Skip to main content

SecureDrop for Newsrooms

SecureDrop is the gold standard for receiving sensitive documents from whistleblowers. This guide explains what it is, how it works, and what smaller newsrooms should use instead.

General guidance, not professional security advice. For high-risk threat models involving state actors or organised crime targeting, consult a qualified security professional or the Access Now Digital Security Helpline.

Last reviewed: Next review due:

What is SecureDrop?

SecureDrop is an open-source whistleblower submission system originally developed by Aaron Swartz and Kevin Poulsen, now maintained by the Freedom of the Press Foundation (FPF). It allows sources to submit documents and communicate with journalists completely anonymously, over the Tor network, without any identifying metadata being stored on the SecureDrop server.

SecureDrop is used by major news organisations including The Guardian, The Washington Post, The New York Times, and BBC News. It operates on dedicated hardware within the newsroom’s own infrastructure — not on shared cloud hosting. Sources access it only via Tor Browser, which strips IP address and location information. The newsroom-side involves an air-gapped (network-disconnected) computer for reading submissions.

The system is designed to be as hostile to subpoenas and legal demands as possible: the SecureDrop server stores very little data, and what it does store is encrypted. The FPF has a warrant canary — a regularly updated statement that no secret legal demands have been served — which is monitored by the security community.

When this matters most

  • 1Your newsroom regularly receives sensitive documents from government, corporate, or security sector sources.
  • 2You cover beats where sources face significant legal or physical risk if identified.
  • 3Your newsroom has received or expects to receive legal demands for source information.
  • 4You have the technical and budgetary capacity to maintain dedicated server infrastructure.
  • 5You want to publish your SecureDrop address publicly so that potential sources can find it.

SecureDrop vs alternatives

SecureDrop (FPF)Large newsrooms

Pros: Gold standard. Air-gapped, Tor-only, FPF-audited, warrant canary.

Cons: High setup cost (dedicated hardware), requires IT staff, ongoing maintenance commitment.

GlobaLeaksMid-size newsrooms

Pros: Free, open-source, easier to set up than SecureDrop. Used by ICIJ and others. Tor-capable.

Cons: Less hardened than SecureDrop. Still requires server hosting and ongoing security maintenance.

OnionShareIndividual journalists

Pros: Free, no infrastructure needed, peer-to-peer over Tor, ephemeral — no persistent server.

Cons: Not publicly addressable (sources need a specific .onion link per session). Not for at-scale intake.

Red flags in your SecureDrop operations

  • Journalists accessing SecureDrop submissions on a networked device instead of the air-gapped viewing station.
  • Documents moved from the viewing station to a networked device without being sanitised.
  • The SecureDrop address published without a corresponding operational security policy for journalists.
  • Source communications conducted outside the SecureDrop system after initial contact.
  • Admin access to the SecureDrop server conducted over a non-secure network.

Newsroom SecureDrop checklist

  • We have assessed whether SecureDrop or an alternative is right for our newsroom size and resources.
  • We have a dedicated air-gapped viewing station for reading submissions.
  • All journalists who use SecureDrop have received operational security training.
  • We have published our SecureDrop address on our website's contact page.
  • We have a documented procedure for verifying the authenticity of received documents.
  • We have a documented procedure for communicating securely with sources after initial contact.
  • We have assigned responsibility for system maintenance and security updates.
  • We have reviewed the FPF's warrant canary recently and understand what to do if it lapses.

Source protection tools

Assess your newsroom’s source protection posture with our checklist.

Source Protection Checklist

Common mistakes

  • Reading SecureDrop submissions on a networked computer — the air-gap is essential.
  • Communicating with sources via standard email after initial SecureDrop contact.
  • Not training all relevant journalists on the operational security requirements.
  • Underestimating the ongoing maintenance burden — SecureDrop requires regular security updates.
  • Publishing a SecureDrop address without a clear editorial policy on who monitors it and how quickly.

Related guides

Primary sources

Frequently asked questions

How much does SecureDrop cost to set up?
SecureDrop software is free and open-source, maintained by the Freedom of the Press Foundation. However, the hardware costs — dedicated servers, air-gapped viewing station, network configuration — typically run to several thousand pounds. Ongoing maintenance requires dedicated technical staff. The FPF provides installation support and an ongoing support agreement for newsrooms.
Can a small newsroom or freelance journalist run SecureDrop?
SecureDrop is designed for newsrooms with dedicated IT capacity. For smaller newsrooms, GlobaLeaks is a viable open-source alternative that is easier to set up and maintain. For individual journalists, OnionShare provides similar one-time file transfer functionality without the infrastructure overhead.
How does a journalist read documents submitted via SecureDrop?
Journalists use a dedicated, air-gapped viewing station — a computer with no network connection — to read SecureDrop submissions. Documents are transferred from the SecureDrop server to the viewing station via a dedicated USB stick. This prevents submitted documents from ever touching a networked device, which could expose the source through network logs.
Can I trust documents received through SecureDrop?
SecureDrop protects the source's identity and the integrity of the transmission. It does not guarantee the documents are authentic. Standard journalistic verification still applies: corroborate the content through independent sources, check document metadata (with ExifTool), verify internal consistency, and where possible speak to the source for additional context.