About us

We're Mylocybe, the team behind the popular myco shop cylocybe.co.uk.

Why this shop was built

Have you been paying attention and noticed websites left, right and centre are being hacked with data ending up on the dark web for anyone to download? So have we. We launched this site, and the very next day it happened with ASOS being hacked.

More online shops run on WordPress with WooCommerce than on anything else, usually with a stack of plugins. Every plugin is code written by someone else, and plugins are where most break-ins start.

For the sites not built on WordPress, they are mostly built on Shopify. We recently set an account up on Shopify to see what kind of telemetry they have - trust us when we tell you that it's bad. Really bad. A website on their platform has to essentially sign away their customers' privacy to have a fully functioning website on their platform.

We built Mycoscopy differently: the less there is, the less can go wrong and the data collected is respected so that you can make private orders.

One small program we wrote ourselves

The whole shop is a single program written in Go. No WordPress, no plugins, no themes, no database. Apart from Go itself, it uses one extra package, made by the Go team, and only to switch on the lockdown described below.

How much code is behind a shop

A typical WordPress shop runs on a lot of code. We downloaded the latest versions and measured them ourselves:

That's around 400 MB and over 5 million lines of code, written by many different companies and people.

In 2026 alone, up to the end of September, 9,139 security holes were found in WordPress, its plugins and its themes. That's more than 30 a day, and almost half were rated high or critical. 31 were in WordPress itself, including a critical one in September that let attackers take over some sites without logging in. Every shop has to install each fix before attackers get there first.

The code we wrote for this website is just 0.33 MB, about 8,600 lines.

Sources: sizes and line counts measured by us on 5 October 2026 from the official downloads of WordPress, WooCommerce, Storefront and the 30 most popular plugins in the WordPress plugin directory. Average number of plugins: Studio Wombat, Plugin Insights 2026. Security holes in 2026: Patchstack WordPress vulnerability statistics. WordPress's own fixes: WordPress security releases.

OpenBSD

The server runs OpenBSD, an operating system built with security as its first priority.

So far in 2026, Debian, one of the most popular Linux systems, has put out 457 security updates, fixing 7,594 security holes. 2,648 of those were in the Linux kernel alone. In the same time, OpenBSD needed 33 security fixes.

Of Debian's 7,594 security holes, 3,763 were rated high or critical, including 771 critical. OpenBSD's 33 fixes covered 75 numbered holes, 29 of them high or critical.

Sources: Debian security advisories, counted by us from the Debian security tracker list (1 January to 4 October 2026). OpenBSD's fixes for the same period: OpenBSD 7.8 errata and OpenBSD 7.9 errata. Severity ratings: US National Vulnerability Database.

Where the shop is hosted

Right now the shop runs on a Virtual Private Server: a server we rent in a data centre, which we set up and run entirely ourselves. Soon it will move to our own hardware on our own premises, so no outside company will host the shop or the encrypted orders and messages kept on it.

Locked down while it runs: pledge and unveil

The shop uses two OpenBSD security features. With pledge, the shop promises OpenBSD, as it starts, the only kinds of things it will ever do, such as answering web requests and saving files. If it ever tries anything else, like running another program, OpenBSD stops it on the spot. With unveil, the shop tells OpenBSD the only folders it needs, its orders and messages folders, and everything else on the server becomes invisible to it. So even if someone found a flaw in the shop, they couldn't use it to run their own programs, or to read or change anything else on the server.

No admin dashboard

There's no admin area, login page or control panel on the website for anyone to attack. We manage orders from our own laptops, which collect them over an SSH encrypted connection.

Nothing runs in your browser

No JavaScript, no cookies, no trackers, no analytics, no third-party scripts. Our security settings tell your browser to refuse scripts outright, so even if someone sneaked code into a page, it wouldn't run.

You can also visit us over Tor at nk5iqjpcj7flbilyyba7ldz3akddigel6gokgdcmyesr2r7tjndyv3yd.onion.

Nothing worth stealing

There are no accounts or passwords, and we never handle card details. You pay by bank transfer or cash.

Every order and message is encrypted the moment it's saved, using public-key cryptography. The shop only holds the public key, which can lock files but can't unlock them. The private key that unlocks them is never on the server: it's kept only on our own laptops, which collect the orders. So even if someone broke into the server before orders and messages were purged, they would only find files they can't read.

Orders don't stay on the server

Each order is saved as a file, which we move regularly multiple times a day to our own local systems before deleting from the server. The one thing kept there is any conversation you choose to have with us on the site: encrypted, readable only with your private code, and deleted after 12 weeks.

Your details are deleted after 12 weeks

12 weeks after your order, we delete everything that ties it to you: your name, delivery address, email address, phone number, order notes and support code. You can get in touch to ask for your details to be deleted before then.

What we keep is what was bought, how many, the price, the date, how it was paid and the country it went to. That's all HMRC, the UK tax office, needs: a record of every sale, not of who made the purchase.

No tracking at all

Most websites watch their visitors. A study of millions of websites found that 75% of pages contain at least one tracker from another company. Google Analytics is on 53% of pages and Facebook's tracking pixel on 15%. This website has none: no Google Analytics, no tracking pixels, no cookies, and nothing loaded from any other company's servers. We keep no record of which pages you look at.

Source: HTTP Archive Web Almanac 2025, Privacy chapter.

Spam protection without tracking

The order and contact forms are protected without scripts or third-party captchas, and the server limits how much any one visitor can send.

Encrypted connections only

Every page is served over HTTPS, using only modern encryption.