Identify the harm before choosing the trigger

List the people who could be harmed by disclosure, the adversaries who may seek the material, the consequences of a false release and the time in which a response would matter. If the required response is measured in minutes or hours, a service with a 1-day minimum check-in and daily processing is not an appropriate safety trigger.

The safer use is delayed editorial continuity: a trusted editor receives enough authenticated context to locate and assess material under existing newsroom procedures.

Consent does not become optional after death

A source may consent to publication of facts but not identity, raw messages, location, medical information or family details. Record the scope of consent and the conditions under which it may change.

Do not assume that posthumous disclosure is harmless. The source and associated people may remain exposed. Name the editor or lawyer responsible for reviewing consent and public-interest considerations.

Model the metadata and recipient

Encryption protects file contents, not every surrounding fact. Account email, timing, file size, recipient address and service access may create metadata. The recipient's inbox and device can also be compromised.

Use the minimum necessary data, independently authenticate important evidence, and keep source identity separate when possible. Private mode requires a password or recovery phrase ZeroLatch does not store; losing it makes the files unrecoverable.

Prevent automatic publication of unverified material

A switch should not turn absence into a publish command. Evidence may be incomplete, manipulated, legally restricted or unsafe. Give the recipient a verification checklist, provenance information, hashes where useful, and explicit stop conditions.

Preserve authoritative copies in an approved newsroom or legal system. ZeroLatch is not a public drop, content host, publisher, warrant canary or legal review.

Test the boring failure modes

Test a bounced or mistyped email, scanner-opened link, expired token, recipient using another device, missing recovery code, service outage and file-integrity check. Confirm the recipient knows the legitimate domain and support route.

Review the plan when a story, source, editor, jurisdiction or threat changes. A threat model is a maintained decision record, not a one-time configuration.