Send a sealed, anonymous tip
This page seals your message to one recipient's post-quantum key in your browser and posts it through an IP-blind relay. No account, no app, no Tor required. The server stores an unlabeled sealed row it cannot read or trace — deleted after 7 days.
You need a desk link from the organization you're contacting (it looks like …/svc/drop#d=…). Open their link, or paste it:
Run a newsroom, tip line, or audit desk? Your drop link is one tap away in NULL messenger → Account → NULL Drop.
Send a sealed tip to
Sealed in your browser to this desk's post-quantum key. Sent IP-blind. Nothing about you is attached unless you write it.
Sent. If you want to hear back, save this pickup code:
Anyone with this code can read the desk's replies to you — treat it like a key. Come back to this page → Check for a reply. Nothing links the code to you; losing it just means no reply channel.
What this protects — and what it can't
Protected:
- Content: sealed with hybrid ML-KEM-768 + X25519 → AES-256-GCM (post-quantum). Only the desk can open it.
- Your network address: sent via an IP-blind relay lane; the receiving server never sees your IP.
- Metadata: the server stores a sealed row with no sender, no recipient, padded to a fixed size, deleted after 7 days — indistinguishable from the rest of the sealed feed.
- Your identity: there is no account. The optional reply channel is a random derived mailbox, unlinkable to you.
Not protected:
- Your device. Malware or an employer-managed machine can see what you type. Use a device you trust.
- What you write. Writing style and details can identify you. Share documents' contents, not files with metadata.
- This page's delivery. The code you're running is served by the same site; for maximum-stakes situations use a trusted device on a clean network, and consider Tor Browser as an extra layer.
- Local traces. Use private browsing; this page stores nothing, but your browser history will show you visited.
Full threat model: NULL messenger · server posture: /api/posture