The five Point of View we look for:
You were stopped, flagged or misidentified.
A system read your face and something followed: a question, a refusal, an escort to the door. You do not need to know how it worked. What happened to you is the evidence.
Open this questionnaireYou build, integrate or test the technology.
You know how a system is assembled, where one falls short of its spec sheet, or you have run a Ghostyle or a workshop look against a real system and can tell us how it performed. The form shows only the questions for what you can speak to.
Open this questionnaireYou operate it, day to day.
And can describe how the system is used in practice, what the manual says, and your boss asks.
Open this questionnaireYou bought it, sold it or signed it off.
Contracts, tenders, budgets, vendor pitches, impact assessments: you know the purchase terms and agreements.
Open this questionnaireYou noticed something, or none of the above fits.
A camera, a kiosk, a sign, a pair of glasses you did not expect. Or something about face recognition the other four questionnaires do not ask for. No inside access needed.
Open this questionnaireBefore you write anything.
Before reporting, consider how your device might log, save, and record your digital activities. It normally happens automatically. The few whistleblowers that get exposed, is because they used their work device to report. Reading this page isn't a problem per se, as the link is spread all over the internet and anyone can stumble on it by mistake! but if someone consider reporting, should read this page and understand the basic protections.
- Do not mention your plan to colleagues, your manager, or friends who might repeat it without realising what it means.
- Do not use your employer's device, account or network to read this page or to prepare anything.
- Do not go and get material for us. Report what you already know and already have access to. Accessing a system, an account or a document beyond your normal permissions creates a new offence and a new trail, and we do not want either.
- Photos and documents carry hidden information: timestamps, device IDs, GPS coordinates, printer tracking dots. We do not publish material we receive; we use it as a lead. When in doubt, describe what you saw in your own words instead of uploading the original file.
- When you are ready, use Tor Browser to open the submission page, from a device and a network that are not tied to your workplace.
These practices reduce avoidable exposure; no reporting channel removes every risk. Choose the precautions that match your situation, and do not continue if doing so would put you in danger. If you need help assessing that risk, a digital-rights or whistleblower-support organisation may be able to help before you send anything.
Know more, if you want to.
The whistleblowing platform is based on GlobaLeaks, the open-source system used by newsrooms and NGOs worldwide, and it is reachable over Tor.
Each questionnaire asks only what a person in that position can answer, and almost every field is optional, answer only what you know! You can always add to a report later with your receipt code.
None of this reading is required before you submit. It is here for people who want to go deeper on their own digital security, or who are managing an ongoing risk rather than sending a one-off report.
Source protection guides
Freedom of the Press Foundation on reaching a journalist safely, written for people on your side of the exchange.
Surveillance Self-Defense
EFF's general guide to digital security, from the basics to specific tools and scenarios.
Holistic Security
Tactical Tech's guide for activists. Digital, physical and psychological safety treated as one problem.
Whistleblowing International Network
Directory of national whistleblower-support organisations that can advise on legal protection where you live.
What happens to what you send.
A report is read by named people on the project's editorial and research team, not by an automated filter. The submission screen shows you who they are before you send. From there, four rules apply to every report, whichever questionnaire it came through.
- Nothing you send is published as received. Reports are leads, not articles. A document or a screenshot is used to verify and to direct the next test, and it stays inside the reporting system.
- Everything is corroborated before it is used. Each questionnaire ends by asking how you know and what would confirm it. A single-source claim is treated as a question to investigate, not as a finding to repeat.
- Your restrictions are followed, even when they weaken the story. At the end of each form you can tell us to use a report only as a lead, not to quote you, not to name a place or an organisation, or not to contact anyone before asking you. We honour that.
- What returns to the public is minimised. A finding becomes public only after editorial and security review, stripped of anything that points to a source: aggregated where several reports agree, redacted where one does not. Verified findings can change the reference archive, the tests run in the lab and what is published in the Fediverse. Confidential reports never go there directly.
If a report would be better served by a newsroom or an advocacy
organisation than by us, we will
propose that to you through your receipt code, and we will not
pass anything on without your
agreement.
Reports that receive no further activity are deleted from the reporting system after 180 days. A case that is still open can be kept longer by the people handling it, and you can ask, through the receipt, for a report to be deleted at any time.
What we cannot promise.
- Legal protection. Whistleblower laws, including the EU directive and its national versions, mostly protect reports made to your employer, to a designated authority or, under conditions, to the public. Reporting to a research project is usually not one of the protected routes. If your position depends on legal protection, talk to a whistleblower-support organisation or a lawyer first; the resources above can point you to one.
- Intervention in your case. We investigate systems. We are not able to appeal a decision, represent you or act on your behalf, though we can suggest who might.
- A reply on a deadline. A person reads new reports at least weekly and answers through the receipt conversation. Nothing is forgotten, but this is volunteer work.
- Payment. We do not pay for information, and we would treat an offer to sell it as a reason for caution.
How the submission works.
The reporting node is a separate GlobaLeaks installation with two addresses. The first is a normal HTTPS site. The second is an Onion Service, opened with Tor Browser, which hides from your network and from us where you are connecting from, and resists selective blocking. Prefer the Onion address whenever you can.
HTTPS: raccontaci.nina.watch
Tor: [onion address to be published]
- You do not create an account, and nothing in the forms asks for your name or contact details.
- Most fields are optional. Answer what you can and skip the rest.
- Write in the language you think in. We read Italian and English directly and translate the rest.
- Files are optional everywhere. A description in your own words is often safer and just as useful.
- If Whistleblowing is a new concept for you, check out this Wikipedia article.
Submitting is the beginning, not the end.
At the end of the form you are given a private receipt code.
That code is the only way, for you or for us, to reopen your report. Save it somewhere safe, offline if you can. If it is lost, the conversation cannot be recovered. That is by design.
Come back and use it. We may have follow-up questions, we may want to check one detail before a finding moves forward, and you may want to add something you left out or withdraw something you regret. A source who keeps that thread open helps an investigation go much further than a single anonymous drop. Secure reporting works when there is a network of technical, legal and editorial support around it rather than a box that swallows a report and returns nothing, which is the same thinking behind GlobaLeaks' own House of Whistleblowers initiative.