Contact Onyx Mail

Use the general channel for project and policy questions. Use the security channel for vulnerability reports. Email transport exposes metadata, and encryption applies only when the sender verifies and uses the published key correctly.

General Inquiries

Channel: ordinary email

Do not send passwords, private keys, recovery secrets, or unnecessary personal data. No response-time commitment is represented.

Security Reports

Send vulnerability reports to [email protected]. Include the affected route, observed behavior, reproduction conditions, and request identifier when available.

Key role: Published

Tor Access

Onyx Mail is available through the published Tor v3 address. Tor changes the network path; it does not encrypt ordinary email or conceal mail metadata.

Address: Published

Security Report Procedure

  • Verify the complete fingerprint before encrypting.
  • Encrypt sensitive report content to the security contact key.
  • Do not include live credentials, private keys, or unrelated personal data.
  • Verify signatures on replies against the same complete fingerprint.

[SECURITY CONTACT KEY]

Security Contact OpenPGP Key

FingerprintBCF4 79BE 7BF5 6646 600D 5CDD 84D7 298E 7EE5 650B
Key ID84D7298E7EE5650B
Download Contact Key

[METADATA BOUNDARY]

Email encryption can protect message content. It does not conceal sender, recipient, timing, or routing metadata.