Skip to content
[ VOL. 24 / LAUNCH EDITION ]
SYNC // UTC
// FILE // SECURITY_PROTOCOLS

Security Protocols

How to send sensitive information responsibly, and the limits of what we can protect.

People sometimes want to send a publication material they consider sensitive. Before you do, you deserve a plain account of what ReportUltra can and cannot protect. Our short answer: we are a small, independent publication, and at launch we have no secure drop.

What we do not have

There is no encrypted submission portal, no anonymous upload system and no dedicated secure messaging channel. The only way to reach us is the address [email protected]. Standard email is not end-to-end encrypted. Messages can be read by mail providers along the route, may be stored in several places, and can be linked to your address, your device and your network.

We will not pretend otherwise, and we will not offer promises of anonymity that we cannot keep.

What we ask you not to send

  • Classified material. Do not send information that is classified or protected by law, including state secrets.
  • Illegally obtained material. Do not send data you accessed without authorization, stolen credentials, or the contents of breached systems.
  • Personal data of others. Do not send private records, identity documents or financial account details belonging to third parties.
  • Anything that could put you at serious risk. If sending it could endanger you or someone else, do not send it by email.

If you are unsure whether something is safe or lawful to share, the safest step is to share nothing and seek independent legal advice first.

If you still want to write to us

Describe the topic in general terms rather than attaching documents. Tell us what you know, what you do not, and how you came to know it. We can discuss next steps from there. Consider writing from an address that does not identify you, and think about the device and network you use. Remember that our launch-edition dossiers are illustrative scenarios, so we are not set up to receive or verify sensitive documents in the way an investigative newsroom might be.

Reporting a vulnerability on this site

If you find a security weakness in the ReportUltra website, we would like to hear about it. Email [email protected] with a clear description of the issue, the page involved and the steps needed to reproduce it. Please do not access data that is not yours, disrupt the service or publish details before we have had a reasonable chance to respond. We cannot offer rewards, but we will read your report and fix real problems.

Keeping this page honest

If we add stronger options later, this page will say so, and will describe their limits just as plainly. Until then, treat email as a postcard: assume that others could read it.