Core Protocols & Infrastructure
Every data channel, storage node, and communication pipeline is secured through industry-standard cryptographic protocols. Our infrastructure is regularly audited and penetration-tested.
Transport Layer Security (TLS 1.3)
All web traffic, API endpoints, and CDN routes are enforced over TLS 1.3 with perfect forward secrecy. HSTS is enabled with a one-year max-age and preload flag.
Network EncryptionAES-256-GCM Storage Encryption
All persistent data, including article drafts, source submissions, and reader metadata, is encrypted at rest using AES-256-GCM with hardware-backed key management.
Data at RestPGP/GPG Source Communications
Anonymous tips and source materials are accepted via PGP-encrypted channels. We operate a dedicated secure drop infrastructure with zero-logging policies.
Source ProtectionSignal Protocol Messaging
Internal editorial and field correspondence utilizes end-to-end encrypted messaging. No plaintext backups are stored on shared cloud infrastructure.
Internal CommsSource Protection & Secure Drop
Whistleblowers and anonymous sources trust us with sensitive information. Our secure drop system is built to withstand legal subpoenas and technical interception attempts.
- β Tor-hidden service for anonymous submissions with no IP logging
- β PGP-encrypted upload pipeline with automatic key rotation
- β Metadata scrubbing applied to all images, documents, and audio files
- β Dual-key decryption requiring editorial and security leads to authorize access
- β Zero-knowledge architecture: encrypted materials are never decrypted in memory
Reader Privacy & Data Minimization
We do not sell, track, or profile our readers. Encryption protects your session, while our privacy architecture ensures minimal data collection.
- β End-to-end encrypted reader comments and community forums
- β No third-party analytics, trackers, or fingerprinting scripts
- β Cookie-less browsing option with encrypted session tokens
- β Automatic PII scrubbing from logs every 24 hours
- β GDPR/CCPA compliant data retention with cryptographic erasure
PGP Public Key Verification
Verify our identity and encrypt communications before sending sensitive materials. Our editorial security team monitors this key for submissions.
Fingerprint: A1B2 C3D4 E5F6 7890 1234 5678 9ABC DEF0 1234 5678
Have a Security Concern?
Found a vulnerability or have an encrypted tip? Contact our security team directly. We guarantee confidential handling and rapid response.
π‘οΈ Contact Security TeamPGP-encrypted emails preferred. Response within 24 hours.