Contact

The fastest way to reach Kinryu Labs is by email: contact@kinryu.sh.

What to write to us about

  • Coordinated disclosure — you're a vendor responding to one of our reports, or a researcher coordinating with us on something related.
  • Corrections — you've spotted an error, an outdated detail, or something that needs a follow-up in a published writeup.
  • Collaboration — you're working on something adjacent in space systems or threat intelligence and think there's overlap worth exploring.
  • Tips — you've come across something relevant to what we cover and think it's worth a look.

Reporting a vulnerability?

To help us triage quickly, your first message can include:

  • The affected product, vendor, and version(s)
  • A short description of the issue and its likely impact
  • Reproduction steps or a proof of concept (redacted, if it's sensitive)
  • Your preferred disclosure timeline, and whether you'd like public credit

We follow a coordinated-disclosure approach: we won't publish anything about an issue until it's been addressed, or a reasonable timeline has passed without a response. See About for more on what we will and won't put out.

Before you send anything sensitive

Plain email isn't a secure channel. Please don't send embargoed details, unredacted proof-of-concept material, credentials, or anything else that needs to stay confidential in the initial message — reach out first and we'll figure out a safer way to handle specifics.

Encrypted contact

PGP for encrypted disclosures isn't set up yet — this section will carry a fingerprint and public key once it is. If you need to share something sensitive in the meantime, say so (without the sensitive part) in your first message and we'll sort out a secure channel from there.

Response times

Kinryu Labs is a small group publishing on an irregular cadence, so replies won't always be fast — but we do read everything that comes in. If something is time-sensitive (a disclosure deadline, an embargo date), say so up front and we'll prioritise accordingly.

Frequently asked

Do you take on paid engagements?

Not currently. Kinryu Labs publishes independent public research on its own schedule — no clients, no retainers — and that's what lets us say what we actually find. If that ever changes, we'll say so here first.

Can I stay anonymous when reporting something?

Yes. Tell us how you'd like to be credited — by name, by handle, or not at all — and we'll go with that. A throwaway address works fine for first contact if you'd rather not use your everyday inbox.

How long until I hear back?

We read everything, but replies aren't always quick — see "Response times" above. Flagging anything time-sensitive up front helps us prioritise it.

Do you take on research collaborations?

Often, yes — particularly where it overlaps with space-systems security or threat intelligence. Send a short outline of what you have in mind and we'll take it from there.