PGP & encrypted communication

Use this key to encrypt anything sensitive you send to Improbus, or to verify our signed messages and advisories.

Placeholder. The production PGP key, fingerprint, and WKD-discoverable key file are pending provisioning by Improbus AS. The structure of this page is final; the fingerprint and key download below will be updated when the production key is in place. For now, use one of the channels on our Contact page.

Fingerprint

XXXX XXXX XXXX XXXX XXXX  XXXX XXXX XXXX XXXX XXXX
Verify out of band. Before you trust this fingerprint, confirm it through a second channel — ask us to read it back by phone, or check it in person. A fingerprint shown only on a web page can be swapped in transit.

Key details

Type
Published with the production key (modern ECC, or RSA‑4096)
Key ID
Created
Expires
Rotated on a defined schedule

These fields are filled in when the production key is provisioned.

Download the public key

All Improbus public keys live here under /pgp/ — one canonical location, regardless of language.

Verify & locate

gpg --auto-key-locate clear,wkd --locate-keys contact@improbus.com

The command above asks GnuPG to discover the current public key for contact@improbus.com via WKD (Web Key Directory) — no manual download required.

Send us something encrypted

  1. Get our keygpg --import improbus-contact.asc, or fetch it by WKD: gpg --locate-keys contact@improbus.com.
  2. Encryptgpg --encrypt --armor --recipient contact@improbus.com yourfile.
  3. Send — email the resulting .asc (or paste the ciphertext) to contact@improbus.com.

What we encrypt and/or sign

Key rotation

The production PGP key is rotated on a defined schedule, and out-of-cycle on suspected compromise. Superseded keys are revoked, and the revocation certificate is published alongside the replacement key.