Security dossier
Security practices
Current
In an era of mass surveillance and digital repression, security is not optional—it's essential for resistance. This page details our security practices and how you can stay secure while using our resources.
Last Updated: October 2025
Our Threat Model
We assume the following adversaries may attempt to compromise this site or its users:
State Actors
Law enforcement, intelligence agencies, and authoritarian governments seeking to identify and target activists.
Fascist Groups
Far-right extremists who may attempt to doxx, intimidate, or attack resistance organizers.
Corporate Surveillance
Tech companies and data brokers seeking to monetize user data and behavior.
Bad Actors
Malicious individuals or groups attempting DDoS attacks, defacement, or data breaches.
Infrastructure Security
HTTPS Everywhere
All connections use TLS 1.3 encryption with perfect forward secrecy. HTTP requests are automatically redirected to HTTPS.
TLS 1.3 + HSTS + OCSP StaplingDDoS Protection
Cloudflare provides DDoS mitigation and caching. Note: We minimize data collection through Cloudflare.
No JavaScript Tracking
Site functions without JavaScript. No analytics, no fingerprinting, no surveillance capitalism.
Tor-Friendly
Full support for Tor Browser users. No CAPTCHAs or blocks for Tor exit nodes.
Data Security
- Encrypted at Rest: All stored data is encrypted using AES-256
- Encrypted in Transit: TLS 1.3 for all connections
- Zero-Knowledge Architecture: Where possible, we implement zero-knowledge systems
- Regular Audits: Quarterly security audits and penetration testing
- Incident Response Plan: Documented procedures for security breaches
Protecting Yourself
While we implement strong security measures, your personal security practices are equally important:
Responsible disclosure
How to Report
If you discover a security vulnerability, please report it responsibly:
-
Step01
Start here
Use our secure contact methods
Use the secure contact methods linked from this route.
-
Step02
Next
Provide detailed information about the vulnerability
Complete this step before moving to the next.
-
Step03
Next
Give us reasonable time to fix the issue before public disclosure
Complete this step before moving to the next.
-
Step04
Next
Do not exploit the vulnerability or access/modify data without permission
Complete this step before moving to the next.
We commit to acknowledging reports within 48 hours and providing updates every 7 days
Security Headers
We implement strong security headers to protect against common attacks:
| Header | Protection |
|---|---|
Content-Security-Policy | Prevents XSS attacks |
X-Frame-Options | Prevents clickjacking |
X-Content-Type-Options | Prevents MIME sniffing |
Strict-Transport-Security | Forces HTTPS |
Referrer-Policy | Limits referrer leakage |
Permissions-Policy | Restricts browser features |
Legal demand status
Warrant Canary
As of October 1, 2025:
National Security Letters
Gag orders
Forced modifications
We have NOT been forced to modify our code or infrastructure
Warrants for user data
Related routes
Security Resources
Continue to internal privacy guidance or trusted external security resources.