contact

Contact And Keys

one address, one key, and a written answer. encrypted when it needs to be.

status
available
timezone
utc+01
channels
email · pgp · signal · matrix · session
[01] >

Channels

Email first. The rest exist for the cases where email is the wrong shape - a handle you would rather not tie to a mailbox, or a file that should not sit unencrypted on a mail server.

primary

Email

[email protected]

The address that gets read. Plain text is fine for scheduling and scoping; encrypt anything carrying reproduction steps, credentials or a client name.

  • plain text
  • attachments under 10 mb
  • pgp welcome
secondary

Signal, Matrix, Session

Same person, slower inbox. Use one of these when the address itself is the sensitive part, or when a short live conversation is cheaper than four rounds of mail.

  • Signal @rky.placeholder voice or text, no group invites
  • Matrix @rky:placeholder.invalid direct messages only, encrypted rooms
  • Session 05...placeholder no phone number, no account

Placeholder handles - replace with the real Signal, Matrix and Session identifiers before launch.

form

Send a message

A pseudonym is fine. A company name is faster if there is a contract at the end of this.

Target class, what you want looked at, and the window you have in mind. Three sentences is enough to get a real answer back.

This form has no server. Submitting composes an email in your own mail client - nothing is transmitted from this page. If your browser has no mail handler, write to [email protected] directly.

Reporting a vuln?
[02] >

What to include

A first mail that answers these gets a real answer back, usually with a number in it. One that does not gets a round of questions first, and that costs both of us a day.

  1. 01

    Who you are

    Company or handle, and who is able to authorise testing. A pseudonym is fine for the first mail; a signature is needed before anything is touched.

  2. 02

    The target

    Product, binary, domain or protocol, with a version or build if you have one. Say whether you own it or operate it under contract, and who else has a say in the scope.

    required

  3. 03

    What you want from it

    A surface review, one specific question answered, a second opinion on someone else's report, or a retest of findings that were already fixed once.

  4. 04

    Constraints

    Deadline, budget band, change freezes, systems that must not be touched, and whether production is in play at all. Constraints shape the quote more than the target does.

    drives the quote

  5. 05

    How to reach you

    The address or handle you actually read, and whether you can receive encrypted mail. If you cannot, say so now rather than after the report is written.

[03] >

Response windows

Mail is read on working days from UTC+01, usually twice a day. Weekends and public holidays only while an engagement is live.

Targets, not a contractual SLA. Working days are Monday to Friday. An agreed response time inside a signed engagement always overrides this table.
What you sent First reply What follows
Vulnerability report under 24h triage note with a reference inside 72h
Scoping or quote request 1-2 working days fixed quote, or a clear no, inside 5 working days
General enquiry 2-3 working days answered in the same thread
Live engagement same working day daily notes while the window is open

If a week passes with nothing, assume the mail did not land rather than that it was ignored. Resend it, or use one of the secondary channels - greylisting and aggressive spam filters eat more of these than you would think.

[04] >

Keys

One key covers this address and every channel above. Anything signed by a different key is not mine, whatever the display name says.

pgp public key

A71F 4C09 2B3D E884 5FD2 9C31 0E67 B4AA 21D5 F308

Placeholder key - replace with the real fingerprint before launch.

Pull the public key from a keyserver by fingerprint, then verify it out of band before you trust it. The short form printed in the footer and the drawer is the first half of the same fingerprint, so the two should agree on every page.

Encrypt anything that carries reproduction steps, credentials, client names or unreleased detail. Scheduling, invoicing and a one-line question do not need it, and encrypting them only makes the thread harder to search later.

Sending a finding rather than a question? The submit page has the intake form, the severity bands and the disclosure timeline. The machine-readable version of all of this lives at /.well-known/security.txt.

[05] >

Rules of engagement

The rule runs the same way in the other direction. Nothing of yours is touched without a written scope that names the targets and the window, signed by somebody who can authorise it. No scope, no work, however small the job looks from the outside.

Findings go to the vendor first. Coordinated disclosure, ninety days by default, extended when a fix is genuinely in flight. Nothing is sold or passed to a non-vendor, and nothing client-attributable is ever published - the track record is anonymised for exactly that reason.

The longer answers - payment, jurisdiction, what happens when nothing is found - are on the FAQ, and the engagement shapes and ranges are on the prices page.

next step

Sitting on a live finding?

The intake form asks for target, severity and reproduction in one pass, and tells you what happens to the report after it lands.