Tell me what you want to understand

Send your website, API or Shopify store URL and your question. If you're unsure which service fits, describe the problem in your own words.

I'll reply within one business day with a proposed next step, scope and start date. We work in writing.

Website or API audit

Include the URL and what you want the audit to answer.

Ask about an audit

Shopify check

Include your storefront URL, .myshopify.com domain, primary market and up to three priority products.

Ask about a Shopify check

Or write your own message

Email info@turva.dev. Existing scanner results are welcome, but you do not need them to get started.

The buttons above open a draft in your email app. You can edit it before sending, or write the same details in a plain email.

Other ways to reach me

Signal works for short questions. Send longer documents by email. You can open Signal directly or use the QR code.

Signal encrypts messages end to end. Scanning the code opens my contact in Signal.

Signal QR code for the username turva.19. Scan it with a phone to start a Signal chat. @turva.19

Reply time and languages

You can write in English or Finnish. Reports are in English unless we agree on Finnish in the written scope. An unrequested brief is written in the language of the company it is about.

Confidential material

I sign your own NDA as it stands, at no charge, before material is shared.

The audit does not require production credentials. Any deployment, DNS, Shopify or repository access needed for purchased implementation is agreed separately and limited to the work.

Optional encrypted email

You can send OpenPGP-encrypted email to erik@turva.dev. Encryption is optional, and an ordinary message receives the same reply time.

The version 4 key is at https://turva.dev/pgp-key.asc. It is also published through Web Key Directory, so a mail client that supports WKD can look it up from the address alone. The version 6 key is at https://turva.dev/pgp-key-v6.asc and is not published through Web Key Directory.

Two keys are published for the same address. The first is an OpenPGP version 4 key, Ed25519 for signatures with a Curve25519 encryption subkey. The second is an OpenPGP version 6 key, ML-DSA-65+Ed25519 for signatures with an ML-KEM-768+X25519 encryption subkey, the post-quantum pair that carries the encryption when a client uses this key. The version 6 key is for clients that read OpenPGP version 6.

Whether a client can use either key depends on whether it reads that key version and those algorithms, not on OpenPGP support in general, and version 6 support alone does not settle the second one, because the post-quantum algorithms are a separate extension to the format. Clients also differ in whether they look a key up through WKD at all, and which of the two keys a client uses depends on that client.

I have not tested any particular mail client against these keys.

GnuPG 2.4.9 imported the version 4 key from /pgp-key.asc and refused the version 6 key. That was a test of the command-line tool and not of a mail client.

Fingerprint of the version 4 Ed25519 key:

96EA E8CF 3B99 FB0E 8E28 7426 C5E6 B20F 8FF0 7FC6

Fingerprint of the version 6 post-quantum key:

43DA 21C6 8589 9321 BD1A 70C0 AD85 25CE B408 3B71 DF22 6EFC BE5C 737C BDDA 8DA7

Check the fingerprint before you use the key. A fingerprint shown on this page relies on the trustworthiness of the page itself.

Business details