Complete implementation kit · KIT-JOURNALISM-001

Protect the source, the investigation, and the public record.

Protect journalism by separating source identity from reporting content, minimizing metadata, securing administrative authority, binding vendors, creating emergency publication and archive continuity, distinguishing imminent operational harm from protected investigation, and measuring institutional readiness rather than tracking readers or sources.

Direct implementation answer

Protect journalism by separating source identity from reporting content, minimizing metadata, securing administrative authority, binding vendors, creating emergency publication and archive continuity, distinguishing imminent operational harm from protected investigation, and measuring institutional readiness rather than tracking readers or sources.

People and roles

Do not collapse different people into one surveillance category.

The same technology can create different risks depending on power, age, role, location, legal authority, and the consequences of disclosure.

KIT-JRN-POP-01

Sources and whistleblowers

Consent, confidentiality, safe recontact, metadata, relatives, and the consequences of disclosure must be handled as separate risks rather than one generic source record.

KIT-JRN-POP-02

Staff journalists and editors

Protect reporting, editorial judgment, labor activity, and disagreement from topic-based monitoring while maintaining accountable security and publication controls.

KIT-JRN-POP-03

Freelancers, fixers, translators, and local partners

Do not shift the highest physical, legal, payment, or identity risks onto people with the least institutional protection.

KIT-JRN-POP-04

Exile and diaspora media

Plan for transnational repression, family intimidation, cross-border legal uncertainty, payment interruption, and loss of hosting or identity services.

KIT-JRN-POP-05

Readers and communities

Avoid reader dossiers and analytics that expose people seeking sensitive reporting, especially in restricted or conflict-affected environments.

KIT-JRN-POP-06

Public-interest archives

Preserve provenance, chain of custody, correction history, multilingual relationships, and redundant custody without exposing protected contributors.

Context boundaries

Controls must stay inside the context that justifies them.

KIT-JRN-CTX-01

Reporting and research

Investigation of violent, extremist, criminal, military, or controversial subjects is not itself evidence of endorsement or intent.

KIT-JRN-CTX-02

Publication and immediate danger

A narrow delay or redaction may be justified by concrete, time-sensitive danger to an identifiable person or operation; institutional embarrassment is not enough.

KIT-JRN-CTX-03

Source protection and legal process

Promises, privilege, warrants, subpoenas, emergency demands, and cross-border duties require qualified local review and documented authority.

KIT-JRN-CTX-04

Archive and correction

Preservation must retain authentic history while supporting corrections and preventing a revised public page from silently overwriting source evidence.

Bounded threat model

Name systems, protected activity, and credible failure paths.

Scope: Source intake, messaging, notes, raw evidence, drafts, editorial systems, AI transcription and translation, cloud collaboration, analytics, publication, archives, domains, DNS, hosting, application stores, payment, legal demands, device compromise, physical seizure, harassment, and cross-border operations.

Protected activity: Lawful investigation, source contact, adversarial research, editorial judgment, confidential drafting, criticism of powerful actors, multilingual publication, public-interest archiving, and access to independent reporting.

KIT-JRN-TH-01Worldwide principle

Source identification through metadata

Contact channels, cloud logs, account recovery, document history, payment, location, and analytics can reveal a source even when message content is encrypted.

KIT-JRN-TH-02Technical recommendation

Account, device, and administrator compromise

Phishing, malware, spyware, device seizure, recovery abuse, and overbroad administrator access can expose sources, drafts, and publishing credentials.

KIT-JRN-TH-03Jurisdiction-specific legal question

Legal and informal coercion

Subpoenas, emergency requests, injunctions, licensing, regulatory threats, national-security claims, and informal pressure can bypass ordinary editorial independence.

KIT-JRN-TH-04Worldwide principle

Infrastructure and financial chokepoints

A newsroom can lose reach through domain, DNS, hosting, cloud, app-store, identity-provider, advertising, payment, or crowdfunding termination.

KIT-JRN-TH-05Technical recommendation

Platform and search invisibility

Demotion, labeling, suspension, demonetization, false reporting, and citation exclusion can suppress lawful reporting without an explicit ban.

KIT-JRN-TH-06Worldwide principle

Transnational repression and family pressure

Exile journalists and their relatives may face surveillance, threats, doxxing, travel pressure, financial coercion, and violence across borders.

KIT-JRN-TH-07Technical recommendation

Synthetic evidence and provenance attacks

Deepfakes, altered documents, context stripping, impersonation, and provenance removal can corrupt reporting and discredit authentic evidence.

