[ About ]
We approach software the way attackers do.
RootXLabs is an independent offensive security research lab. We are less interested in what a tool flags than in how a system is actually put together — and where those assumptions break.
Why we exist
Most security tooling is optimised to produce findings. That is not the same as producing security. A scanner that reports two hundred issues has moved the work, not done it — someone still has to open each one, decide whether it is reachable, and decide whether it matters. Most are not, and most of that time is wasted.
We work the other end of that problem. We read a system for its architecture, its assumptions and its trust boundaries, look for the unexpected behaviour at the edges, and follow it through an exploit chain until it reaches real impact — or until we are sure it does not. The output is not a list of maybes. It is the small number of things that are actually true.
How we think
The lab runs on three habits, not a methodology deck:
- Curiosity. The interesting bug is usually in the part of the system nobody wanted to explain. We go there first.
- Adversarial thinking. Every boundary is an assumption about what an attacker cannot do. We treat that as a question, not a fact.
- Real-world validation. A finding is not a finding until it reproduces on a clean build, with a negative control proving which path actually fired.
How we work
- Exploit or it did not happen. Findings ship with a working proof-of-concept. If we cannot build one, it stays internal.
- Scope is sacred. We test what you own and authorize, and nothing adjacent to it — no matter how interesting it looks.
- We take the minimum. One record instead of the table, a redacted screenshot instead of a dump. Enough to prove it, no more.
- Severity is honest. If a bug is a Low, we call it a Low. Inflating severity to look productive burns the trust that makes the next report worth reading.
Track record
Our findings have earned assigned CVEs and acknowledgements from major vendors, several in widely deployed products. We publish a finding only once the vendor has shipped a fix and cleared it — so several of ours are not listed anywhere yet, and will not be until they are. The public record and the disclosure rules behind it are on the research page. If you are evaluating us and want the detail before an embargo lifts, ask and we will walk you through it under NDA.
Where we are
Early, and honest about it. We would rather say that than pad this page with a leadership grid and customer logos we have not earned. There is no SOC 2 report yet, no ISO certificate, and no paid bug bounty. When those exist they will be listed with dates and auditor names — not as badges.
Talk to us
Engagements: hello@rootxlabs.ai. Security issues in our own systems: security@rootxlabs.ai. The way we disclose — in both directions — is on our responsible disclosure page.