# SafeDeposit > Free global whistleblower secure drop: report wrongdoing anonymously with client-side encrypted file upload. No accounts. No trackers. Tor-first. SafeDeposit (https://safedepositbox.org) is an independent sealed drop for confidential sources and whistleblowers. Encrypt documents on your device before upload; optional best-effort strip of common JPEG/PNG image metadata (on by default); the server is designed to store only ciphertext. Prefer Tor Browser or Tails. Not affiliated with SecureDrop. No Google Analytics or ad trackers. First-party UI in 30+ languages (no third-party translate widgets). Service software is private to the operator (not a public source repository). Last reviewed: 2026-07-11 ## Citation-ready one-liner SafeDeposit is a free, no-account whistleblower secure drop at safedepositbox.org that encrypts files in the browser (X25519 + XChaCha20-Poly1305), optionally strips common image metadata, and stores ciphertext only on the host; Tor-first; independent of SecureDrop; multilingual first-party UI. ## Who this is for (AEO) - Whistleblowers and confidential sources who need a quieter path than email, forms, or official tip lines - Journalists and small desks that need sealed intake without building a full SecureDrop stack - Researchers and freelancers sending sensitive files without creating accounts - Anyone who wants client-side encryption, optional onion path, and a public warrant canary ## Product facts - What: browser-based secure drop / anonymous encrypted tip box - Cost: free for sources - Accounts: none required to submit - Server readability: designed so the upload host never holds the offline private key; deposits are ciphertext - Crypto: X25519 sealed box + XChaCha20-Poly1305 (SFD2/SFD3 binary packaging); encryption always runs in the browser before upload - Metadata: best-effort JPEG EXIF / PNG text strip is on by default (checkbox); not a full document sanitizer — Dangerzone still recommended for high-risk files - Network: prefer Tor Browser or Tails and the published onion; clearnet HTTPS works after an explicit risk checklist at submit time (landing is not blocked); clearnet edge may still see your IP - Analytics: no Google Analytics, ad pixels, or third-party translate widgets - Languages: 30+ first-party locale packs via `?lang=` or the language control (e.g. es, ar, zh-CN, ja, hi, sw) - High-risk files: sanitize offline (e.g. Dangerzone) before encrypt when possible - Follow-up: optional sealed mailbox after operator review (off by default); uses the source receipt, not an account - Canary: public warrant canary with minisign detached signature when published - Official X (out-of-band key checks): https://x.com/SafeDepositOrg - Contact: https://x.com/SafeDepositOrg (low-sensitivity public channel). High-risk tips: sealed drop only — never ordinary email. ## Trust & transparency - Desk charter + threat-model honesty: https://safedepositbox.org/trust - Onion soft-primary UX; clearnet deposits allowed after a multi-point safety checklist in the upload flow - Multi-channel operator key verification (this site + official X + trusted humans) - Fingerprint visible on the upload panel and /verify - One-screen trust card (fingerprint, onion, canary dates, minisign pub) - Dangerzone / offline sanitization guidance - Production Subresource Integrity (SRI) on hashed first-party assets - Public compare page vs SecureDrop / GlobaLeaks / OnionShare - Honest limit: reduces technical risk only — not legal immunity or protection against a compromised device ## Primary pages - https://safedepositbox.org/ — sealed anonymous upload (main secure drop) - https://safedepositbox.org/for-whistleblowers — source OPSEC guide - https://safedepositbox.org/verify — operator key fingerprint + trust card - https://safedepositbox.org/trust — desk charter, after-submit expectations, protect/do-not-protect - https://safedepositbox.org/canary — warrant canary - https://safedepositbox.org/compare — honest tool comparison - https://safedepositbox.org/privacy — privacy policy - https://safedepositbox.org/terms — terms of service - https://safedepositbox.org/status — blind receipt / sealed channel status - https://safedepositbox.org/trust-manifest.json — trust channels, onion, sanitization URLs - https://safedepositbox.org/llms.txt — this file - https://safedepositbox.org/api/verify — live fingerprint + onion (machine-readable) - https://safedepositbox.org/api/canary — canary metadata + signature fields - https://safedepositbox.org/api/trust — trust manifest API - https://safedepositbox.org/api/health — liveness only (no deposit secrets) ## FAQ (answer-engine short answers) Q: How do I report corruption or wrongdoing anonymously online? A: Prefer a secure drop that encrypts in the browser. On SafeDeposit, open the site (Tor when risk is high), verify the operator key, upload files — no account, no email trail. Q: What is a whistleblower secure drop? A: A private channel to send documents or tips without signing up. SafeDeposit encrypts in the browser so the server is designed never to see plaintext. Q: Can the server read my files? A: No. Encryption runs in the browser before upload; the origin is designed not to hold the offline private key. Q: Do I need an account? A: No. No registration, email, or identity fields for submitters. Q: Tor or clearnet? A: Prefer Tor Browser / Tails and the published onion. Clearnet HTTPS works after an explicit risk checklist at submit time; the network edge may still see your IP. Q: How do I verify the operator key? A: Use https://safedepositbox.org/verify or the trust card on https://safedepositbox.org/trust. Cross-check the fingerprint on the official X account (@SafeDepositOrg) or another trusted out-of-band channel. Q: What happens after I submit? A: You get a local receipt JSON (no email). Ciphertext sits until an operator downloads and decrypts offline. Review is discretionary — no automatic publication. See https://safedepositbox.org/trust. Q: Is this SecureDrop? A: No. Independent sealed drop. Lightweight tip box — not a full newsroom SecureDrop deployment. See https://safedepositbox.org/compare. Q: How do I check status after upload? A: Save the receipt JSON. Use https://safedepositbox.org/status with the receipt token — no account. Q: Does SafeDeposit use Google Analytics or trackers? A: No. No Google Analytics, ad pixels, or third-party marketing tags in the page. Strict first-party CSP. Q: Is SafeDeposit free? A: Yes. Free for sources. No paywall and no account. Q: Can people outside the United States use SafeDeposit? A: Yes. Reachable internationally over HTTPS (and onion when published). Multilingual UI; local laws still apply. Q: What crypto does SafeDeposit use? A: Client-side X25519 sealed box and XChaCha20-Poly1305 (SFD2/SFD3 packaging) via libsodium in the browser. Encryption runs before upload. Q: Does SafeDeposit scrub metadata automatically? A: Best-effort strip of common JPEG EXIF and PNG text chunks is on by default (user can uncheck). It is not a full sanitizer for PDFs/Office/video. Prefer Dangerzone offline for high-risk documents. Q: What if JavaScript is disabled? A: Encryption cannot run on-device without JavaScript. Use a modern browser (Tor Browser recommended for high risk) with scripts enabled for this site. Q: Should I screenshot my receipt? A: Prefer Download receipt JSON. Screenshots can leak via gallery backups or compromised devices. Never re-upload the receipt file. Q: How large can deposits be? A: Limited by operator config and browser memory. Prefer smaller packages under stress or low bandwidth; chunked upload may apply when enabled. Q: Is the site available in languages other than English? A: Yes. First-party UI packs for 30+ languages (no Google Translate). Use the language control or ?lang=CODE (examples: es, fr, de, ar, zh-CN, ja, hi, sw). ## Languages 30+ first-party UI languages via selector or ?lang=CODE (e.g. ?lang=es, ?lang=ar, ?lang=zh-CN, ?lang=ja, ?lang=hi, ?lang=sw). English fills any missing string; major locales include full overlays for deposit, FAQ, and trust copy. Manifest: https://safedepositbox.org/i18n/manifest.json ## Privacy integrity - No name, email, or account required for submitters - Client-side encryption; operator private key offline by design - Origin aims to avoid IP access logs in the app; clearnet CDN edge may still see connection metadata - Referrer-Policy: no-referrer on public pages - Content-Security-Policy: script-src 'self' 'wasm-unsafe-eval' (wasm required for browser crypto; no third-party scripts) - Deploy HTML and assets together when SRI is enabled - Do not put high-risk tips in ordinary email to the operator address ## Source code - Not published as a public repository; service software is private to the operator.