TODO: Your Name Security engineer writing about critical infrastructure, surveillance, and the people they fail.

Contact

Ordinary questions, corrections, and pitches: email is fine. If sending me something could put you at risk, read the note at the bottom first.

Signal
yourname.01

Preferred for anything sensitive. Signal usernames don't reveal a phone number to either of us. Set disappearing messages on.

Email
you@example.com

Fine for routine contact. Assume the metadata — who wrote to whom, and when — is visible to others even if the body is encrypted.

PGP
0000 0000 0000 0000 0000 0000 0000 0000 0000 0000

Public key. Verify the fingerprint through a second channel before you rely on it — a key served from this site is only as trustworthy as this site.

If you're taking a real risk by contacting me

Be honest with yourself about your threat model before you send anything. None of the channels above make you anonymous to me, and none of them hide the fact that you contacted a journalist from someone who can see your network or your device.

If the risk to you is serious:

  • Contact me from a device and network that isn't your employer's and isn't your own — and not from an account tied to your name.
  • Don't take documents you aren't authorised to have before we've talked about how to do it safely. The act of collecting them is often what gets detected, not the sending.
  • Read the Freedom of the Press Foundation guides and the CPJ digital safety kit first. They're written for exactly this moment.
  • Access Now's Digital Security Helpline gives free 24/7 support to journalists, activists, and civil society. You can talk to them without talking to me.

TODO: once you're handling material from at-risk sources regularly, talk to Freedom of the Press Foundation about a real submission system. Don't roll your own.