Secure Drop
Anonymous · Encrypted · No login required
Your message is sealed and anonymous. We cannot identify you. No account or login is needed.
Your message
Max 3 files, 10 MB each
Secure Channel
Anonymous · Bidirectional · Encrypted
Start an anonymous conversation. You'll receive a thread code to check for replies later.
Your message
Max 3 files, 10 MB each
Thread Code
Enter your thread code above to check for replies.
PRACTICAL SECURITY WORKFLOWS

Security playbooks for high-stakes communication

Six concrete starting points for configuring identity, delivery, proof, and message controls. Each playbook names the threat it addresses, the City of Hats features that may help, and the risks no messaging product can remove.

Version 1.0 · Reviewed 10 August 2026

Choose the workflow closest to yours

These are educational baselines, not guarantees or substitutes for legal, regulatory, or professional security advice.

JOURNALISM

Journalist–source intake

Let a new source make first contact without joining the journalist’s ordinary address book or exposing a carrier number.

Recommended workflow

  • Publish a dedicated Sealed Tip or Hat intake route separate from personal accounts.
  • Use a Disposable Hat for a single story or source relationship.
  • Verify identity through an independent channel before trusting high-impact material.
  • Move sensitive files into an appropriate security mode and agree on a deletion window.
  • Document an emergency device-loss plan before the first exchange.
Limitations: A compromised endpoint, malicious recipient, photographed screen, traffic observation, or physical coercion can still expose a source or story.
EXECUTIVE TRAVEL

Travel and device-inspection plan

Reduce how much sensitive context is carried across borders or exposed when a device is inspected, lost, or stolen.

Recommended workflow

  • Use a trip-specific Disposable Hat rather than a permanent work identity.
  • Minimize retained conversation history before travel and agree on a re-keying plan after return.
  • Use GeoLock only when location-gated access helps more than the location dependency hurts.
  • Prefer short-lived controls for especially sensitive content.
  • Assume an unlocked or compromised device can reveal plaintext and plan accordingly.
Limitations: Cryptography cannot prevent compelled unlocking, physical coercion, device malware, or disclosure of information already read and remembered.
INCIDENT RESPONSE

Out-of-band incident coordination

Establish a communication path that does not depend on the potentially compromised corporate email or collaboration tenant.

Recommended workflow

  • Pre-stage verified emergency Hats before an incident and store verification material offline.
  • Use a dedicated Phrase ID only where its discoverability matches the threat model.
  • Confirm role changes and key decisions through a second channel.
  • Use Certified Send for operational acknowledgements that require evidence.
  • Maintain a non-digital fallback because any app or network can become unavailable.
Limitations: City of Hats cannot guarantee service availability, validate the truth of every participant claim, or secure an already compromised response device.
HEALTHCARE

Sensitive clinic intake

Collect and discuss sensitive information while minimizing identifiers and applying clear access controls.

Recommended workflow

  • Define which records belong in the clinical system of record and which communications should remain transient.
  • Use a clinic-specific intake route and verify the patient before disclosing results.
  • Apply Verified Eyes Only, PIN, or another security mode only after accessibility review.
  • Set retention and escalation procedures outside the messaging tool.
  • Complete legal, privacy, and vendor-risk review before regulated production use.
Limitations: This playbook does not claim HIPAA, GDPR, PIPEDA, or local health-law compliance. Compliance depends on contracts, configuration, workflow, jurisdiction, and organizational controls.
ETHICS & COMPLIANCE

Anonymous employee reporting

Offer a reporting route that does not require the reporter to disclose a personal phone number or email address.

Recommended workflow

  • Publish a Sealed Tip route with a plain-language anonymity and retention notice.
  • Limit case-handler access and separate intake from investigation identities.
  • Use a case-specific Hat for follow-up without asking for a personal address-book identifier.
  • Explain what technical and organizational metadata may still exist.
  • Define escalation, evidence handling, and anti-retaliation procedures outside the app.
Limitations: Anonymity can be undermined by writing style, submitted files, workplace networks, cameras, organizational access logs, or facts known only to a small group.

Controls shared by every playbook

  • Verify people and keys independently when impersonation matters.
  • Treat recipient behavior and endpoints as part of the system.
  • Minimize retained data instead of relying on deletion as a perfect eraser.
  • Keep an availability fallback and an incident escalation route.
  • Use the Threat Model Advisor before adopting a playbook unchanged.

Turn the playbook into your own plan

Answer five private, browser-only questions to identify the controls and limitations most relevant to your situation.