
Some work carries a risk that most work does not. Investigative reporting, human rights research, security research on the wrong subject, activism under a hostile government. The specific danger varies. The planning problem is the same shape.
You are holding material. If you cannot check in, that material needs to reach specific people. While you can keep checking in, it must reach nobody, including anyone who compels you to open it.
This post is about the structure of that problem. It is not operational security advice for a specific threat model, and it is not a substitute for talking to your organization's security team or a group like the Freedom of the Press Foundation.
Start with the threat model
Before choosing any tool, be honest about who you are actually defending against. The right answer differs enormously.
Accident and illness. You are hit by a car. Nobody is targeting you. The requirement is simply that your work is not lost and your colleagues can continue it. This is the most common case by a wide margin, and the easiest.
Detention. You are held, possibly with your devices. The requirement is that your material reaches your editor or lawyer, and that whoever holds you cannot get it out of you by taking your laptop.
Coercion. Someone can compel you to unlock. The requirement is a system that behaves differently when you are being forced, because encryption does not help if you are made to open it.
A sophisticated state adversary. If this is genuinely your threat model, no consumer product is your answer. You need your organization's security team, purpose-built tooling, and probably an air gap. Take the framing here and nothing else.
Most people reading this are in the first two categories and should plan for those honestly rather than adopting the posture of the fourth.
The four requirements
Whatever you use, a timed disclosure setup needs these properties.
It must not fire early. A false positive is worse than no system. If your material is released while you are on a reporting trip with no signal, you have burned a source and possibly endangered them. This means a waiting period, escalating notifications, and a cancel path that works from anywhere with minimal connectivity.
Cancelling must be easy and low-bandwidth. You may be somewhere with bad connectivity, on a borrowed device, or with a phone that was taken and replaced. If checking in requires your laptop and a stable connection, it will fail when you need it not to.
Recipients must be reachable and prepared. Your designated recipient needs to know the system exists, expect a message from it, and know what to do. A notification arriving cold, from a service they have never heard of, gets treated as phishing. This is the failure mode nobody plans for.
The provider should not be able to read the material. Encrypted on your device before upload, so the service holds ciphertext. Then read carefully about the handoff, because every system has to solve the problem of getting a key to someone else at a future moment, and that is where the honest tradeoffs live.
The coercion problem
This deserves its own treatment, because it is the requirement most tools ignore.
Encryption assumes the adversary cannot make you decrypt. If they can, by legal compulsion or otherwise, the cryptography is not protecting you.
Approaches to this exist. A duress password is a second password you can give under pressure that produces a different outcome than your real one. It is not magic and it is not universally applicable, but for the detention case it is a meaningful option, and it is the reason it exists.
If your threat model includes compulsion, ask specifically whether a tool has a story here. Most do not.
Where HeirVault fits, honestly
This is our site, so here is the direct account, including the limits.
HeirVault is leave, check-in, and claim for contingency handoffs. You leave documents, notes, and files, name who receives what, and check in on a schedule. Miss a check-in and a waiting period starts with notices to you. Check in and everything stops. If the waiting period passes, the contacts you named can claim what you set aside for them.
Your live vault is protected by end-to-end encryption and encrypts in your browser before upload. That means HeirVault stores ciphertext and cannot decrypt your live vault.
The Shield plan is the one built for this case. It adds a duress password, which is a second password for when you are forced to unlock. It also allows shorter check-in intervals, down to one day, device check-ins via an API so a script or device can hold the switch, and a priority queue for release and reminder emails.
Now the limits, because you should not choose a tool for this based on marketing.
HeirVault-assisted delivery, the convenient default, stores a protected handoff key and transfers it to the beneficiary account after claim. That path is not end-to-end to the beneficiary alone. If your threat model requires that HeirVault never hold anything that could open a handoff, use one of the other delivery modes: enroll your recipient now so the handoff is wrapped to their account key, or share a unique beneficiary password with them out of band. Both keep that handoff key off our servers. The security page documents each mode.
We are also a small company, and for a state-level adversary that is a relevant fact. Weigh it.
The high-risk page and the journalists page cover this in more detail, and the duress password page covers that feature specifically.
Practical setup advice
Whatever you choose, these matter more than the tool.
- Tell your recipient in advance. Show them what the notification will look like. Agree on how they will verify it is real. This single step prevents the most likely failure.
- Pick an interval matched to your work, not your anxiety. Daily check-ins during a specific dangerous assignment. Monthly the rest of the time.
- Practice the cancel. Do it once from your phone, on mobile data, so you know it works and how long it takes.
- Separate the sensitive from the merely important. Not everything needs the same protection. Source-identifying material and your general work notes can be handled differently, and mixing them raises the risk on everything.
- Write context for your recipient. They need to know what they are looking at, what is verified, what is not, and what you wanted done with it. Raw files with no framing can do harm.
- Review it when the assignment changes. Stale recipients and stale intervals are how these systems quietly stop matching reality.
Further reading
For operational security in journalism specifically, the Freedom of the Press Foundation publishes practical, current guidance and is a better starting point than any vendor, including us.
This is general information, not legal advice. Rules differ by country and state. Talk to a qualified professional about your own situation.


