Digital Security Handbook.
When questioning structural power, your operational security is paramount. Read this carefully before submitting sensitive documents.
1. The Legal Reality in India
India currently lacks absolute shield laws for whistleblowers and journalists. The state can compel organizations to hand over user data, IP addresses, and communication logs under the Digital Personal Data Protection (DPDP) Act and the Bharatiya Nagarik Suraksha Sanhita (BNSS).
Never assume a standard web form or email is safe. Even if we have a strict zero-logging policy on our servers, your ISP or the cellular network can log the metadata of your connection.
2. How to Submit Anonymously
- Use the Tor Browser: Do not use Chrome, Safari, or regular Firefox. Download the Tor Browser to mask your IP address and route your traffic through encrypted relays.
- Scrub Document Metadata: Before uploading PDFs or images, remove EXIF data. Tools like Dangerzone or ExifTool can strip hidden author tags, GPS coordinates, and device information from files.
- Do Not Use Work Devices: Never use a university Wi-Fi network, a government-issued laptop, or your personal cellular connection to submit leaks. Use a public Wi-Fi network while running Tor.
- End-to-End Encryption: For direct communication with journalists or our researchers, use Signal (with disappearing messages enabled) or PGP-encrypted email (e.g., ProtonMail). Avoid WhatsApp, as metadata is shared with Meta.
Our Commitment (Zero-Logging Policy)
The EduRep Secure Intake Portal is configured to drop all origin IP addresses. We do not store browser user agents, timestamps of submission, or tracking cookies.
However, we cannot protect data intercepted before it reaches our servers. You must take the technical precautions listed above.