KIT-JRN-TH-08Worldwide principle

Archive deletion and narrative replacement

Takedowns, account loss, automated moderation, censorship, compromised backups, or silent edits can erase records needed for history and accountability.

Minimum safeguards

Build a rights-preserving floor before adding complexity.

These safeguards state the purpose that must survive local implementation. They are not a claim that every jurisdiction uses identical law or procedure.

KIT-JRN-SG-01Operational practice

Define source states and authority

Record whether a source is anonymous, confidential, pseudonymous, attributable, embargoed, or on the record, who may change that state, and what consent actually covers.

EvidenceCL-41-04
KIT-JRN-SG-02Technical recommendation

Separate identity, content, and publication authority

Compartmentalize source identity, communications, notes, raw evidence, drafts, legal records, publishing credentials, translation files, analytics, and archives.

KIT-JRN-SG-03CognitiveLiberties.com policy proposal

Minimize metadata and reader observation

Disable unnecessary analytics, session replay, cross-site tracking, detailed referrers, and identity-linked readership histories for sensitive reporting.

KIT-JRN-SG-04Technical recommendation

Use strong authentication and recoverable custody

Use password managers, phishing-resistant authentication, separated administrator roles, protected recovery material, and tested emergency reassignment.

EvidenceCL-41-04
KIT-JRN-SG-05Worldwide principle

Protect secure intake honestly

Describe what a channel can and cannot hide, provide safer alternatives, and do not call a channel anonymous when providers or metadata can identify the source.

KIT-JRN-SG-06Operational practice

Bind cloud, AI, and collaboration vendors

Prohibit undisclosed model training, unrelated profiling, sale, and onward use; require subprocessors, retention, deletion, breach notice, export, and remedy.

KIT-JRN-SG-07Worldwide principle

Preserve editorial independence

Document ownership, regulator, funder, advertiser, donor, platform, and government pressure while protecting good-faith editorial judgment and corrections.

KIT-JRN-SG-08CognitiveLiberties.com policy proposal

Distinguish imminent operational harm from criticism

Require a defined person, operation, vulnerability, probability, time horizon, and least-restrictive mitigation before delaying or limiting publication.

KIT-JRN-SG-09Technical recommendation

Create redundant publication and domain continuity

Maintain independent domain and DNS custody, alternative hosting, exportable publishing systems, mirrors where lawful, and emergency communication channels.

KIT-JRN-SG-10Technical recommendation

Maintain authenticated, distributed archives

Preserve source bytes, hashes, provenance, timestamps, corrections, translations, and independent custody across organizational failure.

KIT-JRN-SG-11Operational practice

Protect collaborators and wellbeing

Include freelancers, fixers, translators, photographers, local partners, and relatives in physical, legal, payment, mental-health, and relocation planning.

KIT-JRN-SG-12Worldwide principle

Provide correction, appeal, and restoration

Create visible paths for sources, subjects, staff, and publishers to challenge errors, unauthorized disclosure, platform actions, or internal misuse.

Staged implementation

Move from visibility to enforceable controls to durable resilience.

First 30 daysKIT-JRN-STAGE-30

Map source risk and secure administrative control

Outcome: The newsroom knows where source identity and reporting content live, removes avoidable exposure, and can preserve publication authority through a basic incident.

  1. KIT-JRN-ACT-30-01Operational practice

    Assign accountable owners

    Name owners for source protection, security, legal review, publication, archives, translation, payments, and staff safety.

  2. KIT-JRN-ACT-30-02Technical recommendation

    Map sensitive systems and trust boundaries

    Inventory intake, messaging, notes, cloud documents, email, AI tools, devices, accounts, admins, hosting, DNS, payments, analytics, and backups.

    EvidenceCL-10-01
  3. KIT-JRN-ACT-30-03Technical recommendation

    Secure privileged accounts and recovery

    Move critical accounts to phishing-resistant authentication, split custody, named recovery, and documented emergency succession.

    EvidenceCL-41-04
  4. KIT-JRN-ACT-30-04Operational practice

    Publish source and correction boundaries

    Explain confidentiality choices, channel limits, correction practices, urgent contact, and what the newsroom cannot promise.

Within 90 daysKIT-JRN-STAGE-90

Make source protection and continuity testable

Outcome: The newsroom has contractual controls, compartmentalized workflows, publication continuity, archive redundancy, and practiced legal and security response.

