[ Research ]
The record, and what we can say about it.
RootXLabs runs its own agents against real production software. This page is the honest state of that work: the numbers are verifiable today, the details are not — most of these findings are still under coordinated disclosure.
Findings acknowledged by
- Apple
- Meta
- Microsoft
- Cisco
- Perplexity
- Dell
- NASA
Acknowledgement means the vendor independently reproduced the finding and credited it. It is the weakest claim we can make that is still worth anything — and unlike a severity rating, it is not ours to award.
Why there is no list of findings here
Because most of them are not fixed yet. Naming a vendor alongside a product and a bug class is a disclosure whether or not a CVE ID is attached to it — anyone reading that pairing knows where to look, and the systems they would be looking at are still running the vulnerable version.
So this page carries counts and vendor names and nothing that maps one to the other. It is a weaker page than it could be. It is also the only version of this page we can publish without handing someone a starting point.
If you are evaluating us and need more than a number, we will walk through the work under NDA — security@rootxlabs.ai.
How we disclose
- The vendor hears first
- Every finding goes to the vendor's security channel before it goes anywhere else — no pre-announcement, no teaser, no conference abstract that names the product.
- The vendor sets the clock
- We do not publish a fixed 90-day countdown. Complex fixes take longer than simple ones, and a deadline that forces a rushed patch helps nobody. We ask for a date and we hold to it.
- Nothing that helps an attacker reach an unfixed system
- Between report and fix we will confirm a finding exists if asked directly, and say nothing more. That includes the product name, the version range and the bug class.
- The write-up comes after the fix
- Once a fix ships and the vendor is ready, the full analysis is published — the path we took, what the guard missed, and the proof-of-concept.
The full policy, including how to report something to us, is on /responsible-disclosure.
What we can show you: the method
The findings are embargoed. The way they were produced is not, and it is the part that generalises anyway.
- A finding without a proof-of-concept is a guessThe failure mode of AI-assisted security work is not missing bugs. It is producing confident, well-written reports for bugs that were never there.Read it
- Prove the scanner fires before you trust a clean resultA tool that reports nothing and a tool that is silently broken produce identical output. The only way to tell them apart is to plant something it must find.Read it