Signal for journalists: protecting sources without the myths
Published: October 7, 2026 · Updated: October 8, 2026
Signal is the messaging app most journalists already use with sources, and for good reason: end-to-end encryption, disappearing messages, and minimal metadata are real protections. But tools do not protect sources; habits do. A reporter with perfect Signal settings and sloppy practices is less safe than a careful reporter on a weaker app. This guide covers source-protection workflows that actually work, newsroom group hygiene, what happens if a device is seized, and the myths to stop repeating. No tool is NSA-proof, and anyone telling you otherwise is selling something.
from Signal's official site — file hosted by Signal, not by us
Source-protection workflows that work
Source protection is a workflow, not an app install. The workflow has three phases: first contact, ongoing communication, and the moment something goes wrong. Signal handles the middle of each phase well; the ends are on you.
The threat model comes first, and it should be explicit. Who are you protecting the source from? A corporation's lawyers, a local police department, and a national intelligence agency are three completely different adversaries with completely different capabilities. Signal plus good habits defeats the first two in most scenarios. Against the third, the honest answer is that no consumer app is sufficient on its own, and the protection comes from legal process, operational discipline, and minimizing what exists to be found. Write the threat model down before the first message, not after.
The second principle: minimize what exists. Every message, photo, and contact entry is something that can be found later. Disappearing messages, careful contact naming (a source saved as "Plumber" rather than their real name), and keeping source material off the phone's camera roll are all the same idea: the safest data is data that does not exist. Signal's encryption protects data in transit; your habits protect data at rest.
The first contact: setting up a source safely
First contact is the most dangerous moment, because neither side has verified the other yet. If you publish a Signal number or username for tips, assume adversaries see it too. That is fine; a tip line is meant to be public. What matters is what happens next.
When a source reaches out, move quickly to verification in both directions. Verify their safety number through a second channel you trust, and give them a way to verify you: your published username, a newsroom page that lists it, or a colleague they already know. Safety numbers are the unique key fingerprints Signal generates for each contact; matching them confirms nobody is intercepting the conversation. It takes under a minute and defeats the most common interception scenario.
Agree on ground rules early, in plain language: what is on the record, what is background, what is off the record entirely. Then set a disappearing-message timer appropriate to the sensitivity, and tell the source what the timer does and does not do. It deletes from devices on schedule; it does not stop screenshots. A source who understands the limits will behave accordingly; a source who believes the app is magic will take risks the app cannot cover.
Ongoing source communication
For continuing source relationships, routine beats heroics. Keep source chats separate from everything else: no source conversations in the newsroom group, no source names in story-planning threads. Use nicknames or code names in contacts and chat titles. Turn off link previews for sensitive chats if you are cautious about metadata, and keep message content focused; every extra detail in a chat is a detail that exists on two phones.
Calls deserve the same care as texts. Signal's voice and video calls are end-to-end encrypted, which makes them far safer than a phone call, but call metadata (that a call happened, and when) is harder to hide than message content. For the most sensitive conversations, consider whether the call needs to happen at all, and whether both parties are in a safe location. Sealed sender helps here: it hides who is messaging whom from Signal's own servers, so even the service cannot easily map the relationship.
Registration lock and screen lock are non-negotiable for journalist phones. Registration lock stops someone from re-registering your number on another device; screen lock with a short timeout stops the casual snoop. These are device settings, not Signal features, but they are part of the workflow because the workflow includes the phone. The sealed sender explainer covers the metadata protection in detail.
Newsroom group hygiene
Newsroom Signal groups are where good source protection goes to die. A group with forty staff, interns rotating through, and ex-employees never removed is a broadcast channel, not a secure room. Treat newsroom groups with the same discipline as source chats.
Keep groups small and purposeful: the investigations desk, the story team, the editors. Review membership quarterly and remove anyone who has left; there is no auto-offboarding, so put it on someone's calendar. Never put source-identifying information in any group, no matter how trusted the members. If the story team needs to discuss a source, use code names, and keep the identifying details in one-to-one chats with the reporter.
Disappearing messages in newsroom groups need a deliberate policy, because newsrooms also have records to keep. Editorial decisions, legal review notes, and anything that might matter in a libel case should not auto-delete. A common workable split: logistics and chatter on short timers, editorial substance kept. Write the split down; "everyone knows" is not a policy.
The device-seizure reality
Now the hard part, stated plainly. If your phone is seized and unlocked, Signal's encryption does not protect the chats on it. End-to-end encryption protects messages traveling between devices; on the device, messages are readable by design, because you need to read them. A seized unlocked phone gives up its Signal history to whoever holds it, regardless of the app.
This is why the layers around the app matter more than the app. A strong device passcode (not a four-digit PIN, not biometrics alone in jurisdictions where you can be compelled to unlock with a finger or face) is the first wall. Disappearing messages are the second: a short timer means a seized phone holds days of history, not years. Keeping sensitive material out of the chat in the first place is the third: notes, documents, and recordings live in encrypted storage or not on the phone at all.
