Security work is priced for the people who can afford it, which leaves out exactly the people who need it most: journalists, activists, community groups, and everyday people living under surveillance. So we sell it to the ones with a budget and give it to the ones without.
We architect systems so we can't hand over what we never had.
Every line of code, every audit, every dollar donated is published.
No advertisers, no data brokers. Funded by our own client work and by people like you.
Each division has its own mandate and its own site. They share the same engineering standards, the same disclosure policy, and the same rule: we don't collect what we don't need.
The engineering and research team. Writes the open-source tools, runs the audits, publishes the disclosures. Everything it produces is public and free.
The education division. Teaches operational security to students, young developers, and community groups, and mentors the ones who want to go further into real research.
The commercial division. Sells audits, penetration tests, threat modelling, and opsec training to businesses. What it earns pays for the work the other two give away.
Companies that can afford security work pay Uwitz Corporate for it. Individual donors cover the rest. Between them they keep the tools free for the people who can't pay — and keep us out of the funding models that would compromise them.
DonatePaid engagements with businesses. Scoped, invoiced, and kept at arm's length from what the core team publishes — a client never gets to decide what we disclose.
One-time and recurring contributions from people who use the tools. Reported openly, down to the line item.
No advertisers, no data brokers, and no funding that comes with a say in our research.
Questions, press, or a vulnerability to report? Reach us directly — we read every message.