How to email me? Anonymous email recommended. Using PGP encryption recommended.
Frequency of checking emails: Last checked 2026-07-31. I will check my emails atleast once in three months.
Warrant canary: Last updated 2026-07-31. I have not received any legal request involving data or server access to samuelshadrach.com. I will update this paragraph atleast once in three months.
Proof of date: Ethereum block height 25860775, block hash 0xf15fe1d93b3af2df4ae953239d67562c6c0493b19d79f3f0a9c7da26f991fb42. This proves this document was edited at date equal to or later than 2026-08-29
Proof of identity: TO DO. (Only long-form video or in-person meeting counts as conclusive proof IMO, and I haven't yet uploaded such a video yet.)
Overall security: Medium
If you don't need a high level of security: You probably don't need to contact me on this address, just use my other (less secure) protonmail or Signal instead. I do not check emails on this address frequently, as mentioned below.
If you need a moderate level of security: You can send me PGP-encrypted messages on this address
If you need the highest possible security: I do not follow security practises that are sufficient for this. You can either submit your leak to a server listed on the official SecureDrop server directory, or redact and publish the leak yourself (to ethereum blobdata or similar).
Why do I maintain a PGP-encrypted email address that I only check once in 3 months?
You are welcome to contact me on this address for any purpose whatsoever.
The primary reason I decided to maintain this email address is for a worst-case scenario where you have some leaked information or documents that you wish to publish, but are unable to work with a journalist operating SecureDrop. For example, this could happen if the US govt became more authoritarian and prevented journalists living on US soil from publishing your leak. Since I live in India, it may hence be easier for me to redact and publish your leak.
As of 2026-08, this is a highly unlikely scenario. In most scenarios, you should not be working with me. You can either submit your leak to a SecurDrop server, or redact and publish the leak yourself. Journalists operating Securedrop typically have a bigger legal budget than I do, they have more previous experience doing redaction than I do, and they may have some political immunity provided by the people funding their media house.
If however, we end up in a worst case scenario where you are relying on me to redact and publish your leak, then I will probably do my best to actually upgrade my security practises. My current security level as of 2026-08 is only Medium, but there are steps I can take to bring it closer to High, if it were absolutely necessary.
Security practises followed
Security, digital
Dedicated PC for this purpose.
Inbox and keys accessed on TAILS only.
128-bit memorised seedphrase (never used outside of tails) + 128-bit seedphrase in secure physical location (never used outside of tails) + PGP privkey (has left tails). All 3 pieces of info required to decrypt.
All emails are deleted within 1 month of being read.
Security, physical
This inbox is only operated from secure physical location. Seedphrase (mentioned above) stored in secure physical location.
I do not live 24x7 in a secure physical location. I visit secure location to operate the inbox.
My physical location is not secret. There exist people (including people I don't trust) who know where I live.
Legal
Do not have significant legal budget
Likely to cooperate with law enforcement in India in case of investigation. Discretion used on case by case basis.
Social / psychological
Operating solo. No dedicated team
Only operating part-time not full-time
No social isolation practised
Keeping secrets solo may be psychologically unsafe
Sober since 2026-02
I blog about my life, which could leave clues about me or my social circle.
Server host
Proton may be preserving email content and metadata (timestamps, file sizes, email addresses used, browser fingerprints, etc)
Proton has previously cooperated with law enforcement in investigations
Proton has never encountered a significant breach of data or passwords, as of 2025-06
Subscribe
Enter email or phone number to subscribe. You will receive atmost one update per month.
Alternatively, you can subscribe via RSS, or a third-party service like blogtrottr