What we look for.
Each card below opens a separate, dedicated questionnaire we configured; Find if you fit in any of it, and then keep reading the page for all the necessary security practices.
You work with facial-recognition technology.
You know how a system is built, what it covers, and who touches the data. Not every question needs an answer.
Open this questionnaireYou know where a deployment falls apart.
You've seen where a specific system is misconfigured, poorly maintained, or easy to spot from the outside. Tell us what to look for, and where.
Open this questionnaireYou've seen the paperwork.
Contracts, tenders, vendor pitches, internal budgets. The commercial side of facial recognition is usually better hidden than the cameras themselves.
Open this questionnaireYou run the system, day to day.
You're the one watching the alerts, overriding false matches, or logging who gets flagged. You know things the spec sheet doesn't say.
Open this questionnaireYou approved it, funded it, or signed off on it.
Public tenders, impact assessments, oversight reports. Sitting on the buying side of the table means you saw a different version of the story.
Open this questionnaireYou spotted something in public space.
A camera, a kiosk, a sign, a badge you didn't recognize. You don't need inside access, but just a location and what you saw.
Open this questionnaireYou were stopped, flagged, or misidentified.
Something went wrong on the other side of the lens, and it happened to you. Your experience is evidence too.
Open this questionnaireBefore you write anything.
Most whistleblowers aren't exposed by a broken encryption algorithm. They're exposed by something that happened before any tool was involved. A comment to a colleague, a search from a work laptop, a detail that only one person could have known. None of what follows is about a specific piece of software. It's about the decisions that come first.
- Don't mention your plan to colleagues, your manager, or friends who might repeat it without realizing what it means.
- Don't use your employer's device, account, or network to research this page, or to prepare anything.
- Photos and documents carry hidden information: timestamps, device IDs, GPS coordinates, printer tracking dots.We do not plan to release ANY of the material received, but rather to use that as investigation lead. When in doubt, describe what you saw in your own words instead of uploading the original file.
- When you're ready, use the Tor Browser to open the submission page, ideally from a device and network that isn't tied to your workplace.
These are practices we ask to our sources to protect themselves. Less secure channels might work too, but we should assume to be surveilled even if our research in the public interest is meant to strenghen the state of rights. so, please, follow the above instructions, and if you need help, meet friendly digital rights organizations where you can get additional support!
Know more, if you want to.
None of this reading is required before you submit anything. It's here for people who want to go deeper on their own digital security, or who are doing this as part of an ongoing risk they're managing, not a one-off report.
Source protection guides
Freedom of the Press Foundation on reaching a journalist safely, written for people on your side of the exchange.
Surveillance Self-Defense
EFF's general guide to digital security, from the basics to specific tools and scenarios.
Holistic Security
Tactical Tech's guide for activists — treats digital, physical, and psychological safety as one problem.
Security in a Box
Step-by-step digital security guides organized by device and by task.
How the submission works.
GlobaLeaks organizes each reporting channel into a questionnaire — a set of questions tailored to a specific kind of knowledge. Below, you'll pick the one that matches what you actually know, rather than filling in one generic form built for no one in particular.
- Most fields are optional. Answer what you can and skip the rest — a partial answer is still useful to us.
- You don't create an account, and nothing in the form asks for your name or contact details.
- The submission itself happens inside GlobaLeaks, reachable over Tor, the same system used by whistleblowing projects at newsrooms and NGOs worldwide.
Submitting is the beginning, not the end.
A real person on our editorial and research team reads every submission — not an automated filter. Before you send anything, the submission screen shows you who's set to receive it, so you're not dropping this into an anonymous inbox on our side, even while you stay anonymous on yours.
At the end of the form, you'll be given a private receipt code.
That code is the only way — for you or for us — to reopen your case. Save it somewhere safe, offline if you can. If it's lost, the conversation can't be recovered. That's by design, not a bug.
Come back and use it. We may have follow-up questions, and a source who keeps that thread open tends to help an investigation go much further than a single anonymous drop ever could. Secure reporting works best as part of a wider network of technical, legal, and editorial support around it, not as a black box that swallows a report and gives nothing back — that's the same thinking behind efforts like GlobaLeaks' own House of Whistleblowers initiative, and it's why we treat the code above as the start of a conversation, not a drop box receipt.