Be honest with sources about this. "Our chats are encrypted" is true and incomplete; "if my phone is taken and unlocked, our recent chats could be read, which is why we use short disappearing timers and code names" is the complete version. Sources deserve the complete version before they trust you with their safety. The police-access explainer walks through what law enforcement can and cannot get from Signal itself.
Myths to stop repeating
A few myths circulate in newsrooms and they are actively harmful, because false confidence is worse than honest caution.
| Myth | The reality |
|---|---|
| "Signal is NSA-proof." | No consumer app resists a top-tier intelligence agency. Signal raises the attack cost enormously, but "proof" is a fantasy word. |
| "Disappearing messages mean it is gone." | They delete from devices on schedule. They do not stop screenshots, photos of the screen, or copied text. |
| "If we both use Signal, we are safe." | Safe from interception in transit. Not safe from compromised phones, spyware, coerced unlocks, or the other person talking. |
| "Deleting the app deletes everything." | Deletion is local to your phone. The other person's phone, their backups, and screenshots keep the content. |
"Signal is NSA-proof." No consumer app is proof against a top-tier intelligence agency with device-exploitation capabilities. Signal raises the cost enormously compared to unencrypted alternatives, and that matters, but "proof" is a fantasy word. Stop using it, especially with sources.
"Disappearing messages mean it's gone." They mean it is deleted from the devices on schedule. They do not mean the recipient did not screenshot it, photograph the screen, or copy the text elsewhere first. Treat disappearing messages as exposure reduction, not erasure.
"If we both use Signal, we're safe." You are safe from interception in transit. You are not safe from a compromised phone on either end, from spyware, from a coerced unlock, or from the other person simply talking. The app secures the channel; the endpoints and the humans are separate problems.
"Deleting the app deletes everything." Deleting the app removes it from your phone. It does not delete messages from the other person's phone, from backups they made, or from screenshots they took. Deletion is local unless everyone involved deletes.
What Signal can't do for you
The limits, journalist edition.
Signal cannot protect a compromised device. Spyware on your phone or your source's phone reads messages before encryption and after decryption. If device compromise is in your threat model, the fix is device hygiene and expert help, not a different chat app.
Signal cannot hide that you communicate. Your carrier or ISP can see that your device talks to Signal's servers and when. Sealed sender hides who you talk to from Signal itself, but network-level observation of "this phone uses Signal" is largely unavoidable. In some contexts, merely using an encrypted app draws attention; plan for that.
Signal cannot verify who you are talking to. Usernames and display names are self-chosen. A source, or someone impersonating one, is whoever holds the keys. Verify safety numbers through a trusted second channel before anything sensitive, every time the app warns you a key changed.
Signal cannot give you legal protection. Shield laws, source-protection statutes, and press freedoms vary wildly by jurisdiction and are legal questions, not technical ones. The app does not know your jurisdiction. Talk to your newsroom's lawyer about what protection actually covers you, and do it before you need it.
Signal cannot keep your newsroom's records. If your organization has retention duties, or if editorial and legal review notes might matter in court, those do not belong under a disappearing timer. Keep the records your lawyers would want, in systems built for records.
The pre-publication checklist
Before a sensitive story publishes, run this review with everyone involved. It takes twenty minutes and it is the highest-value security work most newsrooms never do.
Review who knows what
List every person who knows the source's identity. If the list is longer than it needs to be, that is the finding. Shrink it now.
Check the chat histories
Confirm disappearing timers are on for source chats, and that no identifying material sits in newsroom groups. Delete what should not exist.
Verify devices
Everyone on the story: screen lock on, OS updated, registration lock on, no unknown linked devices in Signal settings. Check linked devices explicitly; a forgotten desktop client is an open door.
Confirm the legal position
Has the newsroom lawyer reviewed the source-protection plan for this jurisdiction? If not, that conversation happens before publication, not after a subpoena.
Brief the source
Tell the source what changes at publication: attention increases, old messages may be re-examined, and the agreed story about how you met should be consistent. Agree on post-publication communication rules.
Frequently asked questions
Is Signal safe for journalists' sources?
Signal's encryption, disappearing messages, and sealed sender are genuinely strong protections for source communication. But safety comes from habits: verification, minimal data, short timers, and device security. The app is one layer, not the whole plan.
Should sources verify safety numbers?
Yes. Matching safety numbers through a trusted second channel confirms no one is intercepting the conversation. Do it at first contact and again any time the app warns that a contact's key changed.
Can police read a journalist's Signal messages?
From Signal's servers, no: there is essentially nothing to hand over beyond basic account dates. From a seized unlocked phone, yes: chats on the device are readable. That is why timers, lock screens, and minimal data matter.
Should newsroom groups use disappearing messages?
For logistics and chatter, yes. For editorial decisions and legal review notes, no: those may need to be kept. Write the split into newsroom policy rather than leaving it to individual judgment.
Is Signal really NSA-proof?
No, and stop saying it. No consumer app is proof against a top-tier intelligence agency. Signal raises the attack cost enormously, which defeats most realistic adversaries, but absolute claims create dangerous false confidence.
Keep reading
- the sealed sender explainer
- what police can actually get
- how disappearing messages really behave
- nonprofit teams with similar needs