NAILS
Plausibly deniable dual-environment computing for NixOS
Cyber Security Engineer · Linux systems engineer
Building NixOS-first systems, security tools, and repeatable infrastructure.
Based in Zürich and working as a Cyber Security Engineer. MSc in Information Security from Stockholm University. Background in Linux systems engineering, automation, and security work, with current public projects focused on NixOS, privacy-focused system design, and forensic testing.
Cyber Security Engineer · Linux systems engineer
full time in Zürich · open to selected consulting
MSc in Information Security · Stockholm University
NixOS first · Rust for core tooling · Python and Bash for automation
8+ years with Linux systems · 4 years at ETH Zürich
nixpkgs · portmaster package and NixOS module
selected work
Plausibly deniable dual-environment computing for NixOS
Privacy-focused amnesic NixOS live distribution built for NAILS
Download apps on-demand while still showing them as installed to keep the host lighter
Repository data from GitHub as of 2026-09-10.
MSc thesis · Stockholm University · 2026. The academic groundwork behind NAILS. Combines declarative NixOS configuration and overlay filesystems into a reproducible dual-environment design, with a forensic evaluation of what traces remain.
Packaged the Portmaster application firewall and wrote its NixOS module. Maintained in nixpkgs since August 2026.
consulting
I work full time as a Cyber Security Engineer. Consulting stays limited to a few scoped engagements that do not conflict with that role. Typical work is fixed scope audits, reviews, and tooling.
Design and deploy fully declarative NixOS systems from scratch.
Same shell, same tools, same versions on every machine that runs it.
Reduce your Linux system's attack surface against a real threat model.
Purpose-built CLI tools and automation in Rust, Python, or Bash.
Structured testing of what traces your systems leave behind.
Audit where your infrastructure retains or leaks data beyond intent.
Engagements are scoped individually. Reach out at contact@witteshadovv.dev with context on your situation.
tools / approach
What I use most right now.
How I build and run systems.
Security work tied to real systems and real investigations.
The defaults behind my design choices.
Static public site. Minimal JavaScript used only for theme choice and small interface polish.
contact / verification
Plain email is the best first contact for hiring, consulting, or general questions.
Use the security address for disclosures, reviews, or anything sensitive.
Primary public code and repository trail.
Cross-link proof and identity graph.
Fingerprint: FCEB 73CE 73A7 00A8 8548 F25D CB4B BA75 1B7B 4D4D
Secondary channel when needed.
Published disclosure policy and encryption reference.