An open-source whistleblower submission system — a project of @FreedomofPress Foundation
Joined October 2013
- Tweets1K
- Following48
- Followers17.2K
- Likes42
We have updated our guidance for sources, to warn against using AI chatbots or services linked to their personal identity.
We also strongly recommend that newsrooms using SecureDrop update their landing pages with these new warnings.
securedrop.org/news/updated-…
We will be rotating the SecureDrop release signing key next year.
This is a routine signing key rotation; the current key is still secure and in active use.
The new key will be distributed in releases later this year and start signing releases in 2027.
securedrop.org/news/new-rele…
SecureDrop Workstation 1.9.0 is now available!
This release hardens the updater against some edge cases discovered during the 1.8.0 release.
securedrop.org/news/securedr…
"It could be as significant an upgrade as HTTPS."
A nice explainer of WEBCAT, our project to make JavaScript tamper-proof and the web a safer place for everyone:
blog.siv.org/2026/07/verifia…
SecureDrop Workstation 1.8.0 and SecureDrop Inbox 1.5.0 are now available!
These releases add support for Debian 13 “trixie” and automatically upgrade the underlying VMs.
securedrop.org/news/securedr…
SecureDrop 2.16.0 is now available, with a number of improvements to APIv2, and a fix for a low-severity security vulnerability:
securedrop.org/news/securedr…
SecureDrop Inbox 1.4.0 is now available!
This release fixes a number of accessibility-related issues and fully removes the legacy client package:
securedrop.org/news/securedr…
SecureDrop Inbox 1.3.1 is now available!
This release fixes a low-priority security issue in the securedrop-proxy component.
securedrop.org/news/securedr…
SecureDrop Inbox 1.3.0 is now available!
This release adds a label to show the number of selected sources, disables downloading of files in offline mode, and updates a number of dependencies.
securedrop.org/news/securedr…
And thanks to the generous matchfunders @cakewallet, @ZcashCommGrants, @Logos_network, and @OctantApp.
Want to be a part of it? A crypto gift can maximize your impact:
internetfreedom.torproject.o…
We're grateful to @TorProject and @FundingCommons for including us in this crowdfunding campaign alongside nine other cool projects as a new way to fund internet freedom!
internetfreedom.torproject.o…
SecureDrop Inbox 1.1.0 is now available!
This version fixes a number of small issues that didn’t make it into the previous release.
securedrop.org/news/securedr…
SecureDrop 2.15.1 is now available, improving memory management while handling APIv2 requests, and fixing an issue with restoring backups without transferring over the network:
securedrop.org/news/securedr…
We're getting closer to the release of the brand new SecureDrop Inbox — today we're publishing results from the security audit we commissioned to ensure it's safe before putting it in the hands of journalists.
securedrop.org/news/audit-of…
Replying to @SecureDrop
This is the result of work begun by the SecureDrop team in July 2025 to completely overhaul how journalists process submissions. SecureDrop Workstation users will receive it automatically during a system update in the next few weeks.
securedrop.org/news/securedr…
SecureDrop 2.15.0 is now available, which enables the updated API needed for the upcoming SecureDrop Inbox.
securedrop.org/news/securedr…
SecureDrop Client 0.17.5 has been released to address a low-priority security issue. Exploiting this vulnerability would require a compromised server, and we are not aware of any exploits in the wild.
securedrop.org/news/securedr…
SecureDrop Inbox, the new window into the SecureDrop Workstation, has been rewritten to replace the previous client for journalist users.
Improving upon the core functionality, it also includes bug fixes, speed improvements, and a range of new features.
securedrop.org/news/new-feat…
SecureDrop Workstation 1.5.2 has been released, as well as SecureDrop Client 0.17.4.
This update contains multiple security fixes, all of which are low or informational priority. We are not aware of any exploitation in the wild for any vulnerability.
securedrop.org/news/securedr…