SolidarityTools

Digital hygiene for organisers

A short checklist for any group holding other people's information.

A tenant group knows who is behind on rent. A mutual aid network knows who needed food. A union branch knows who is about to be disciplined. That information is the most valuable thing the group holds, and it is usually kept on personal phones with no plan at all. This is a workable baseline — not paranoia, and not nothing.

Start here. The single biggest risk to a small group is not a sophisticated attacker. It is a lost phone, a shared spreadsheet with open link access, and a group chat that keeps everything forever. Fix those three and you have removed most of the danger.

Know what you hold, and who holds it

Messaging

Accounts and access

Devices

Documents

When something goes wrong

Have this written down before you need it, because you will not think clearly in the moment:

  1. Who is told first. Name a person, not "the committee".
  2. How access is cut off the same day: passwords changed, sessions logged out, the missing device wiped remotely.
  3. Who contacts members. The people whose information was exposed should hear it from you, plainly, before they hear it elsewhere.
  4. What you will not do: do not ask members to delete evidence, and do not discuss what happened in the main chat.

Absolute limits. This page is general hygiene, not legal advice and not threat-model advice. If your group faces state attention, organised opposition, or is supporting people in criminal proceedings, general hygiene is not enough — get situation-specific guidance from an organisation that does this work for a living, and do it before the situation, not after.

Free to copy, adapt and pass on. Corrections to hello@solidaritytools.com.