NAILS
Plausibly deniable dual-environment computing for NixOS
security engineer · Linux systems engineer
Security engineer and Linux systems engineer building NixOS-first systems, security tools, and repeatable infrastructure.
Based in Stockholm and finishing an MSc in Information Security at Stockholm University. Background in Linux systems engineering, automation, and security work, with current public projects focused on NixOS, privacy-focused system design, and forensic testing.
security engineer · Linux systems engineer
MSc in Information Security · Stockholm University
NixOS first · Rust for core tooling · Python and Bash for automation
8+ years with Linux systems · 4 years at ETH Zürich
selected work
Plausibly deniable dual-environment computing for NixOS
Privacy-focused amnesic NixOS live distribution built for NAILS
Download apps on-demand while still showing them as installed to keep the host lighter
GitHub snapshot cached locally on 2026-06-11.
consulting
Design and deploy fully declarative NixOS systems from scratch.
Same shell, same tools, same versions — on every machine that runs it.
Reduce your Linux system's attack surface against a real threat model.
Purpose-built CLI tools and automation in Rust, Python, or Bash.
Structured testing of what traces your systems leave behind.
Audit where your infrastructure retains or leaks data beyond intent.
Engagements are scoped individually. Reach out at contact@witteshadovv.dev with context on your situation.
tools / approach
What I use most right now.
How I build and run systems.
Security work tied to real systems and real investigations.
The defaults behind my design choices.
Static public site. Minimal JavaScript used only for theme choice and small interface polish.
contact / verification
Plain email is the best first contact for hiring, consulting, or general questions.
Use the security address for disclosures, reviews, or anything sensitive.
Primary public code and repository trail.
Cross-link proof and identity graph.
Fingerprint: FCEB 73CE 73A7 00A8 8548 F25D CB4B BA75 1B7B 4D4D
Secondary channel when needed.
Published disclosure policy and encryption reference.