Ghostmaxxing A public lab for testing camouflage
Leak to us

Document face recognition in the real world.

Ghostmaxxing tests open-source face recognition technology, but out there in the wild there are proprietary, modded configuration we can't test. For this, we need allies: who have met a real deployment can say what is installed, who runs it, what it gets wrong and who paid for it

This page introduces to the whistleblowing/reporting process, it explains the five channels designed to capture relevant information, and belows offer some security guidance on what can be known: the for any possibile concern.

The five Point of View we look for:

Before you write anything.

Before reporting, consider how your device might log, save, and record your digital activities. It normally happens automatically. The few whistleblowers that get exposed, is because they used their work device to report. Reading this page isn't a problem per se, as the link is spread all over the internet and anyone can stumble on it by mistake! but if someone consider reporting, should read this page and understand the basic protections.

  • Do not mention your plan to colleagues, your manager, or friends who might repeat it without realising what it means.
  • Do not use your employer's device, account or network to read this page or to prepare anything.
  • Do not go and get material for us. Report what you already know and already have access to. Accessing a system, an account or a document beyond your normal permissions creates a new offence and a new trail, and we do not want either.
  • Photos and documents carry hidden information: timestamps, device IDs, GPS coordinates, printer tracking dots. We do not publish material we receive; we use it as a lead. When in doubt, describe what you saw in your own words instead of uploading the original file.
  • When you are ready, use Tor Browser to open the submission page, from a device and a network that are not tied to your workplace.

These practices reduce avoidable exposure; no reporting channel removes every risk. Choose the precautions that match your situation, and do not continue if doing so would put you in danger. If you need help assessing that risk, a digital-rights or whistleblower-support organisation may be able to help before you send anything.

Know more, if you want to.

The whistleblowing platform is based on GlobaLeaks, the open-source system used by newsrooms and NGOs worldwide, and it is reachable over Tor.

Each questionnaire asks only what a person in that position can answer, and almost every field is optional, answer only what you know! You can always add to a report later with your receipt code.

None of this reading is required before you submit. It is here for people who want to go deeper on their own digital security, or who are managing an ongoing risk rather than sending a one-off report.

What happens to what you send.

A report is read by named people on the project's editorial and research team, not by an automated filter. The submission screen shows you who they are before you send. From there, four rules apply to every report, whichever questionnaire it came through.

  • Nothing you send is published as received. Reports are leads, not articles. A document or a screenshot is used to verify and to direct the next test, and it stays inside the reporting system.
  • Everything is corroborated before it is used. Each questionnaire ends by asking how you know and what would confirm it. A single-source claim is treated as a question to investigate, not as a finding to repeat.
  • Your restrictions are followed, even when they weaken the story. At the end of each form you can tell us to use a report only as a lead, not to quote you, not to name a place or an organisation, or not to contact anyone before asking you. We honour that.
  • What returns to the public is minimised. A finding becomes public only after editorial and security review, stripped of anything that points to a source: aggregated where several reports agree, redacted where one does not. Verified findings can change the reference archive, the tests run in the lab and what is published in the Fediverse. Confidential reports never go there directly.


If a report would be better served by a newsroom or an advocacy organisation than by us, we will propose that to you through your receipt code, and we will not pass anything on without your agreement.

Reports that receive no further activity are deleted from the reporting system after 180 days. A case that is still open can be kept longer by the people handling it, and you can ask, through the receipt, for a report to be deleted at any time.

What we cannot promise.

  • Legal protection. Whistleblower laws, including the EU directive and its national versions, mostly protect reports made to your employer, to a designated authority or, under conditions, to the public. Reporting to a research project is usually not one of the protected routes. If your position depends on legal protection, talk to a whistleblower-support organisation or a lawyer first; the resources above can point you to one.
  • Intervention in your case. We investigate systems. We are not able to appeal a decision, represent you or act on your behalf, though we can suggest who might.
  • A reply on a deadline. A person reads new reports at least weekly and answers through the receipt conversation. Nothing is forgotten, but this is volunteer work.
  • Payment. We do not pay for information, and we would treat an offer to sell it as a reason for caution.

How the submission works.

The reporting node is a separate GlobaLeaks installation with two addresses. The first is a normal HTTPS site. The second is an Onion Service, opened with Tor Browser, which hides from your network and from us where you are connecting from, and resists selective blocking. Prefer the Onion address whenever you can.

HTTPS: raccontaci.nina.watch
Tor: [onion address to be published]

  • You do not create an account, and nothing in the forms asks for your name or contact details.
  • Most fields are optional. Answer what you can and skip the rest.
  • Write in the language you think in. We read Italian and English directly and translate the rest.
  • Files are optional everywhere. A description in your own words is often safer and just as useful.
  • If Whistleblowing is a new concept for you, check out this Wikipedia article.

Submitting is the beginning, not the end.

At the end of the form you are given a private receipt code.

That code is the only way, for you or for us, to reopen your report. Save it somewhere safe, offline if you can. If it is lost, the conversation cannot be recovered. That is by design.

Come back and use it. We may have follow-up questions, we may want to check one detail before a finding moves forward, and you may want to add something you left out or withdraw something you regret. A source who keeps that thread open helps an investigation go much further than a single anonymous drop. Secure reporting works when there is a network of technical, legal and editorial support around it rather than a box that swallows a report and returns nothing, which is the same thinking behind GlobaLeaks' own House of Whistleblowers initiative.