contact

  • email — chattr [at] linux [dot] com (deobfuscate: [at]@, [dot].). The right door for everything: research, services, corrections.
  • PGP — key will be published at /pgp.txt; placeholder until it lands. Encrypt vulnerability reports and anything sensitive.
  • codegithub.com/skeletonsec. Bug reports for my tools are best filed as issues on the relevant repo.
  • security.txt/.well-known/security.txt for the machine-readable contact and disclosure policy.

Response time: I read everything; expect a reply within 72h, usually faster. Reports of vulnerabilities in my tools jump the queue — those get acknowledged within 72h with a PGP-signed thread if you encrypted yours.