Core Protocols & Infrastructure

Every data channel, storage node, and communication pipeline is secured through industry-standard cryptographic protocols. Our infrastructure is regularly audited and penetration-tested.

πŸ”’

Transport Layer Security (TLS 1.3)

All web traffic, API endpoints, and CDN routes are enforced over TLS 1.3 with perfect forward secrecy. HSTS is enabled with a one-year max-age and preload flag.

Network Encryption
πŸ“¦

AES-256-GCM Storage Encryption

All persistent data, including article drafts, source submissions, and reader metadata, is encrypted at rest using AES-256-GCM with hardware-backed key management.

Data at Rest
πŸ”

PGP/GPG Source Communications

Anonymous tips and source materials are accepted via PGP-encrypted channels. We operate a dedicated secure drop infrastructure with zero-logging policies.

Source Protection
πŸ“±

Signal Protocol Messaging

Internal editorial and field correspondence utilizes end-to-end encrypted messaging. No plaintext backups are stored on shared cloud infrastructure.

Internal Comms

Source Protection & Secure Drop

Whistleblowers and anonymous sources trust us with sensitive information. Our secure drop system is built to withstand legal subpoenas and technical interception attempts.

  • βœ“ Tor-hidden service for anonymous submissions with no IP logging
  • βœ“ PGP-encrypted upload pipeline with automatic key rotation
  • βœ“ Metadata scrubbing applied to all images, documents, and audio files
  • βœ“ Dual-key decryption requiring editorial and security leads to authorize access
  • βœ“ Zero-knowledge architecture: encrypted materials are never decrypted in memory

Reader Privacy & Data Minimization

We do not sell, track, or profile our readers. Encryption protects your session, while our privacy architecture ensures minimal data collection.

  • βœ“ End-to-end encrypted reader comments and community forums
  • βœ“ No third-party analytics, trackers, or fingerprinting scripts
  • βœ“ Cookie-less browsing option with encrypted session tokens
  • βœ“ Automatic PII scrubbing from logs every 24 hours
  • βœ“ GDPR/CCPA compliant data retention with cryptographic erasure

PGP Public Key Verification

Verify our identity and encrypt communications before sending sensitive materials. Our editorial security team monitors this key for submissions.

-----BEGIN PGP PUBLIC KEY BLOCK----- mQINBF2mXxYBEADJk8z7vF3Q9xR2pL4mN8tY6wZ1cV0eH3jK5sA9bX2dF7gU4iL qR6tM0oP1vW3yE8nC5kA2hJ9mS4xZ7bD0eF3gH6iL8nO1pQ2rS4tU5vW6xY7zA9 B0cD1eF2gH3iJ4kL5mN6oP7qR8sT9uV0wX1yZ2aB3cD4eF5gH6iJ7kL8mN9oP0qR 1sT2uV3wX4yZ5aB6cD7eF8gH9iJ0kL1mN2oP3qR4sT5uV6wX7yZ8aB9cD0eF1gH 2iJ3kL4mN5oP6qR7sT8uV9wX0yZ1aB2cD3eF4gH5iJ6kL7mN8oP9qR0sT1uV2wX 3yZ4aB5cD6eF7gH8iJ9kL0mN1oP2qR3sT4uV5wX6yZ7aB8cD9eF0gH1iJ2kL3mN 4oP5qR6sT7uV8wX9yZ0aB1cD2eF3gH4iJ5kL6mN7oP8qR9sT0uV1wX2yZ3aB4cD 5eF6gH7iJ8kL9mN0oP1qR2sT3uV4wX5yZ6aB7cD8eF9gH0iJ1kL2mN3oP4qR5sT 6uV7wX8yZ9aB0cD1eF2gH3iJ4kL5mN6oP7qR8sT9uV0wX1yZ2aB3cD4eF5gH6iJ 7kL8mN9oP0qR1sT2uV3wX4yZ5aB6cD7eF8gH9iJ0kL1mN2oP3qR4sT5uV6wX7yZ 8aB9cD0eF1gH2iJ3kL4mN5oP6qR7sT8uV9wX0yZ1aB2cD3eF4gH5iJ6kL7mN8oP -----END PGP PUBLIC KEY BLOCK-----

Fingerprint: A1B2 C3D4 E5F6 7890 1234 5678 9ABC DEF0 1234 5678

Have a Security Concern?

Found a vulnerability or have an encrypted tip? Contact our security team directly. We guarantee confidential handling and rapid response.

πŸ›‘οΈ Contact Security Team

PGP-encrypted emails preferred. Response within 24 hours.