Secure Drop
Anonymous · Encrypted · No login required
Your message is sealed and anonymous. We cannot identify you. No account or login is needed.
Your message
Max 3 files, 10 MB each
Secure Channel
Anonymous · Bidirectional · Encrypted
Start an anonymous conversation. You'll receive a thread code to check for replies later.
Your message
Max 3 files, 10 MB each
Thread Code
Enter your thread code above to check for replies.
INTERACTIVE SECURITY PLANNING

What are you protecting—and from whom?

Answer five short questions to turn a vague security concern into a practical communication plan, relevant City of Hats features, and the limits you still need to manage.

Runs only in your browserYour answers are not submitted, stored, or added to analytics. This tool provides educational guidance, not a guarantee of safety.
Start the assessment
YOUR ASSESSMENT

Threat Model Advisor

Choose the answer that best matches your situation.

What kind of information are you protecting?

Choose the closest match; you can rerun the advisor for another situation.

HOW IT WORKS

A threat model is a decision, not a fear score

The advisor combines the sensitivity of the information, the likely adversary, identity exposure, delivery needs, and endpoint condition. The result prioritizes controls; it does not certify that a situation is safe.

1

Name the asset

Identify the information, identity, relationship, or proof that needs protection.

2

Name the adversary

Distinguish networks, services, impostors, recipients, compromised devices, and physical access.

3

Accept the boundaries

Choose controls that address the named threat and document what remains outside their protection.

STRAIGHT ANSWERS

Threat Model Advisor FAQ

Does the advisor send my answers to City of Hats?

No. The assessment runs in your browser. It does not submit your selections to City of Hats or require an account.

Is a “high attention” result proof that I am in danger?

No. It means your selections include endpoint, identity, metadata, recipient, or physical risks that need more than basic encrypted messaging.

Can the result replace a professional security assessment?

No. It is an educational starting point. Organizations and people facing targeted threats should seek qualified legal, security, or operational advice appropriate to their circumstances.

Why does the advisor discuss limitations?

A security control is useful only when its boundary is understood. Encryption protects particular data paths; it does not automatically secure devices, recipients, metadata, or physical safety.

Verify the claims behind the recommendations

Use the Security Evidence Center to review architecture, data boundaries, limitations, and current verification status before relying on a feature.

Open the Security Evidence Center