing sensitive documents on a device without full-disk encryption.

Related guides

Primary sources

Frequently asked questions

Why can't I just use a Dropbox or Google Drive link to share documents with sources?
Cloud storage providers including Dropbox, Google, and Microsoft can be compelled to produce your files by court order, law enforcement request, or government demand. They also collect metadata about who accessed a file and from where. A production order against you or the cloud provider could reveal that a specific person accessed a file at a specific time and IP address — potentially identifying a source.
What is OnionShare and how does it work?
OnionShare is a free, open-source tool that lets you create a temporary .onion website hosted directly on your computer. A source (or you) can upload files through Tor Browser without any server in the middle. The file goes directly from one device to the other over the Tor network. Each transfer uses a unique, random .onion address that expires after use. No account needed, no cloud storage, no metadata trail on a central server.
Is SecureDrop the same as OnionShare?
No. SecureDrop is a full whistleblower submission system operated by newsrooms on their own infrastructure. It uses Tor, air-gapped servers, and a two-device system with specific hardware requirements. OnionShare is a lightweight peer-to-peer file transfer tool suitable for individual journalists. For newsrooms receiving sensitive documents at scale, SecureDrop is the gold standard. For individual journalists doing a one-off secure transfer, OnionShare is more practical.
Can an encrypted USB stick be used safely?
Yes, with caveats. A hardware-encrypted USB stick (such as those from iStorage or Apricorn) protects files if the stick is lost or seized — without the PIN/password, the data is inaccessible. However, transferring files via USB requires physical proximity, and the USB itself creates a physical evidence trail. For journalists meeting sources in person, a hardware-encrypted USB is practical. Ensure the source uses Tails OS or a clean device when copying files.