Skip to main content

Source Protection Checklist — Twelve Questions Before You Publish

Sources are almost never exposed by a single dramatic failure. They are exposed by a calendar invite, an unstripped document, a badge log at their end, or the fact that only four people could have known. A checklist is a way of remembering all of them at once.

Last reviewed: Next review due:

Source Protection Checklist

Answer Yes or No for each item. Every answer is required — this checklist demands commitment, not uncertainty.

1.Did I agree the level of anonymity in writing with the source (off-record / on-background / not-for-attribution / on-record)?

2.Are we communicating through an encrypted channel (Signal, ProtonMail, SecureDrop)?

3.Have I avoided naming the source in emails, calendar invites, or shared documents?

4.Have I stored notes (digital + paper) in a way the source cannot be identified by them alone?

5.Have I stripped metadata from any documents the source sent (e.g. via DocumentCloud or manual EXIF cleaning)?

6.Have I considered whether my device(s) are secure (full-disk encryption, strong passphrase, OS updated)?

7.Have I considered whether cloud backups or syncs (iCloud, Google Drive) could expose source material?

8.Have I considered whether the source's own digital footprint identifies them (their email metadata, badge logs, building access)?

9.Have I considered whether the source could be identified by exclusion ("only X people knew this") and discussed this with them?

10.Have I considered RIPA/IPA powers — police or state could demand my communications data?

11.Have I considered whether a Production Order could be made against me (PACE s.9, Sch.1) and where my notes physically sit?

12.Do I know the NUJ's source protection guidance and have a lawyer contact in case of legal pressure?

0/12 answered
This checklist is a starting point. High-risk source protection scenarios (e.g. state actors, criminal investigations) require professional security advice and possibly legal counsel.

How it works

  • Twelve fixed yes/no items: agreeing the level of attribution in writing; using an encrypted channel; keeping the name out of email, calendar invites and shared documents; storing notes so they do not identify the source; stripping metadata from documents; device encryption and updates; cloud backup and sync exposure; the source’s own digital footprint at their end; identification by exclusion; Investigatory Powers Act 2016 communications-data risk; PACE Schedule 1 production orders; and knowing the NUJ guidance and having a lawyer contact.
  • Every item must be answered before the results button unlocks; the progress strip turns green or red per item as you go.
  • The score is the number of Yes answers, banded 7-9 amber “Moderate” and 0-6 red “Weak” with the wording “Do not proceed until the issues below are resolved”. A score of 10-12 only reaches green “Strong” if two specific items are also Yes — using an encrypted channel and stripping metadata from anything the source sent; without both, a 10-12 score is still shown as amber.
  • Each No prints a fixed remediation tip naming concrete tools — Signal with disappearing messages, SecureDrop, VeraCrypt, FileVault or BitLocker, DocumentCloud, ExifTool, MAT2 — plus links to the site’s digital security and whistleblower guidance.

When to use it

  • Before the first substantive contact with a confidential source, while the channel and the ground rules are still open to change.
  • When a source hands over documents, to force the metadata and provenance questions before the files touch a shared drive.
  • At the final read, where jigsaw identification becomes real and the detail that identifies the source is usually a fact you love.
  • When briefing an editor on why a story needs a slower, more careful publication process.

What it does not do

  • This is a prompt, not an assessment. It records what you say you have done — it cannot see your device, your inbox, your notes, or the logs at your source’s employer. A green result is not evidence that your source is safe.
  • The score is still mostly a tally of your own assertions. Ten of the twelve items carry equal weight, so a green verdict can rest on eight easy Yeses plus the two gated ones, and nothing here is checked against your device, your inbox or your source’s employer. Read the missing-actions list, never the colour.
  • Nothing is saved, verified or exported. There is no artefact you can show an editor or a lawyer, and reloading the page clears it.
  • It does not cover targeted device compromise, mercenary spyware, or an adversary with lawful-intercept capability. The tool’s own footer says high-risk scenarios need professional security advice and legal counsel; take that literally rather than as boilerplate.
  • Item 9 — identification by exclusion — is the one no tooling fixes. If only four people could have known, encryption protects nothing. Work it through with the source before publication, and again on the final version.

More tools

This is one of the free tools on UK JournoHub. See the full tools index for the rest.