  1. KIT-JRN-ACT-90-01Operational practice

    Create source-state and disclosure workflows

    Document consent, safe recontact, authority changes, emergency exceptions, relatives, and final publication decisions without overcentralizing identities.

    EvidenceCL-41-04
  2. KIT-JRN-ACT-90-02Operational practice

    Rewrite vendor and AI terms

    Require no undisclosed training, no advertising, retention limits, subprocessor control, export, audit, incident notice, and verified deletion.

  3. KIT-JRN-ACT-90-03Technical recommendation

    Build and test emergency publication

    Exercise loss of an account, device, host, domain, payment provider, or office and publish a signed test artifact through the fallback path.

  4. KIT-JRN-ACT-90-04Operational practice

    Exercise a source-exposure incident

    Use synthetic identities and documents to test containment, legal review, safe notice, credential rotation, correction, and family or collaborator support.

    EvidenceCL-23-04
Within 365 daysKIT-JRN-STAGE-365

Build durable cross-border information resilience

Outcome: Editorial work, source protection, multilingual correction, financing, publication, and authenticated archives can survive coercion, termination, relocation, and organizational failure.

  1. KIT-JRN-ACT-365-01CognitiveLiberties.com policy proposal

    Establish independent governance and review

    Create recurring source-protection, security, legal, editorial, accessibility, and conflict-of-interest review with authority to require correction.

    EvidenceCL-41-04
  2. KIT-JRN-ACT-365-02Operational practice

    Diversify infrastructure and revenue

    Reduce dependence on one cloud, platform, identity provider, app store, advertiser, donor, payment processor, or jurisdiction.

  3. KIT-JRN-ACT-365-03Technical recommendation

    Build multilingual correction and provenance

    Bind derivatives to controlling sources, record assistance, omissions, reviewer authority, hashes, and correction propagation.

  4. KIT-JRN-ACT-365-04CognitiveLiberties.com policy proposal

    Fund archive and exile continuity

    Maintain authenticated copies, cross-border custody, staff relocation and succession, emergency grants, and knowledge transfer.

Evidence and procurement checklist

Do not buy a promise. Require inspectable evidence.

A policy statement is not proof of system behavior. Require architecture, configuration, tests, contracts, logs with bounded retention, deletion evidence, and a remedy when the provider is wrong.

KIT-JRN-PROC-01Operational practice

Complete data and metadata inventory

Require every content field, identifier, log, device signal, inferred risk, document history, location, and support copy to be named.

EvidenceCL-10-01
KIT-JRN-PROC-02Technical recommendation

Source-confidentiality design evidence

Require architecture showing who can see source identity, content, metadata, recovery records, backups, and administrator actions.

KIT-JRN-PROC-03Technical recommendation

Encryption and key custody

Require transport and storage encryption, key ownership, rotation, recovery, compelled-access behavior, and administrator separation.

KIT-JRN-PROC-04Technical recommendation

Retention and verified deletion

Require deletion schedules and tests for messages, files, metadata, logs, AI prompts, embeddings, backups, exports, and subprocessors.

EvidenceCL-10-01
KIT-JRN-PROC-05CognitiveLiberties.com policy proposal

No advertising, sale, or source profiling

Prohibit use of reader, source, journalist, or editorial activity for advertising, sale, eligibility, reputation, or unrelated risk scoring.

EvidenceCL-06-04
KIT-JRN-PROC-06Operational practice

Training and evaluation use

Require explicit authorization before source material, unpublished work, translations, recordings, or prompts enter model training or evaluation.

EvidenceCL-34-02
KIT-JRN-PROC-07Operational practice

Subprocessors and cross-border access

Require a current register, locations, purposes, legal exposure, notice, objection, export, and deletion for each subprocessor.

EvidenceCL-23-01
KIT-JRN-PROC-08Operational practice

Model and policy changes

Require notice and review before changes to moderation, transcription, translation, identity, retention, ranking, or safety behavior.

EvidenceCL-07-04
KIT-JRN-PROC-09Technical recommendation

Account and administrator controls

Require phishing-resistant authentication, role separation, logs, recovery authority, emergency succession, and revocation timing.

EvidenceCL-41-04
KIT-JRN-PROC-10Operational practice

Incident notification and disclosure process

Require notice deadlines, evidence preservation limits, government-demand handling, user notice where lawful, and post-incident assistance.

KIT-JRN-PROC-11Technical recommendation

Export, portability, and continuity

Require usable export of content, media, metadata, access controls, translation relationships, corrections, subscriber records, and configuration.

