Secure Drop
Anonymous · Encrypted · No login required
Your message is sealed and anonymous. We cannot identify you. No account or login is needed.
Your message
Max 3 files, 10 MB each
Secure Channel
Anonymous · Bidirectional · Encrypted
Start an anonymous conversation. You'll receive a thread code to check for replies later.
Your message
Max 3 files, 10 MB each
Thread Code
Enter your thread code above to check for replies.

Controlled Sharing

More control over what you send.

Choose how supported images and files can be opened, verified or signed. City of Hats brings these controls into the conversation instead of leaving every attachment to an ordinary download.

No phone number or email required for core Hat use.

City of Hats Send File dialog showing supported security controls
City of Hats · Controlled Sharing

The useful difference

Choose the control that fits the content.

01

View Once

A supported file is deleted from the delivery service after one download. A recipient may still retain a copy after opening.

02

Sealed File

Send a PIN-locked file and share the PIN separately when you are ready.

03

Verified Eyes Only

Require the supported biometric check before viewing.

04

GeoLock

Require the recipient to be in the approved area before viewing supported content.

05

NFCLock

Require a tap of the recipient’s NFC Hat. In the app this is labeled “Hat Tap to Unlock.”

06

VoiceLock

Require the recipient’s supported voice verification before viewing.

07

Verified Digital Signature

Request a PKI/PAdES-signed PDF. This workflow requires appropriate signer enrollment.

08

Signature Request

Ask the recipient to sign and return a signed copy of a supported PDF.

09

Certified Send

Use protected viewing with proof of access for a supported PDF.

How it works

Three deliberate steps.

01

Add your content

Open a Hat channel and choose an image or file to send.

02

Choose a mode

Review the controls offered for that content type. Some controls need enrollment, hardware or recipient support.

03

Send with clear expectations

Tell the recipient what is needed to open or sign the file. Share a PIN through a separate trusted route.

Know the boundary

Choose controls with clear expectations.

Some controls rely on the app or service. They do not guarantee that recipients cannot photograph a screen or retain content after opening. Signature workflows and Certified Send are offered for supported PDFs; legal effect depends on the context. Recall is an additional app control, not a guarantee that all recipient copies can be erased.

Review the security evidence

Questions, answered

Before you get started.

Can I use every mode for every file?

No. The app shows the controls supported for the selected image or file. PDF signature workflows, hardware requirements and enrollment can limit availability.

Do these modes prevent every copy?

No. App and service controls reduce specific risks, but a recipient may keep a downloaded file, photograph a display or use a compromised device.

City of Hats is free to use. Feature availability and limits vary by plan and client. Premium is optional; review current limits in the app or on the plans page.

Explore what matters next

Build the workflow around your work.

Start with a Hat

Give sensitive work its own space.

Start free. Choose your controls as the work requires them.