Skip to content

Digital safety

Source protection is not a procedural courtesy on a Southeast Asian verification desk. In Laos, Thailand, the Philippines, Sri Lanka, Malaysia and Indonesia the gap between a careless workflow and an exposed source is the gap between a published debunk and a person who can no longer go home. The Digital Safety section is the part of the toolkit where that proposition is taken at face value. It does not replace the T6 source-protection tree; T6 is the routing layer, used in-case, while the live work is in front of you. This section is the layer behind T6. It is where the threat model that T6 codifies is explained, where the country-specific legal architecture is set out in operational terms, where the ten S-classes are read together as one editorial system instead of as a list of separate gates, and where the pre-upload, pre-publication, pre-source-contact, and post-publication checklists are laid out as a small set of habits a working desk can adopt and reuse.

The section's editorial position is direct, and the rest of the toolkit hangs from it. A workflow that produces a verification at the cost of exposing a source is not a verification. It is a security incident that happened to include a verification result. The T6 tree expresses this as a routing rule. The Digital Safety section expresses it as the standing posture from which the rest of the work proceeds. Every detection tool, every tipline routing decision, every claim-extraction step inherits the framing.

What this section covers

Five pages, each carrying a different operational job.

The Country-specific legal context page reads the six focus jurisdictions as one comparative frame. The country pages already carry the legal facts on a per-country basis. This page collects them, reads them across one another, and surfaces the operational implications a working fact-checker needs in front of them when the verification work touches public officials, security forces, royal or religious subjects, election cycles or any of the cross-border patterns that have appeared in the casework through 2024–2026. It expands the country pages' legal sections without restating them.

The Source-protection aggregation page reads the ten S-classes (S1 through S10) as a single editorial system. T6 routes a case to the S-class that fires. The aggregation page explains why each S-class is its own category, what threat it codifies, how mitigation actually unfolds end-to-end, and what editorial-position statement sits behind it. This is the toolkit's deepest pedagogical text on source protection. A reader who has spent ten minutes here should understand what the toolkit is doing differently from a generic OSINT primer when it says, for example, that S6 (detector-only accusation) and S8 (liar's-dividend) are editorial twins.

The Threat models page works through six recurring actor patterns the Southeast Asian fact-checking environment has produced: the surveillance state, the election cycle (with AI intermediaries now part of the model since the DRI 2025 Sri Lanka study), the scam economy, red-tagging and the anti-press enforcement frame, communal-memory politics, and the cross-border legal-intimidation pattern. Each carries a primary-case anchor and the routing implication into T6, T7 and the relevant tool cards. The page is read alongside the country pages, not after them; the country pages are six grounded reads of the regional environment, and the threat-models page is the recurring patterns those reads share.

The Operational checklists page is the part of the section that is genuinely list-shaped. Pre-upload, pre-publication, pre-platform-report, pre-source-contact, and post-publication monitoring. The checklists are intended to be lifted into a newsroom's standing-operating-procedure document, adapted to the local context, and used as the discipline at the moments where attention is shortest and the consequences are sharpest. They are the operational expression of what the rest of the section sets out as posture.

This index page frames the section and routes the reader. It is the shortest of the five.

When this section applies

Digital Safety applies to every case where source identity, legal sensitivity, or cross-border vendor exposure is in scope. In the six focus countries, that is most political-content work, most security-forces work, most religious or royal-subject work, most cases routed through tiplines, most cases involving cloud-hosted detectors, and most cases reaching diaspora reporters or partner organisations across jurisdictions. The boundary is wide because the operational reality in Southeast Asia is that the surveillance-risk surface is wide.

Two practical signals tell a desk that the section binds on the case in front of it. First, the source whose identity travels with the file (the face on the video, the voice on the audio, the original-poster handle, the WhatsApp number, the named whistleblower) is a person who can be identified by anyone who has the file. Second, the artefact's subject sits inside one of the country-specific legal-exposure surfaces the country-legal-context page lays out. Either signal alone is sufficient. Both together, which is the more common case, is the standing posture for a high-S2 country (Laos, Thailand on Article 112-adjacent material, Sri Lanka on north-and-east community work, the Philippines on red-tagging-adjacent cases).

Cases where the section does not bind in full are the smaller fraction. Routine scam-economy work where the subject is a corporate or celebrity impersonation with no identified source. Election-cycle verification on already-published campaign material. Civic-education-tier work surfacing existing debunks. Even on these, the post-publication monitoring section of the operational checklists still applies; the harassment-backlash and trauma-load surface fires after publication on cases the pre-upload work did not flag.

How this section sits with the rest of the toolkit

T6 carries the routing layer. The country pages carry the regional grounding. The pillar and tier sections (Pillar 1 detection, Pillar 2 counter) carry the technique-level architecture. The tool cards carry the per-tool detail. The decision trees T1 through T7 carry the in-case routing. The Digital Safety section carries the standing posture from which the others operate. The S-admonition that fires on a detector card during a verification pass is the operational expression; the editorial position that justifies the admonition lives here.

Reading order is flexible. A new fact-checker joining a regional desk can read this section first to build the threat-model frame, then move to the country page for the jurisdiction they are working in, then to the pillar sections for technique. A working desk on a current case can route through T6, then the country page, and reach this section in the slower hours afterwards to revise the standing posture for the next case. Both routes work. The section is built to be useful in either direction.

The cross-cutting access-barrier framing that runs through the toolkit (institutional pricing, IFCN gating, enterprise-only deployment) sits inside this section at the S9 cross-border-vendor-retention discussion. Tools that route sensitive Southeast Asian content to US or EU-hosted servers carry data-jurisdiction implications that no in-tool feature can resolve. The toolkit names this directly instead of working around it.

Cross-references

  • T6 source-protection – the operational routing layer this section pedagogically supports
  • Country pages – Indonesia, Laos, Malaysia, Philippines, Sri Lanka, Thailand grounded reads of the regional environment
  • Pillar 1 detection and Pillar 2 counter – the technique sections that operationalise S-admonitions on detector and tipline cards
  • T7 tipline routing – the response-gate where S2, S4, S5 and S7 fire on tipline-routed material
  • Platforms – platform-specific dominance and verification routing, with platform-specific S-firing patterns

Sources

  • Electronic Frontier Foundation. Surveillance Self-Defense. EFF, 2025. ssd.eff.org.
  • Access Now. Digital Security Helpline. Access Now, 2025. accessnow.org/help.
  • Architectural Anchors – Content Policies and Architectural Anchors 1, 2, 3
  • The six country pages (Indonesia, Laos, Malaysia, Philippines, Sri Lanka, Thailand) and the T6 source-protection tree