EvidenceCL-31-04
KIT-JRN-PROC-12Operational practice

Accessibility and low-bandwidth alternatives

Require accessible intake, reading, correction, and emergency publication paths that do not force insecure workarounds.

EvidenceCL-42-04
KIT-JRN-PROC-13Operational practice

Independent audit and transparency

Require security, privacy, moderation, deletion, provenance, availability, and government-request evidence open to qualified review.

KIT-JRN-PROC-14Operational practice

Remedy, exit, and secure destruction

Require correction, restoration, migration support, reasonable exit cost, secure destruction, and survival of confidentiality duties.

Common failure modes

Good intentions can still create cognitive surveillance.

KIT-JRN-FAIL-01Technical recommendation

Calling a channel anonymous without testing metadata

Encryption of content does not hide IP, account, device, payment, or cloud metadata.

KIT-JRN-FAIL-02Technical recommendation

Centralizing every source identity

A single searchable source database creates catastrophic breach, insider, subpoena, and seizure risk.

EvidenceCL-10-01
KIT-JRN-FAIL-03Worldwide principle

Treating controversial research as intent

Topic, query, contact, travel, or draft alone cannot establish endorsement, criminal purpose, or a credible threat.

EvidenceCL-09-04
KIT-JRN-FAIL-04CognitiveLiberties.com policy proposal

Confusing provenance with mandatory identity

Authenticity signals can protect evidence, but compulsory creator identity can expose whistleblowers and excluded communities.

KIT-JRN-FAIL-05Operational practice

Depending on one platform or provider

A single host, identity provider, payment processor, domain registrar, or social platform can become an emergency kill switch.

KIT-JRN-FAIL-06Operational practice

Shifting risk to freelancers and local partners

Institutional staff may be protected while fixers, translators, photographers, and relatives carry exposure without contracts, equipment, or support.

EvidenceCL-23-04
KIT-JRN-FAIL-07Worldwide principle

Publishing silent corrections or overwriting evidence

Unversioned edits can destroy accountability and let a compromised editor replace the historical record.

EvidenceCL-20-03
KIT-JRN-FAIL-08CognitiveLiberties.com policy proposal

Measuring reach through reader dossiers

Detailed audience tracking can expose people seeking independent reporting and can become a map for repression.

Incident-response procedure

Contain concrete harm without multiplying exposure.

  1. KIT-JRN-IR-01Operational practice

    Protect people in immediate danger

    Prioritize a specific source, staff member, collaborator, relative, victim, or active operation; avoid broad disclosure.

    EvidenceCL-23-04
  2. KIT-JRN-IR-02Worldwide principle

    Classify the event and evidence

    Distinguish compromise, legal demand, physical threat, doxxing, synthetic media, platform action, payment loss, archive tampering, and protected reporting.

    EvidenceCL-09-04
  3. KIT-JRN-IR-03Technical recommendation

    Contain access and propagation

    Revoke exposed credentials, isolate systems, pause unsafe synchronization, preserve publication continuity, and stop automated downstream decisions.

    EvidenceCL-41-04
  4. KIT-JRN-IR-04Operational practice

    Preserve only necessary incident evidence

    Retain a documented minimum for recovery, accountability, and lawful process without copying unrelated sources, readers, drafts, or communications.

    EvidenceCL-10-01
  5. KIT-JRN-IR-05Operational practice

    Notify affected people through safe channels

    Coordinate timing, language, relocation, legal support, and family risk; do not repeat the exposure in the notice.

    EvidenceCL-23-04
  6. KIT-JRN-IR-06Worldwide principle

    Require independent editorial and legal review

    Separate immediate operational containment from final publication, disclosure, takedown, or correction decisions.

    EvidenceCL-26-04
  7. KIT-JRN-IR-07CognitiveLiberties.com policy proposal

    Correct, restore, and support

    Restore accounts and publication, correct records and translations, revoke exposed links, delete unsupported labels, and provide staff or source support.

    EvidenceCL-07-04
  8. KIT-JRN-IR-08Operational practice

    Publish aggregate lessons without exposing protected work

    Report cause, response, continuity, correction, and control changes while withholding identities and sensitive operational detail.

    EvidenceCL-15-01
Review cadence

Make safeguards operational rather than ceremonial.

KIT-JRN-REV-01Operational practice

Monthly privileged-access and deletion review

Review administrators, recovery paths, dormant accounts, failed deletion, legal holds, and exceptional source records.

