Newsrooms and press freedom

Protect the devices, people, and workflows behind sensitive journalism.

Secure Origin helps newsrooms and media-support teams protect staff devices, reduce phishing and account risk, secure source and reporting workflows, and validate defenses before a story, source, or incident forces the issue.

Request newsroom security review Use the source protection checklist
Service fit

Security for the reporting lifecycle.

This work is informed by direct experience with a worker-owned newsroom and community organizations, where source trust, staff safety, and limited internal capacity all matter.

Protect Devices
Endpoint visibility, posture, monitoring, patch exposure, alert triage, and monthly reporting for newsroom devices.
Protect People
Email security, phishing protection, identity review, user reporting, and staff awareness for reporters, editors, and operations staff.
Protect The Organization
Secure access, SaaS posture, sensitive source workflows, incident readiness, and leadership-ready reporting.
Security Testing & Validation
Testing, tabletop exercises, and control validation against reporting workflows, identity, cloud services, and exposed infrastructure.
Why it matters

Newsrooms hold source identities, reporting materials, communications, drafts, and pre-publication work that can put people at risk if exposed. The stakes stay high even when the team and budget are small.

When this matters

Security needs change across the reporting lifecycle.

Before sensitive outreach

Review accounts, devices, communication channels, shared folders, and source intake before contacting high-risk sources.

During active reporting

Protect drafts, web captures, FOIAs, source notes, legal materials, and collaboration spaces from accidental exposure.

After a threat or leak concern

Assess suspicious logins, device concerns, exposed files, or newsroom workflows that may put sources or reporters at risk.

Secure intake options

SecureDrop and GlobaLeaks fit different workflows.

SecureDrop

Best for high-risk investigative newsroom source intake where Tor-only submission, strict operational procedures, and air-gapped review workflows are justified.

GlobaLeaks

Often better for NGOs, legal aid organizations, advocacy groups, compliance programs, whistleblowing projects, and smaller teams needing flexible secure reporting workflows.

Secure contact first

Some teams only need clear Signal, PGP, policy, and escalation guidance before they are ready for a full anonymous intake platform.

How we help

Match the service to the workflow.

01
Intake
Clarify sources, reporters, publishing timelines, legal constraints, adversaries, and budget range.
02
Service selection
Choose Protect Devices, Protect People, Protect The Organization, validation work, or workspace support based on the reporting lifecycle and deadline.
03
Delivery
Improve protection, test risk, or set up a workspace within a clear scope.
04
Document boundaries
Make clear what the workflow protects, what it does not, and what to do when risk changes.
Next steps
Request review Book call