Skip to main content

Secure Source Handovers for Investigative Journalists

How to receive sensitive documents from sources safely: choosing the right channel, stripping metadata, documenting the chain of custody, and managing digital and physical security.

Last reviewed: Next review due:

Why handover security matters as much as communication security

Most journalists focus on securing their communications with sources. But the handover moment — when a document or dataset physically or digitally changes hands — is one of the most forensically visible points in an investigation. A document carries metadata that can reveal who created it, when, and on which device. A USB drive can be tracked. An email attachment leaves server logs. A cloud upload creates a copy that may never be fully deleted.

UK journalists operate in a legal environment where the Investigatory Powers Act 2016 gives agencies broad powers to obtain communications data, and where police can seek production orders under PACE 1984 Schedule 1 for journalistic material. If a source is identified through a document handover — not through anything you said or wrote, but through metadata, server logs, or a physical trail — you have failed in your core duty of source protection.

This guide covers the practical protocols for digital and in-person handovers, metadata hygiene, chain of custody documentation, and the decisions you need to make about what to retain, what to delete, and when.

Handover methods: digital and physical

SecureDrop

Lowest digital risk

Tor-routed anonymous submission platform. Source uploads documents via Tor Browser without revealing their IP. Best for: anonymous sources, high-sensitivity documents. Requires your outlet to operate a SecureDrop instance. Check the Freedom of the Press Foundation's directory for outlets that do.

OnionShare

Low digital risk

Allows a source to host a temporary Tor onion service on their own machine to send files directly, or receive them. No server required. Both parties need Tor Browser. Good for: one-off large file transfers where SecureDrop is not available.

Signal (with precautions)

Moderate digital risk

End-to-end encrypted messaging. Enable disappearing messages. Use on a dedicated device not linked to your main identity. Be aware that metadata (who communicated, when) may be accessible through communications data requests even if content is encrypted.

In-person physical handover

Low risk if conducted carefully

Meeting in a location with no CCTV, no mobile phone signal (leave phones at a separate location to avoid location data correlation). Encrypted USB stick. Source should use a device and USB that cannot be linked to them. Never the journalist's office or the source's workplace.

Encrypted email (PGP)

Moderate digital risk

Content is encrypted but email metadata (sender, recipient, timestamp, subject line) is visible in server logs. Suitable only when email is the only option and the metadata exposure is acceptable given the risk profile. Use ProtonMail or Tutanota which have minimal metadata logging.

When secure handover protocols are essential

  • 1Any handover from a source who could face serious employment, legal, or personal consequences if identified.
  • 2Documents that were printed or exported from internal systems — printer metadata and document tracking may identify the source.
  • 3Large datasets where internal tracking codes or unique formatting might identify the source even after apparent anonymisation.
  • 4Handovers from sources in the public sector, particularly police, intelligence, defence, or civil service.
  • 5Any handover involving national security, organised crime, or matters subject to court reporting restrictions.
  • 6When your source has already been warned that the organisation is monitoring for leaks.

Red flags that increase exposure risk

  • Using your personal or work email for sensitive document transfer — email servers log metadata.
  • Opening source documents directly on a device connected to the internet before stripping metadata.
  • Cloud sync services (iCloud, Google Drive, OneDrive) enabled on the device used for secure document work.
  • Receiving large files over standard email which creates logs on both sending and receiving mail servers.
  • Meeting a source near your workplace, their workplace, or any location with CCTV coverage of your regular movements.
  • Using a phone in the vicinity of a sensitive in-person handover — location data can be subpoenaed.
  • Forgetting to check a document for embedded printer steganography (yellow dot tracking) before publication.