EvidenceCL-10-01
KIT-JRN-REV-02Operational practice

Quarterly source-protection exercise

Test intake, safe recontact, metadata, device loss, legal demand, and family or collaborator support with synthetic data.

EvidenceCL-23-04
KIT-JRN-REV-03Technical recommendation

Quarterly publication-continuity exercise

Test domain, DNS, hosting, identity, payment, and distribution failure without risking live sources.

EvidenceCL-23-03
KIT-JRN-REV-04Operational practice

Annual vendor, archive, and translation audit

Review training use, subprocessors, cross-border access, model changes, deletion, export, provenance, corrections, and restoration.

EvidenceCL-15-01
KIT-JRN-REV-05Worldwide principle

Immediate review after threat or policy change

Reopen controls after a breach, coercive demand, attack, relocation, conflict escalation, new vendor, or material platform rule change.

EvidenceCL-02-04
Appeals and remedy

A safeguard is incomplete when no one can reverse a mistake.

KIT-JRN-REM-01Operational practice

Source complaint and consent correction

Allow sources to report unauthorized attribution, unsafe contact, consent mismatch, or identity exposure through a protected route.

EvidenceCL-41-04
KIT-JRN-REM-02Worldwide principle

Subject right of reply and factual correction

Provide a documented process for evidence submission, editorial review, correction, and explanation without compelled false balance.

EvidenceCL-41-04
KIT-JRN-REM-03Operational practice

Internal appeal for staff and collaborators

Provide independent review of security restrictions, retaliation, credit, payment, risk transfer, and access decisions.

EvidenceCL-23-04
KIT-JRN-REM-04Technical recommendation

Platform and infrastructure escalation

Maintain evidence packages, reason requests, appeal contacts, alternative distribution, and public transparency for suspension or demotion.

KIT-JRN-REM-05Technical recommendation

Correction across languages and archives

Propagate material corrections to derivatives, syndication partners, mirrors, feeds, archives, and structured records.

KIT-JRN-REM-06CognitiveLiberties.com policy proposal

Downstream deletion of unsupported labels

Require vendors and internal systems to remove false source, threat, authenticity, or policy labels and their consequences.

EvidenceCL-07-04
KIT-JRN-REM-07CognitiveLiberties.com policy proposal

Meaningful restoration and support

Restore publication, credentials, compensation, credit, services, and reasonable safety support where the organization caused avoidable harm.

EvidenceCL-23-04
Data-deletion expectations

Delete the cognitive trail when the authorized need ends.

KIT-JRN-DEL-01Technical recommendation

Source intake metadata

Delete unnecessary IP, device, referrer, analytics, upload, and account metadata as soon as routing, security, and agreed recontact needs end.

EvidenceCL-10-01
KIT-JRN-DEL-02Operational practice

Messages and contact records

Use source-specific schedules and delete unnecessary copies, contact graphs, notifications, previews, and synchronized history.

EvidenceCL-23-01
KIT-JRN-DEL-03Operational practice

Notes, drafts, and document history

Retain only what reporting, accountability, archive, and legal needs justify; remove abandoned copies and uncontrolled histories.

EvidenceCL-20-03
KIT-JRN-DEL-04Technical recommendation

AI transcription and translation artifacts

Delete prompts, audio, transcripts, embeddings, model caches, intermediate translations, and provider copies unless explicit authority supports retention.

KIT-JRN-DEL-05CognitiveLiberties.com policy proposal

Reader and audience data

Use aggregate, privacy-preserving measurement and delete person-level reading histories, detailed referrers, and inferred interests not required for service delivery.

KIT-JRN-DEL-06Technical recommendation

Security and fraud logs

Apply short, risk-based retention; separate abuse indicators from editorial topics and delete resolved false positives.

EvidenceCL-10-01
KIT-JRN-DEL-07Jurisdiction-specific legal question

Legal holds and compelled preservation

Record authority, scope, notice limits, custodian, review date, and end condition; release unrelated and expired material promptly.

EvidenceCL-26-04
KIT-JRN-DEL-08Technical recommendation

Backups and subprocessors

Propagate expiry and correction to backups, support systems, data lakes, collaboration tools, archives under newsroom control, and third parties.

EvidenceCL-10-01
KIT-JRN-DEL-09CognitiveLiberties.com policy proposal

Identity and risk labels after correction

Remove unsupported authenticity, source, threat, policy, or trust labels and correct every downstream use.

EvidenceCL-07-04
Measurable outcomes without dossiers

Measure systems, controls, response, and recovery—not what named people think.

