SecureDrop consists of three components: a submission server that hosts the source interface as a hidden service, an admin server that manages the system and hosts the journalist interface as a separate hidden service, and an air-gapped admin workstation used by journalists to access decrypted submissions. The submission and admin servers can run on the same physical machine or on separate VPS instances for additional isolation.
All communication between sources and the system occurs through hidden service addresses. Sources use a Tor Browser to visit the submission hidden service, submit documents and messages, and can return later to check for replies using a codename. Journalists access the admin hidden service only from an air-gapped admin workstation running the Tails operating system, preventing journalist device compromise from affecting the confidentiality of sources or submissions.
AnubizHost offshore VPS in Iceland or Romania is appropriate for hosting the server components. Both jurisdictions have strong data protection environments and no mandatory data retention requirements that would force logging of onion service access patterns. The hosting provider sees an anonymously provisioned VPS but cannot access the encrypted submissions stored on it.