Self-hosted secure tip line
A secure tip line your sources can trust, that you can run yourself.
OpenCyph is an open-source intake system for newsrooms, human rights organisations and whistleblower programmes. Submissions are encrypted end to end, and sources talk to you through a code rather than an identity.
- Open source and self-hostable
- The server operator cannot read submissions
- Sources reply through a code, not an identity
The problem
Organisations that need confidential submissions mostly use an email address, which exposes the source completely, or a hosted whistleblowing service whose operator can see everything and is subject to legal compulsion.
Sources are increasingly sophisticated and will not use a system they cannot verify, so the disclosures that matter most never arrive.
Who it is for
Newsrooms and investigative units
Journalists who receive sensitive disclosures and need a channel that sophisticated sources are willing to use.
Human rights organisations
Organisations taking confidential submissions that must not expose the person making them.
Ethics programmes and regulators
Corporate ethics and whistleblower programmes, and regulators who receive sensitive disclosures.
What could your tip line expose about a source?
Answer fifteen questions about how your organisation receives confidential submissions: the channel, talking to sources, what can be verified and how submissions are handled. See the gaps to close first. Runs in your browser. No account, no card, no call.
Method: yes scores a question in full, partly scores half and no scores nothing. Each is weighted from one to three by how directly a no could expose a source, and the score is the weighted share out of a hundred. Unanswered questions are left out.
How it works
OpenCyph, from the first step to the result.
- 01
Deploy it yourself
One command, on your own infrastructure, with documentation to follow.
- 02
Receive submissions
Messages and large files, encrypted end to end.
- 03
Talk to the source
An anonymous two-way conversation through a code, never an identity.
- 04
Show sources what you keep
The code and cryptographic design are public, so what the system retains can be checked.
An intake system a source can verify
Open-source, self-hostable secure intake, built so an organisation can prove to a source what it does and does not retain.
End-to-end encryption
Submissions are encrypted end to end, so the server operator cannot read them.
Metadata minimised by design
Metadata minimisation is built into the design, so as little as possible is kept about a source.
Anonymous two-way conversation
Talk with a source anonymously. The source uses a code rather than an identity.
Large file submissions
Sources can submit large files, not only messages.
Published cryptographic design
The cryptographic design is published and auditable, and the code is public, so anyone can check how it works.
One-command deployment
Run it on your own infrastructure with a one-command deployment and thorough documentation.
Questions people actually ask
- Can the server operator read submissions?
- No. Submissions are encrypted end to end, so the server operator cannot read them.
- How do we talk to a source without knowing who they are?
- Through an anonymous two-way conversation. The source uses a code rather than an identity.
- Why self-host rather than use a hosted whistleblowing service?
- Because the code is open source and runs on your own infrastructure, you can prove to a source what the system does and does not retain. Serious sources will not use a system they cannot verify.
- Is there a hosted option?
- Yes, for organisations without infrastructure capability. The trust trade-off of using a hosted service is stated plainly rather than glossed over.
- What does it cost?
- The software is free and open source. The hosted service is 199 dollars a month for small organisations, or 990 dollars a month for larger ones, which adds custom domains and retention policy controls.
- Can you help us deploy and harden it?
- Yes. Paid deployment, hardening and training engagements start from 6,000 dollars.
- Can we check the cryptography ourselves?
- Yes. The cryptographic design is published and auditable, and all of the code is public.
- Why should I trust the tip line source protection check?
- The score comes from your answers, worked out in your browser. It does not test your system or its encryption. OpenCyph's published cryptographic design and public code are how its own claims can be checked.
Pricing
Free and open source to run yourself. Pay for hosting, or for help deploying, hardening and training on your own installation.
Open source
The full intake system on your own infrastructure.
- End-to-end encryption
- Anonymous two-way conversation
- One-command deployment
Hosted
For small organisations without infrastructure capability.
- Hosted for you
- Trust trade-off stated plainly
Hosted, larger
For larger organisations.
- Custom domains
- Retention policy controls
Deployment and training
Help running your own installation.
- Deployment
- Hardening
- Training
Prices in USD. The open-source version is free forever.
What could your tip line expose about a source?
Answer fifteen questions about how your organisation receives confidential submissions: the channel, talking to sources, what can be verified and how submissions are handled. See the gaps to close first. Runs in your browser. No account, no card, no call.
Open the free toolIt runs in your browser. OpenCyph never sees your inputs.