No metric in this kit requires an identity-linked history of lawful questions, reading, research, beliefs, associations, or use of privacy tools.

KIT-JRN-OUT-01Operational practice

Private source-intake availability

Percentage of editorial desks with tested, accessible intake choices and accurate channel limitations.

Measurement boundary: Measure channels and synthetic test transactions, not source identities.

EvidenceCL-23-01
KIT-JRN-OUT-02Technical recommendation

Deletion assurance

Percentage of scheduled deletion and subprocessor deletion events completed and independently sampled on time.

Measurement boundary: Use test records and aggregate jobs rather than live source histories.

EvidenceCL-10-01
KIT-JRN-OUT-03Technical recommendation

Privileged-account protection

Percentage of publishing, domain, DNS, cloud, payment, and archive administrators using phishing-resistant authentication and separated recovery.

Measurement boundary: Measure account controls, not editorial activity.

EvidenceCL-41-04
KIT-JRN-OUT-04Operational practice

Vendor-control coverage

Percentage of relevant contracts covering training, profiling, retention, deletion, subprocessors, incident notice, audit, remedy, and exit.

Measurement boundary: Measure contractual evidence without disclosing sources or readers.

EvidenceCL-15-01
KIT-JRN-OUT-05Operational practice

Source-state and consent completeness

Percentage of high-risk source relationships with an explicit current disclosure state, authority, safe-contact plan, and review date.

Measurement boundary: Count governance records; do not publish identities or reporting topics.

EvidenceCL-41-04
KIT-JRN-OUT-06Operational practice

Appeal and correction timing

Median time to acknowledge, decide, correct public and internal records, propagate translations, and restore access.

Measurement boundary: Publish aggregate process timing and categories.

EvidenceCL-07-04
KIT-JRN-OUT-07Technical recommendation

Infrastructure continuity

Recovery time in exercises involving domain, DNS, hosting, identity, payment, or publication loss.

Measurement boundary: Use controlled exercises without live source material.

EvidenceCL-23-03
KIT-JRN-OUT-08Technical recommendation

Archive integrity and recovery

Percentage of sampled artifacts whose hashes, provenance, correction history, and independent restoration validate.

Measurement boundary: Measure artifact integrity, not audience identity.

KIT-JRN-OUT-09Operational practice

Multilingual correction propagation

Percentage of material corrections reaching known derivatives and partners within the defined target.

Measurement boundary: Track publication objects and partners, not reader behavior.

EvidenceCL-42-04
KIT-JRN-OUT-10Operational practice

Incident containment and corrective action

Time to contain, notify, restore, and close verified corrective actions in synthetic or real incidents.

Measurement boundary: Report aggregate incident classes without exposing protected work.

EvidenceCL-15-01
Jurisdiction-specific legal review

Ask these questions locally before claiming compliance.

The worldwide baseline is a rights and architecture framework. Binding duties vary across constitutions, human-rights systems, privacy, consumer, education, press, labor, accessibility, cybersecurity, records, procurement, contracts, and court procedure.

Evidence basis and limits

Research, standards, law, technical guidance, and site proposals remain distinguishable.

The kit translates supplied reporting, exile-media, privacy, archive, platform, and due-process research into operational guidance. It does not establish journalist privilege, source immunity, legal compliance, physical safety, or the truth of a specific allegation in every jurisdiction.

Current law, vendor behavior, system configuration, and local risk must be independently rechecked before deployment. The exact 64-report archive remains preserved separately from this implementation derivative.

Questions institutions ask

What this kit does—and does not—require.

Does this kit require publishing information that would immediately endanger someone?

No. It supports narrow delay, redaction, or alternate handling where evidence shows concrete and time-sensitive danger to an identifiable person, active operation, victim, or system. It rejects vague safety labels as a substitute for that showing.

Can a newsroom promise complete anonymity?

Only when the whole path—including device, network, account, provider, metadata, payment, recovery, and internal access—has been evaluated. The kit requires accurate limitations rather than an absolute promise the architecture cannot keep.

Does content provenance require identifying every creator?

No. Provenance can authenticate an artifact or custody event while protecting the source. Mandatory public identity may expose whistleblowers and should not be treated as a universal condition of credibility.

How can a newsroom measure reach without tracking sensitive readers?

Use privacy-preserving aggregate measurement, voluntary feedback, public distribution statistics, synthetic availability checks, and infrastructure evidence rather than person-level reading histories.