Encrypted contact
PGP & encrypted communication
Use this key to encrypt anything sensitive you send to Improbus, or to verify our signed messages and advisories.
Placeholder. The production PGP key, fingerprint, and WKD-discoverable key file are pending provisioning by Improbus AS. The structure of this page is final; the fingerprint and key download below will be updated when the production key is in place. For now, use one of the channels on our Contact page.
Fingerprint
XXXX XXXX XXXX XXXX XXXX XXXX XXXX XXXX XXXX XXXX
Verify out of band. Before you trust this fingerprint, confirm it through a second channel — ask us to read it back by phone, or check it in person. A fingerprint shown only on a web page can be swapped in transit.
Key details
- Type
- Published with the production key (modern ECC, or RSA‑4096)
- Key ID
- –
- Created
- –
- Expires
- Rotated on a defined schedule
These fields are filled in when the production key is provisioned.
Download the public key
- improbus-contact.asc — ASCII-armoured, suitable for
gpg --import(coming soon) - WKD: discoverable from
contact@improbus.comvia--auto-key-locate wkd(coming soon)
All Improbus public keys live under /pgp/ — one canonical location, regardless of language.
Verify & locate
gpg --auto-key-locate clear,wkd --locate-keys contact@improbus.com
The command above asks GnuPG to discover the current public key for contact@improbus.com via WKD (Web Key Directory) — no manual download required.
Send us something encrypted
- Get our key —
gpg --import improbus-contact.asc, or fetch it by WKD:gpg --locate-keys contact@improbus.com. - Encrypt —
gpg --encrypt --armor --recipient contact@improbus.com yourfile. - Send — email the resulting
.asc(or paste the ciphertext) to contact@improbus.com.
What we encrypt and/or sign
- Confidential informationConfidential business information such as contracts, financials, plans, and internal documents.
- Identity-sensitive materialAnything that could expose a person, including whistleblowing and witness intake, sources, and personal data.
- Incident communicationsLive DFIR coordination when an out-of-band, TLP:RED channel is needed.
- Vulnerability reportsCoordinated disclosures, proofs-of-concept, and sensitive technical detail.
- Advisory informationSecurity advisories and notices we sign, so you can verify they are genuinely from us.
- Privileged or confidential data of any kindAnything else legally privileged or confidential. When in doubt, encrypt it.
Key rotation
The production PGP key is rotated on a defined schedule, and out-of-cycle on suspected compromise. Superseded keys are revoked, and the revocation certificate is published alongside the replacement key.
Related: Traffic Light Protocol (TLP) — how we classify what needs encrypting · /.well-known/security.txt