Investigate. Verify. Reveal.

Source Protection Protocol

Last Updated: June 24, 2026

1. Why Sources Matter

Institutional accountability is rarely achieved through official press releases. The most critical investigations rely on the courage of insiders, whistleblowers, and sources who risk their livelihoods to expose systemic failures, corruption, and abuse of power. The Postmortems recognizes that our ability to investigate institutions is entirely dependent on our ability to protect the individuals who provide us with evidence.

2. Source Protection Principles

Protecting a source's identity is not a preference; it is a foundational journalistic obligation. We employ strict operational security protocols to shield our sources from legal, professional, and physical retaliation. However, we also enforce rigid verification standards to ensure that source protection is never used to launder unverified claims or personal grievances.

3. Confidential Sources

A confidential source is an individual whose identity is known to our reporters and editors, but who is granted anonymity in our published investigations. We grant confidentiality only when the source faces credible risks of retaliation, and when their information is of vital public interest and cannot be obtained through on-the-record channels.

4. Anonymous Sources

An anonymous source is an individual whose identity remains unknown even to our reporters. While we accept materials submitted anonymously, anonymous allegations alone are never sufficient for publication. We do not publish accusations based solely on the word of an unidentified party.

5. Handling Anonymous Submissions

When we receive an anonymous submission, our focus shifts immediately to the accompanying evidence. The anonymity of the sender requires us to subject the provided documents or data to an extreme standard of forensic and contextual verification. If the provided evidence cannot be independently verified and authenticated, the investigation cannot proceed.

6. Whistleblower Protection

We treat whistleblowers—individuals exposing misconduct from within an organization—with the highest degree of operational security. We utilize encrypted communication channels, secure drop systems, and legal counsel to minimize their exposure. We work with whistleblowers to establish strict boundaries regarding what information can be published without inadvertently exposing their identity.

7. Verification Requirements

The burden of proof remains entirely on The Postmortems. We do not transfer the responsibility of verification to the reader. Evidence must be independently verified whenever possible. A source's credibility, while important, does not replace the necessity for hard documentation and independent verification of the facts they provide.

8. Evidence Requirements

We evaluate evidence based on its provenance, authenticity, and context. Acceptable evidence from sources includes internal communications, financial ledgers, legal filings, and technical data. We require sources to provide the rawest form of evidence available to prevent manipulation. Summaries or interpretations of documents provided by a source are not treated as primary evidence.

9. Corroboration Standards

Claims require corroboration. We mandate that critical allegations supplied by a confidential or anonymous source be corroborated by at least one independent, documentary source, or multiple secondary sources with direct knowledge of the events. Uncorroborated single-source claims are generally insufficient for publication.

10. Evidence Verification Workflow

Upon receiving evidence from a source, we execute a strict workflow:

  1. Digital forensic review to ensure documents are not forged or altered.
  2. Cross-referencing claims against public records and open-source data.
  3. Attempting to secure independent, parallel documentation of the same events.
  4. Review by an independent editor isolated from the original source relationship.

11. Secure Communications

We mandate the use of end-to-end encrypted messaging applications for all sensitive source communications. We instruct sources on how to utilize secure drop platforms accessed via the Tor network for the safe transmission of high-risk documents. We routinely train our staff in operational security and threat modeling.

12. Secure Document Review Process

Highly sensitive documents are reviewed on air-gapped systems separated from the internet. We systematically strip metadata from all files, images, and documents prior to any internal distribution or external publication to prevent the inadvertent disclosure of the source's identity, location, or hardware.

13. Identity Protection

The identity of a confidential source is restricted to the primary reporter and the executive editor. It is not recorded in centralized digital databases or unencrypted internal communications. We employ strict compartmentalization to ensure that a breach of one system does not compromise our source network.

14. Reporter-Source Separation Principles

Reporters are instructed to maintain a professional distance from their sources. We strictly separate the act of source cultivation from the act of evidence verification. A reporter may advocate for the importance of a source's information, but an independent editor must objectively assess the validity of the evidence.

15. Editorial Review

The decision to grant confidentiality is never made unilaterally by a reporter. It requires the approval of the executive editor, following a rigorous assessment of the source's motives, the public interest of the information, and the impossibility of obtaining the evidence elsewhere.

16. Publication Approval Standards

Publication decisions are based on evidence, not accusation. Before an investigation utilizing confidential sources is approved for publication, the editorial board must reach a consensus that the evidence is overwhelming, the verification is bulletproof, and the public interest unambiguously justifies the use of unnamed sources.

We operate within the legal frameworks governing press freedom in India, but we are prepared to exhaust all legal remedies to protect the identities of our confidential sources. Our legal counsel reviews all high-risk investigations prior to publication to assess both defamation risks and the legal exposure of our sources.

18. Publication Standards

When relying on a confidential source, we explain to our readers, with as much detail as safely possible, why the source was granted anonymity and how they are in a position to know the information provided. We strive to maximize transparency without compromising the source's operational security.

19. Source Responsibilities

We require our sources to be honest with our reporters. If a source is discovered to have intentionally misled our team, fabricated evidence, or concealed critical conflicts of interest, The Postmortems reserves the right to terminate the relationship and, in severe cases of manipulation, revoke the agreement of confidentiality.

20. Risk Disclosure

While we deploy state-of-the-art security protocols and rigorously train our staff in operational security, the reality of digital surveillance necessitates absolute honesty regarding the limits of protection.

We do not promise absolute security. No digital communication system can be guaranteed completely risk-free. We strongly advise high-risk whistleblowers to research operational security, utilize non-work devices, and avoid transmitting sensitive data from monitored corporate or government networks.