[ Research ]

The record, and what we can say about it.

RootXLabs runs its own agents against real production software. This page is the honest state of that work: the numbers are verifiable today, the details are not — most of these findings are still under coordinated disclosure.

3
CVEs assigned
8
Vendors acknowledged
#700
Bugcrowd global rank
2022
Hunting since

Findings acknowledged by

  • Google
  • Apple
  • Meta
  • Microsoft
  • Cisco
  • Perplexity
  • Dell
  • NASA

Acknowledgement means the vendor independently reproduced the finding and credited it. It is the weakest claim we can make that is still worth anything — and unlike a severity rating, it is not ours to award.

Why there is no list of findings here

Because most of them are not fixed yet. Naming a vendor alongside a product and a bug class is a disclosure whether or not a CVE ID is attached to it — anyone reading that pairing knows where to look, and the systems they would be looking at are still running the vulnerable version.

So this page carries counts and vendor names and nothing that maps one to the other. It is a weaker page than it could be. It is also the only version of this page we can publish without handing someone a starting point.

If you are evaluating us and need more than a number, we will walk through the work under NDA — security@rootxlabs.ai.

How we disclose

The vendor hears first
Every finding goes to the vendor's security channel before it goes anywhere else — no pre-announcement, no teaser, no conference abstract that names the product.
The vendor sets the clock
We do not publish a fixed 90-day countdown. Complex fixes take longer than simple ones, and a deadline that forces a rushed patch helps nobody. We ask for a date and we hold to it.
Nothing that helps an attacker reach an unfixed system
Between report and fix we will confirm a finding exists if asked directly, and say nothing more. That includes the product name, the version range and the bug class.
The write-up comes after the fix
Once a fix ships and the vendor is ready, the full analysis is published — the path we took, what the guard missed, and the proof-of-concept.

The full policy, including how to report something to us, is on /responsible-disclosure.

What we can show you: the method

The findings are embargoed. The way they were produced is not, and it is the part that generalises anyway.