Skip to content

Self-hosted secure tip line

A secure tip line your sources can trust, that you can run yourself.

OpenCyph is an open-source intake system for newsrooms, human rights organisations and whistleblower programmes. Submissions are encrypted end to end, and sources talk to you through a code rather than an identity.

Open source and self-hostable
The server operator cannot read submissions
Sources reply through a code, not an identity

The problem

Organisations that need confidential submissions mostly use an email address, which exposes the source completely, or a hosted whistleblowing service whose operator can see everything and is subject to legal compulsion.

Sources are increasingly sophisticated and will not use a system they cannot verify, so the disclosures that matter most never arrive.

Who it is for

  • Newsrooms and investigative units

    Journalists who receive sensitive disclosures and need a channel that sophisticated sources are willing to use.

  • Human rights organisations

    Organisations taking confidential submissions that must not expose the person making them.

  • Ethics programmes and regulators

    Corporate ethics and whistleblower programmes, and regulators who receive sensitive disclosures.

What could your tip line expose about a source?

Answer fifteen questions about how your organisation receives confidential submissions: the channel, talking to sources, what can be verified and how submissions are handled. See the gaps to close first. Runs in your browser. No account, no card, no call.

Your tip line today

Answer for the channel sources use now, even if it is an email address. Nothing is sent.

The channel

Are submissions encrypted end to end, so whoever runs the server cannot read them?

Does the channel avoid keeping IP addresses and other metadata about sources?

Can a source submit without an email address, phone number or account in their name?

Can sources send large files through the same channel?

Talking to sources

Can you reply to a source without learning who they are?

Can a source come back later and continue the same conversation?

Do you tell sources plainly what the system keeps and does not keep?

What can be verified

Is the software's code public, so anyone can check what it does?

Is the software's cryptographic design published?

Do you run the server yourself, or tell sources plainly who does?

Handling submissions

Is a retention policy written down and applied to submissions?

Is access to submissions limited to named people?

Do you know what you hold about sources that could be demanded under legal compulsion?

Are the people who read submissions trained in handling them?

Has someone outside the team that runs it reviewed the setup?

Answer the questions to see your score. It updates as you go.

Method: yes scores a question in full, partly scores half and no scores nothing. Each is weighted from one to three by how directly a no could expose a source, and the score is the weighted share out of a hundred. Unanswered questions are left out.

How it works

OpenCyph, from the first step to the result.

  1. 01

    Deploy it yourself

    One command, on your own infrastructure, with documentation to follow.

  2. 02

    Receive submissions

    Messages and large files, encrypted end to end.

  3. 03

    Talk to the source

    An anonymous two-way conversation through a code, never an identity.

  4. 04

    Show sources what you keep

    The code and cryptographic design are public, so what the system retains can be checked.

An intake system a source can verify

Open-source, self-hostable secure intake, built so an organisation can prove to a source what it does and does not retain.

End-to-end encryption

Submissions are encrypted end to end, so the server operator cannot read them.

Metadata minimised by design

Metadata minimisation is built into the design, so as little as possible is kept about a source.

Anonymous two-way conversation

Talk with a source anonymously. The source uses a code rather than an identity.

Large file submissions

Sources can submit large files, not only messages.

Published cryptographic design

The cryptographic design is published and auditable, and the code is public, so anyone can check how it works.

One-command deployment

Run it on your own infrastructure with a one-command deployment and thorough documentation.

Questions people actually ask

Can the server operator read submissions?
No. Submissions are encrypted end to end, so the server operator cannot read them.
How do we talk to a source without knowing who they are?
Through an anonymous two-way conversation. The source uses a code rather than an identity.
Why self-host rather than use a hosted whistleblowing service?
Because the code is open source and runs on your own infrastructure, you can prove to a source what the system does and does not retain. Serious sources will not use a system they cannot verify.
Is there a hosted option?
Yes, for organisations without infrastructure capability. The trust trade-off of using a hosted service is stated plainly rather than glossed over.
What does it cost?
The software is free and open source. The hosted service is 199 dollars a month for small organisations, or 990 dollars a month for larger ones, which adds custom domains and retention policy controls.
Can you help us deploy and harden it?
Yes. Paid deployment, hardening and training engagements start from 6,000 dollars.
Can we check the cryptography ourselves?
Yes. The cryptographic design is published and auditable, and all of the code is public.
Why should I trust the tip line source protection check?
The score comes from your answers, worked out in your browser. It does not test your system or its encryption. OpenCyph's published cryptographic design and public code are how its own claims can be checked.

Pricing

Free and open source to run yourself. Pay for hosting, or for help deploying, hardening and training on your own installation.

Open source

The full intake system on your own infrastructure.

Freeself-hosted, forever
  • End-to-end encryption
  • Anonymous two-way conversation
  • One-command deployment
Get in touch
Recommended

Hosted

For small organisations without infrastructure capability.

$199per month
  • Hosted for you
  • Trust trade-off stated plainly
Get in touch

Hosted, larger

For larger organisations.

$990per month
  • Custom domains
  • Retention policy controls
Talk to us

Deployment and training

Help running your own installation.

From $6,000per engagement
  • Deployment
  • Hardening
  • Training
Talk to us

Prices in USD. The open-source version is free forever.

What could your tip line expose about a source?

Answer fifteen questions about how your organisation receives confidential submissions: the channel, talking to sources, what can be verified and how submissions are handled. See the gaps to close first. Runs in your browser. No account, no card, no call.

Open the free tool

It runs in your browser. OpenCyph never sees your inputs.