If you have ever wondered what SecureDrop is and how it works, the short answer is that it is a purpose-built system for sending sensitive documents to journalists without revealing who you are. It runs as a Tor onion service, and it was designed from the ground up for people who have real reasons to fear being identified.

What SecureDrop actually is

SecureDrop is free, open-source software that news organizations and some NGOs install to receive tips, documents, and messages from sources and whistleblowers. It is not an email inbox and not a cloud storage folder. It is a self-contained system that a newsroom runs on its own servers.

According to SecureDrop's own documentation, no personal information is collected from a source, and everything submitted is encrypted. If what you want to share is not especially sensitive, the documentation itself suggests a phone call or ordinary email may be simpler and more appropriate.

Where it came from

SecureDrop began as a project called DeadDrop, designed by Aaron Swartz and investigative reporter Kevin Poulsen, with James Dolan also credited as a co-creator. After Swartz's death, the first working instance launched at The New Yorker on May 15, 2013, under the name Strongbox.

The Freedom of the Press Foundation then took over development and renamed the project SecureDrop. The foundation has described it as the strongest submission system it could make available to newsrooms, while acknowledging that no security system is ever completely impenetrable.

Since then, SecureDrop has been adopted by major outlets on both sides of the Atlantic, including The New York Times, The Guardian, the Financial Times, and the Associated Press, according to research published on the tool's use in newsrooms.

How it works from the source's side

The source-facing side of SecureDrop is deliberately simple compared to what happens behind the scenes. A source visits the newsroom's SecureDrop onion address using Tor Browser and is given a unique, randomly generated codename rather than any account tied to a real identity.

That codename is used to log back in later and check for replies from the journalist, without ever exchanging names, emails, or phone numbers. Sources can submit written messages and file uploads, with the platform documentation noting a per-file limit of up to 500MB, and multiple files can be sent if needed.

How it works from the newsroom's side

On the journalist's end, the process is intentionally slow and layered. Reporting from the Columbia Journalism Review describes a setup where checking the SecureDrop inbox requires logging into one specific, isolated computer, and viewing or printing any documents requires switching to an entirely separate machine.

That separation exists to reduce the chance that malware in a submitted file or a compromised everyday laptop could expose who sent what. It also means SecureDrop requires dedicated hardware, trained staff, and ongoing maintenance.

How newsrooms vet what arrives

Receiving a document anonymously is only the first step. Journalists still have to establish whether a submission is genuine before it becomes part of a story, and SecureDrop does not do that verification for them.

This vetting process is standard investigative journalism practice. SecureDrop changes how a tip arrives safely; it does not change the editorial standards applied once it does.

What Tor does, and does not, guarantee

SecureDrop only works as a Tor onion service, accessed through Tor Browser, the browser maintained by the Tor Project. Tor routes your connection through multiple relays so that the newsroom's server does not see your real IP address on arrival.

That is meaningful protection, but it is not automatic anonymity. Tor does not stop you from accidentally identifying yourself: writing in a distinctive style, mentioning identifying details in your message, or reusing a codename alongside other accounts can undo the protection Tor otherwise provides.

Using a separate device you do not normally use, avoiding personal account logins during the same session, and thinking carefully about what details you include in a submission all matter as much as the tool itself.

Finding a real SecureDrop address safely

The only safe way to find a newsroom's SecureDrop address is on that newsroom's own official website, on the surface web, where it will usually be listed alongside instructions for sources. Verify it there before using it.

Do not trust SecureDrop links found on general-purpose onion directories or "link list" sites. Directories like various copies of the Hidden Wiki are not curated or verified. They are collections of clones and copycats, and some entries are outdated, mislabeled, or outright scams. A link claiming to be a newsroom's SecureDrop is worthless unless it traces back to that organization's own site.

Who SecureDrop is actually for

SecureDrop is built for people with a genuine, often serious reason to protect their identity: employees exposing wrongdoing, people documenting abuses of power, or sources facing real personal or legal risk if identified.

For a routine tip or a story idea with nothing sensitive attached, the added friction of SecureDrop is unnecessary and the documentation itself says so. It exists for cases where anonymity is not a preference but a requirement for someone's safety.