NOTHING IS UPLOADED — OPEN YOUR NETWORK TAB AND WATCH

The file is
the fingerprint

A document sent to a newsroom carries where it was made, on what, and often by whom.

Drop a file here

Or choose one — it is read directly from your disk and never leaves this tab.

JPEG · PNG · HEIC · WEBP · PDF · DOCX · XLSX · PPTX
Home / Guides

What identifies a source

The author field of a document. The camera serial number in a photograph, which links every image that body ever produced. The GPS coordinates of a picture taken inside a building. A printer's identification pattern in a scan. The username embedded in a file path inside an office document.

Published files carry it onward

Uploading a leaked document to your own site republishes its metadata to the world. The safe practice is to transcribe or re-render the content rather than publish the original file, and to verify the replacement independently.

Instruct sources before they send

By the time a file reaches you, the exposure has already happened, and it may be logged somewhere in transit. Guidance to sources is worth more than any cleaning done at your end: photograph a screen rather than screenshot it, retype rather than forward, avoid the original file where the content can be conveyed without it.

Verification cuts the other way

The same metadata that endangers a source can authenticate a document. Strip it for publication, but consider what you need to retain privately, and separate those decisions deliberately.

Common questions

Can a leaked document identify who leaked it?

Frequently. Author fields, timestamps, editing history and printer patterns have all been used to do exactly that.

Should I publish original files or transcriptions?

Transcriptions or re-rendered versions are safer. Publishing an original republishes everything inside it.

Does stripping metadata make a document unverifiable?

It can. Decide separately what you keep privately for verification and what you publish.

Related