Name the asset
Identify the information, identity, relationship, or proof that needs protection.
Answer five short questions to turn a vague security concern into a practical communication plan, relevant City of Hats features, and the limits you still need to manage.
Choose the answer that best matches your situation.
The advisor combines the sensitivity of the information, the likely adversary, identity exposure, delivery needs, and endpoint condition. The result prioritizes controls; it does not certify that a situation is safe.
Identify the information, identity, relationship, or proof that needs protection.
Distinguish networks, services, impostors, recipients, compromised devices, and physical access.
Choose controls that address the named threat and document what remains outside their protection.
No. The assessment runs in your browser. It does not submit your selections to City of Hats or require an account.
No. It means your selections include endpoint, identity, metadata, recipient, or physical risks that need more than basic encrypted messaging.
No. It is an educational starting point. Organizations and people facing targeted threats should seek qualified legal, security, or operational advice appropriate to their circumstances.
A security control is useful only when its boundary is understood. Encryption protects particular data paths; it does not automatically secure devices, recipients, metadata, or physical safety.
Use the Security Evidence Center to review architecture, data boundaries, limitations, and current verification status before relying on a feature.