Trust this desk in plain language

Desk charter

Operator identity without doxxing. Practices you can hold us to — not a promise of publication or legal immunity.

What we accept
Documents, media, and short sealed messages of public-interest concern. We take source protection seriously. We do not solicit crime, child sexual abuse material, or threats of violence.
What we decline
Spam, malware bombs, pure private disputes with no public stake, and anything we cannot assess safely. Decline does not always produce a reply.
Response time
Best-effort review, typically within a few days to two weeks when the desk is active. Not 24/7. No SLA. Silence is not confirmation of receipt beyond your local receipt file.
Languages
Desk review primarily in English. The public site UI is multilingual; sealed content in other languages may take longer or need trusted help to assess.
Jurisdiction posture
Operators and hosting sit under real-world law. Ciphertext on disk can still be seized. We do not claim extraterritorial immunity. Prefer Tor for network-level risk reduction.
Follow-up
Optional sealed thread after review (off by default). If opened, you use your offline receipt — no account. We never ask you to re-upload the private receipt key.
Contact (low sensitivity)
Operational mail: @SafeDepositOrg (low-sensitivity public contact · sealed drop for tips). Official X (corroboration / public updates — not for high-risk tips): @SafeDepositOrg. Do not put high-risk tips in ordinary email or DMs.

What happens after you submit

  1. Your browser seals the package to the published operator public key(s). The server stores ciphertext only (plus blind metadata: id, size, expiry, content commitment).
  2. You receive a receipt JSON in the browser. Download it offline. It holds the deposit id, content commitment, receipt token, and optional follow-up private key.
  3. The deposit sits until an operator downloads ciphertext offline and decrypts with a key that is not on the upload host (by design).
  4. Review is human and discretionary. There is no automatic publication, no guaranteed story, and no legal representation.
  5. If a sealed follow-up channel opens later, check receipt status with the same file. Clear browser data on shared machines.
  6. Deposits auto-expire after the configured TTL if not handled. Treat expiry as normal hygiene, not a threat signal by itself.

You will not get an email confirmation. The receipt is your only portable proof of what you uploaded.

Threat-model honesty — protect / do not protect

What this design aims to protect

  • Content confidentiality against a compromised or seized upload server (no deposit private key on host).
  • Passive network observers of TLS/onion payloads (ciphertext in transit and at rest on the origin).
  • Submitter accounts and marketing trackers (none by design).
  • Casual phishing that reuses branding but not the published key fingerprint (if you verify).
  • Bulk abuse via proof-of-work and size limits (best-effort).

What this does not protect

  • Compromised devices — malware, screen capture, evil USB, workplace MDM.
  • Bad OPSEC — real names in filenames, personal accounts in the same session, clearnet habit patterns.
  • Global traffic analysis — Tor helps; it is not absolute against a global passive adversary.
  • Coerced or malicious operators who hold the offline private key can decrypt deposits they obtain.
  • Legal process against people, hosts, or canaries in jurisdictions that compel silence.
  • Physical safety or retaliation after disclosure — encryption is not a bodyguard.

This page is the short public honesty layer. Prefer the protect / do-not-protect list above plus key verification and the canary for operational trust checks.

Canary as a dead-man signal

The warrant canary states that, as of its publication date, the operator has not received secret compulsory process of the kind described in the statement. It is a transparency ritual, not courtroom proof.

Expired canary ≠ automatic proof of compromise. It may mean legal pressure, ops failure, or forgetfulness. Combine with key verification and a trusted onion.

Related