■ WARROOM
Notes · Minutes · Documents · for groups that must not leak
Organize without leaks.
WarRoom is a simple notes and meeting-minutes app with one unusual feature: every person receives a slightly different copy of each document. If text turns up where it shouldn't, you know who let it out.
Fingerprinting 13 techniques · Deployment Self-hosted · EU · Auth Passkey · Hardware key
We are meeting at the depot on Monday at 19:00. Carry printed copies of the public statement and the agreed identification badges. Avoid discussing specifics on personal channels.
How it works
Same document. Different fingerprints. One traceable source.
Nothing to learn. You write, you share. WarRoom does the rest quietly in the background.
Write it once
01
A clean block editor for notes, minutes, decisions, action items, contracts. Or record a meeting and get structured minutes from voice.
Share to people, not links
02
Pick recipients. Each gets a copy with tiny natural variations: a synonym here, a comma there, a reworded footnote. Invisible to the reader, unique to the person.
Trace a leak in seconds
03
Paste leaked text, or a photo of it. WarRoom matches the variations against every copy sent and names the source with a confidence score.
Features
Built for organizers, not for IT departments.
Everything a small group needs to keep records and keep them inside the group.
Block editor
Headings, lists, to-dos, decisions, callouts. Type "/" for anything. Works like the note apps you already know.
Voice → minutes
Record a call. Get a transcript, decisions and action items. Transcription runs on-device; audio never touches a disk.
Folders & compartments
Group documents by operation. People only see the compartments they belong to. Codenames differ per compartment.
13 fingerprint techniques
Synonyms, punctuation, numeric jitter, regional spelling, footnote wording, sentence order, "barium meal" source names, and more. Stealth or transparent.
Leak trace
Paste text, upload a screenshot (OCR), or drop in a whole press article. Per-signal confidence breakdown, ranked suspects.
Honeypots
Plant plausible-but-false facts per recipient. If one surfaces, you know exactly who acted on it.
Compartmented chat
Disappearing messages tied to a document. Presence obscured. End-to-end encrypted.
Monitoring & trust tiers
Off-hours access, new devices, bulk exports, watchlists. Anomalies surface before the leak does.
Clean exports
Export as plain .docx or PDF with no branding, EXIF or edit history. Fingerprints stay in the text.
Roles
Four roles. Each sees exactly what it needs.
Access is decided by role and compartment. Stronger roles require stronger authentication.
01 · Superadmin
Runs the system.
Key rotation & policy · Honeypot registry · Emergency wipe · Full audit log
Hardware key required
02 · Manager
Owns documents and people.
Create & share documents · Configure fingerprints · Run leak trace · Monitoring & trust tiers
Hardware key required
03 · Coordinator
Keeps things moving.
Edit shared documents · Dispatch copies · Compartment chat · Cannot trace leaks
Authenticator app
04 · Participant
Reads what is shared.
Personal fingerprinted copy · Read-only · No fingerprint UI in stealth · Duress passcode, and much more, every week
Passkey
Security · threat model
Designed for the day something goes wrong.
We assume devices get seized, people get pressured, and someone inside talks. Each assumption has a control.
| Threat | Control |
|---|---|
| Insider forwards a document | Per-recipient fingerprints, honeypots, leak trace with confidence breakdown. |
| Member is detained and forced to unlock | Duress passcode opens a clean fake workspace and silently alerts managers. |
| Device is left open or stolen | Auto-lock, per-document biometric gate for operational tier, remote emergency wipe. |
| Account takeover | Hardware keys for Manager+, passkeys for everyone, device attestation, no SMS. |
| Slow compromise over time | Anomaly monitoring, trust tiers, watchlists, new-device alerts to peers. |
| Organizer disappears | Dead-man's switch expires owned documents after N days without check-in. |
| Vendor or cloud is compelled | Self-hosted in the EU. Your server, your keys. Tor access optional. |
What WarRoom does not do
It cannot stop a person from photographing a screen or retelling what they read. It makes the copy traceable, so that when it happens, you know who, and can act. Fingerprinting deters more than it prevents.
Cryptography
Per-document AES-256-GCM keys, rotated on schedule. SHA-256 signatures for every version stored in an append-only, signed audit chain. End-to-end encrypted chat over Matrix.
Data location
Runs on your own server or a hosting partner of your choice inside the EU. No analytics, no third-party scripts, no phone-home.
Pricing
Priced for collectives, not corporations.
Flat, per-group pricing. No per-seat surprises. Non-profit and grassroots discounts on request.
Self-hosted
Free · open source
Run it yourself. Full feature set, community support.
— Unlimited members & documents
— All 13 fingerprint techniques
— Leak trace & honeypots
— You manage updates & backups
Hosted · EU
€49 / group / month
We host in the EU on isolated instances. You keep the keys.
— Everything in Self-hosted
— Managed updates & encrypted backups
— Tor onion address
— Email support, 48h
Supported
Custom
For federations, NGOs and newsrooms with several groups.
— Multiple groups, shared policy
— Onboarding & security training
— Priority support & incident help
— Custom threat-model review
FAQ
Questions we get asked.
Will recipients notice their copy is different?
In stealth mode, no. The variations are natural rewordings a careful reader would not notice, and there is no fingerprint UI. In transparent mode, recipients are told their copy is fingerprinted, which is a deterrent in itself.
Does fingerprinting change the meaning of a document?
No. Only interchangeable wording, punctuation and non-critical numbers vary. Dates, names, amounts that matter are never altered. You can preview every recipient's copy before sending.
What if a leak is retyped or paraphrased?
Several techniques survive retyping (word choice, sentence order, invented source names, honeypot facts). Heavy paraphrase lowers confidence, and WarRoom tells you so rather than guessing.
Can it read a screenshot?
Yes. Leak trace accepts photos and screenshots, runs OCR locally, and matches the recovered text against all copies.
Is there a mobile app?
The web app works on phones. Native apps with screenshot blocking are planned; hosted customers get them first.
Who can see the fingerprints and run a trace?
Only Managers and Superadmins. Coordinators can edit and share but never see trace results. Participants see nothing about fingerprinting in stealth mode.
Is it really simple enough for non-technical people?
That is the point. Writing and sharing feel like any modern notes app. All the security is defaults, not settings. A first-run checklist covers the few things we need from each member.
Request a demo
See it with your own documents.
30 minutes, screen-shared. We walk through a real leak trace and answer your threat-model questions. No sales deck.
Replace this text module with a Divi Contact Form module (fields: Name or alias · Email · Group size). Set recipient to contact@wordpress-1534655-6663465.cloudwaysapps.com.
■ WARROOM
wordpress-1534655-6663465.cloudwaysapps.com · EU · self-hosted