The image is rarely the only disclosure
A photograph that appears anonymous can still identify a source through embedded metadata, the frames captured immediately before and after it, the filename, an associated note, a contact record, or the message thread that delivered it.
Protecting the published image while leaving that surrounding context on the same device addresses the smallest part of the problem.
Minimise what the working device carries
Reducing what a working phone carries can reduce exposure. Material transferred and removed from the device can still have residual copies or account-access paths, so include those in the newsroom's threat model.
This requires a working transfer process rather than good intentions, which is why it is a newsroom question rather than an individual one.
Separate spaces for separate work
Keeping source identities alongside publishable media means one disclosed credential exposes both. Independent encrypted spaces, opened by unrelated credentials, change what a single compelled or observed unlock reveals.
NullVault addresses one part of this: a pattern opens the vault it addresses, and the lock screen does not present a list of vault names or a count.
Working practice
- Build a case-specific threat model with newsroom security support, not from general guidance.
- Keep source material in a space separate from publishable media.
- Remove location and unnecessary context before publication, and check adjacent frames.
- Plan for loss, detention, repair, and emergency handoff in advance rather than improvising.
- Maintain an off-device recovery path controlled by you or the newsroom.
What a vault cannot be asked to do
- Defeat a compromised device that observes content at the moment of unlock.
- Resist legal process, which operates on people and organisations rather than ciphers.
- Substitute for institutional security support on a high-risk story.
Get proper support
This guide describes general principles. Work involving genuine source protection warrants advice from your newsroom's security team or an organisation specialising in press freedom and digital security.
Consumer software documentation, including this site's, is not a substitute for that.
A fictional example
Amara starts with a non-sensitive test: “Build a case-specific threat model with newsroom security support.” Next, Amara follows the second check: “Remove location and unnecessary context before publication.” This fictional scenario demonstrates the decision process; it is not a report of product testing.
Common mistakes
- Keeping source identities beside publishable media
- Promising a vault defeats device compromise or legal process
What this workflow does not change
- Keeping source identities beside publishable media
- Promising a vault defeats device compromise or legal process
Questions people ask
Is this operational-security advice for every assignment?
No. High-risk reporting needs organization-specific expertise and current local legal guidance.