Secure Communications

Digital Security for Union Organizing: A Different Threat Model

August 12, 2026 8 min read Haven Team

Most security advice assumes the adversary is external: a criminal, a foreign intelligence service, a stranger trying to get in. Workplace organizing flips that assumption. The party with the most reason to monitor communications is the one who already has legitimate administrative access to the network, the devices, and often the building, and who, in most US states, can terminate the account holder for reasons that have nothing to do with the organizing and everything to do with it.


This isn't a hypothetical concern layered on top of ordinary workplace privacy. Federal labor law in the US, under the National Labor Relations Act, protects the right to discuss wages, working conditions, and unionization with coworkers. That legal protection exists precisely because employer monitoring and retaliation against organizing communication is a well-documented, ongoing practice, not a rare edge case. Knowing the protection exists doesn't change the practical reality that violations are common, remedies are slow, and by the time a labor board rules on a retaliation claim, the immediate harm (a firing, a schedule cut, a hostile work environment) has already landed.

Why the employer's own network is the wrong channel

Company email, company Slack, and company-issued devices are all, by design and usually by written policy, subject to employer monitoring. That's not a security failure of those tools, it's the intended function: an employer has a legitimate interest in visibility over work communication on work systems, the same interest covered in our piece on employee monitoring software. The mistake organizers make most often is procedural rather than technical: assuming a private DM in a work Slack workspace is private from the workspace administrator. Workspace admins can typically read direct messages, not just public channels, and depending on the plan and the org's export settings, often without notifying anyone that a message was pulled.

The same reasoning extends further than most people expect. A shared Google Workspace or Microsoft 365 tenant gives IT admins export tools built for e-discovery and legal hold, the same tooling used to comply with litigation requests, and there is no technical distinction between "export mail for a lawsuit" and "export mail because HR asked." A calendar invite titled vaguely enough to seem harmless still shows attendee lists to anyone with admin access to the calendar. None of this requires anyone to be watching in real time. It only requires someone to ask, after the fact, once organizing activity is already suspected.

The same applies to company-issued phones and laptops, which frequently run mobile device management (MDM) software that gives IT visibility into installed apps, and in some configurations, network traffic. A personal device on the company Wi-Fi network is a smaller risk than a company device, but company Wi-Fi can still see which domains a device connects to, even if it can't read encrypted message contents, which is enough metadata to raise questions an organizer would rather not answer.

The baseline rule

Any organizing communication should happen on a personal device, over a personal cellular connection or a trusted personal network, using an account not tied to the employer in any way, including recovery email or phone number. This single rule closes off the largest and easiest monitoring vector before any app-level choice even matters.

Metadata is the part that gets people, not content

Encrypted chat apps solve the content problem well. Metadata, who talked to whom, when, and how often, is the part organizers underestimate, and it's often the part that actually surfaces in a retaliation case: a pattern of after-hours calls between the same group of employees, a sudden cluster of contact right before a union petition filing, a shared group chat member list that maps cleanly onto who gets disciplined next. None of that requires reading a single message.

This is the same threat model whistleblowers and journalists' sources have faced for years, covered in more depth in our whistleblower operational security guide and secure communications for journalists pieces. The playbook transfers with one adjustment: a journalist's source usually has one relationship to protect. An organizing committee has an entire membership list, and metadata that maps that list is functionally as damaging as a leaked roster.

Practical steps, roughly in order of impact

The honest limit of technical measures

No app fixes an at-will employment relationship. Strong encryption and clean metadata hygiene reduce the employer's ability to build a monitoring-based case, but they don't touch retaliation that doesn't require evidence at all, a pretextual performance review, a schedule change, a "restructuring" timed suspiciously close to a petition filing. Digital security is a real, worthwhile layer of protection for organizing communication, and it is one layer among several that also include knowing the law, documenting events contemporaneously outside any employer-visible system, and coordinating with an established labor organization that has handled retaliation cases before. Treating strong encryption as sufficient on its own understates what organizing actually requires to be safe.

Documentation outlives the conversation

One habit worth building early: keep a personal, timestamped, non-employer-hosted record of anything that looks like retaliation, from the moment organizing conversations start rather than after the first adverse action. A schedule cut, a sudden write-up, a manager's comment referencing "some people stirring things up": each is more useful to a labor board or an attorney when it's logged close to when it happened, in the organizer's own words, on a platform the employer never had access to in the first place. This is the same operational discipline that shows up in personal safety planning more broadly: the goal isn't just preventing exposure, it's making sure that if exposure happens anyway, there's a clean, independently held account of what actually occurred and when.

Try Haven free for 15 days

Encrypted email and chat in one app. No credit card required.

Get Started →