Secure handover checklist

  • I have chosen a handover method proportionate to the risk — highest-risk sources use SecureDrop or in-person.
  • I have advised the source to use Tor Browser for any digital submission.
  • I have opened received documents on a device not connected to cloud sync services.
  • I have stripped metadata from all received documents using ExifTool or MAT2 before storing or sharing them.
  • I have checked for printer steganography if documents appear to have been printed from an internal system.
  • I have documented the chain of custody: when, how, and in what form I received the material.
  • I have stored the original documents in an encrypted folder (VeraCrypt or equivalent).
  • I have deleted from my regular devices any copies of sensitive documents that are not needed for ongoing work.
  • I have consulted my NUJ rep or a media lawyer about my obligations to retain or delete material if legally required.
  • I have talked to my outlet's IT team or NUJ security adviser about the specific security profile of this investigation.

Source protection tools

Use our Source Protection Guide for a full protocol, and the Investigation Risk Register to track your security decisions throughout the investigation.

Common mistakes

  • Opening source documents on a regular work or personal device before stripping metadata.
  • Forwarding documents to colleagues over regular email to get a second opinion — creating additional server log records.
  • Not realising that cloud sync was running silently in the background when working with sensitive documents.
  • Using WhatsApp instead of Signal — WhatsApp's metadata (who communicated with whom) is not end-to-end encrypted.
  • Conducting sensitive in-person meetings with a mobile phone present — even in flight mode, some location data may be logged.
  • Assuming that deleting a file also deletes all copies — check cloud sync, email sent items, backup drives.
  • Not maintaining a chain of custody document — if the investigation is later challenged, you need to show provenance.

Related guides

Primary sources

Frequently asked questions

What is SecureDrop and does my outlet need to run it?
SecureDrop is an open-source whistleblower submission platform that routes documents through the Tor anonymity network. It was designed by the Freedom of the Press Foundation. Running SecureDrop requires a dedicated, air-gapped server and technical administration — it is most suitable for larger newsrooms. Many UK outlets including The Guardian, BBC, and The Times operate SecureDrop instances. If your outlet does not, you can advise sources to use the SecureDrop instances of other newsrooms if they are willing to share the story, or use alternative secure channels such as OnionShare.
Is Signal secure enough for receiving source documents in the UK?
Signal is end-to-end encrypted and provides strong security for communications. However, it has limitations for document handover: the documents land on a device (your phone or computer) that may be subject to legal seizure; Signal's desktop client syncs across devices; and metadata about who you are communicating with may be accessible through communications data requests even if the content is encrypted. For the highest-risk handovers, Signal should be used on a dedicated device that does not also carry your regular communications. For very sensitive material, SecureDrop or an in-person physical handover is preferable.
What metadata is embedded in documents and why does it matter?
Digital documents often contain metadata that can identify the source: Word documents embed author name, creation date, and sometimes track-changes history. PDFs may contain creator information, print dates, and printer identifiers. Images contain EXIF data including device, GPS coordinates, and timestamp. Spreadsheets retain version history. A document printed from a digital system may contain invisible printer steganography — tiny yellow dots encoding the serial number of the printer. Before publishing or storing documents, use a metadata-stripping tool such as ExifTool (command line) or MAT2 (Metadata Anonymisation Toolkit). Never publish original files without checking and stripping metadata.
Should I delete my logs and communications after a handover?
This is a judgment call that requires understanding the specific risk profile. If a source is at serious risk of identification, deleting encrypted communications after the handover reduces the forensic exposure of both parties. However, also consider: you may need to reconstruct the chain of custody for legal or editorial purposes; deleting communications that are subject to a legal hold order may constitute contempt or obstruction. In general: delete what you do not need to keep; retain what you need for editorial or legal defence purposes in an encrypted form; and take advice from your NUJ or a media lawyer about specific cases.
What are the cloud sync risks for documents received from sources?
Cloud synchronisation services (iCloud, Google Drive, OneDrive, Dropbox) automatically copy files from your device to cloud servers, where they may be accessible to the provider and, through legal process, to authorities. If you open a sensitive document on a device that is connected to a cloud sync service, the document may be automatically copied to the cloud without your awareness. Disable cloud sync on any device you use for sensitive document work, or use an air-gapped machine that is never connected to the internet for the most sensitive material.