About OpenCyph
A secure tip line your sources can trust, that you can run yourself.
What we do
An open-source, self-hostable secure intake system. End-to-end encryption so the server operator cannot read submissions, metadata minimisation by design, anonymous two-way conversation with the source through a code rather than an identity, submission of large files, and an auditable, published cryptographic design. Because it is open source and self-hosted, the organisation can prove to a source what it does and does not retain, which is the only thing that makes a serious source use it. A hosted option exists for organisations without infrastructure capability, with the trust trade-off stated plainly rather than glossed over.
Who we built it for
Newsrooms, investigative units, human rights organisations, corporate ethics and whistleblower programmes, and regulators who receive sensitive disclosures.
The problem
Organisations that need confidential submissions mostly use an email address, which exposes the source completely, or a hosted whistleblowing service whose operator can see everything and is subject to legal compulsion.
Sources are increasingly sophisticated and will not use a system they cannot verify, so the disclosures that matter most never arrive.
Try it before anything else
The free config generator runs in your browser with no account. Pick your options, and copy a working config straight away. Open it.
The one promise
The free tool on this site is genuinely free and genuinely useful. It does not withhold the answer behind an email form, it does not degrade after a trial, and it does not exist to harvest your data. If it helps you and you never pay us, that is a fine outcome.
Copy a config that actually runs
Pick authentication, region, client and limits. Copy a config and client snippet that run, with the latency they imply. Runs in your browser. No account, no card, no call.
Open the free toolIt runs in your browser. OpenCyph never sees your inputs.