[ Labs ]

Where we go looking for trouble.

Labs are the standing research tracks we run between engagements — the surfaces we keep pressure-testing because the trust models are still being written. Some are active, some exploratory. None of it is a product claim.

L-01Active

AI agent security

Where an autonomous agent's tool-calling meets a real internal system. We study how prompt context, tool schemas and trust assumptions combine into reachable attack paths.

  • Agents
  • Tool invocation
  • Trust boundaries
L-02Ongoing

Browser & sandbox research

Renderer isolation, IPC surfaces and the assumptions a sandbox makes about the content it contains. Memory-safety and logic bugs at the boundary.

  • Browsers
  • Sandbox escape
  • IPC
L-03Active

Open-source research

White-box review of widely deployed dependencies, reading each security fix for the variant it left behind and the callers the patch never reached.

  • Source audit
  • Patch analysis
  • Variants
L-04Ongoing

Cloud attack paths

Identity chains, over-scoped roles and metadata exposure — turning a cloud misconfiguration inventory into the two or three paths that actually reach data.

  • Cloud IAM
  • Metadata
  • Identity
L-05Research in progress

Application logic research

The bugs no scanner models: state machines, multi-step flows and authorization that is correct per-request but wrong in sequence.

  • Business logic
  • Authorization
  • State
L-06Research in progress

Hardware & emerging platforms

Firmware, devices and new consumer platforms where the trust model is still being written and the tooling barely exists yet.

  • Firmware
  • Devices
  • Emerging

Working on the same surface?

If one of these tracks overlaps a system you own or maintain, we would like to hear about it — collaboration and coordinated disclosure both start the same way.