Protecting sources: encrypted tools for journalists
Source protection is a metadata problem as much as a content problem. What end-to-end encryption solves, what it does not, and how to reduce what you leave behind.
Try it in one click.
Three private surfaces. Same zero-knowledge architecture.
Content is the easy part
Modern end-to-end encryption makes message and file content unreadable to anyone outside the conversation. If your tooling encrypts on the device with authenticated encryption and seals keys per recipient, content confidentiality is largely a solved problem.
Metadata is the hard part
Who contacted whom, when, how often, from where, with what file sizes: that pattern can identify a source without a single word of content. No storage or messaging product eliminates all of it, and any vendor claiming otherwise is overselling. What a serious provider can do is minimise what it retains, document exactly what it holds, and avoid building profiles.
Practical measures that materially help
- **Compartmentalise.** A separate account and device profile for sensitive work, not the same workspace as everything else.
- **Prefer per-recipient protected links** over group links, with expiry and revocation, so a leaked link is attributable and terminable.
- **Split channels.** Send a link one way and its passphrase another.
- **Strip file metadata** before sharing documents and images; EXIF and document properties have exposed more sources than cryptanalysis ever has.
- **Use passkeys and reviewable device trust**, and revoke sessions aggressively after travel or loss.
- **Keep an offline recovery kit**, stored physically, because no zero-knowledge provider can restore your access.
Choosing tooling for a newsroom
Ask the same five questions any regulated buyer should ask: can an administrator read a private space; what does the server hold at upload; what happens cryptographically when someone is removed; are names and structure encrypted; does search send terms to the server. Then add two more: what operational metadata is retained and for how long, and what has the provider published about legal requests.
Things technology cannot fix
A source who photographs a screen, a device seized while unlocked, an ill-considered detail in a published story that narrows the field of possible sources, or a shared account used by a whole desk. Source protection is a practice; tooling raises the floor rather than replacing judgement.
Where DRIVUNO fits
DRIVUNO encrypts content on the device, seals keys per recipient, rotates on removal, offers protected links with passphrase and expiry, and publishes its subprocessors and storage regions. We hold operational metadata necessary to run the service and we document it rather than claiming there is none. For source-protection work, that documentation is the part you should read most carefully.
Try it in one click.
Three private surfaces. Same zero-knowledge architecture.