Why This Stack?
As an investigative journalist, protecting sources is not optional—it’s a professional and ethical obligation. After years of trial and error, I’ve settled on this combination of tools that provides maximum protection without sacrificing usability.
The Core Philosophy
Compartmentalization is key. I never mix my personal and professional identities on the same tools. This stack is exclusively for sensitive work.
Tool Breakdown
SimpleX Chat — Source Communication
SimpleX is the only messenger I trust for initial contact with sources. No phone number, no email, no account—just a QR code or link. Even I don’t know who my sources are unless they choose to reveal themselves.
Pro tip: Generate a new SimpleX address for each major investigation. Delete old ones when the story is published.
Mullvad VPN — Always On
Mullvad runs 24/7 on all my devices. The account number system means no email, no password, no identity. I pay with Monero through a separate wallet.
Pro tip: Use Mullvad’s multihop feature when researching particularly sensitive topics.
Proton Mail — Secure Email
For when sources prefer email (many still do), Proton Mail with PGP encryption is the standard. I maintain separate Proton accounts for different beats.
What I Learned
- Convenience is the enemy of security. Every shortcut is a potential leak.
- Train your sources. Send them a simple guide on using SimpleX before the first conversation.
- Assume compromise. Even with perfect tools, behave as if someone is watching.
Monthly Cost Breakdown
- Mullvad VPN: 5 EUR
- Proton Mail Plus: 4 EUR
- SimpleX: Free
- Total: ~9 EUR (I rounded up for occasional extras)
This is the cheapest insurance policy you’ll ever buy.