Scanners forget.Vulzero remembers.
A research environment for human security researchers and bounded AI assistants — organizational memory, evidence provenance, and human approval enforced as a security boundary rather than a stated intention.
A research environment, not a scanner.
The differentiator is not maximum automated coverage. It is a system that reasons over authorized context, remembers what it learned, and can prove every step.
Organizational memory
Every engagement, observation and decision is retained and searchable. Institutional knowledge stops walking out the door.
Knowledge graph
Hosts, services, findings and evidence linked as a graph the research companion can actually reason over.
Evidence & provenance
Each artefact is hashed and chained. A conclusion you cannot trace back to evidence is not a conclusion here.
Scope enforcement
Targets in or out of scope are checked by the system on every action, not promised in a kickoff call.
Bounded AI assistants
The companion can describe, question and recommend — never act. Consequential steps wait for a human.
Mission control
One dashboard for engagements, agent runs, research notes, evidence and an audit log with an intact hash chain.
Boundaries you can count.
Actions checked against scope
Egress point for every model call
Fabricated findings tolerated
Retained versions per document
Ten capabilities, one environment.
Engagement & scope management
Each engagement defines its own target, scope, rules, restrictions, time window and required approvals.
Human research workspace
Where researchers investigate, take notes, and record observations against authorized context.
Observation & reasoning assistants
Read-only companions that describe, question and recommend over authorized context only.
Evidence & provenance
Artefacts hashed on capture, chained, and never presented as verified until they are.
Reporting & remediation
Professional reports with findings that trace to evidence, plus remediation tracking.
Secure tool integration
Tools reach the platform through one gateway, the single audited egress point.
Engagement to report, in order.
Each step gates the next. Nothing downstream proceeds until its predecessor holds.
- 01
Authorize
An engagement defines target, scope, rules and the approvals required before any work begins.
- 02
Scope
Every target is checked against that scope — in or out — and the check is logged, allowed or denied.
- 03
Research
Humans investigate; bounded assistants reason over authorized context and surface what to look at next.
- 04
Evidence
Findings are backed by hashed, chained artefacts. Observation, hypothesis and conclusion stay separate.
- 05
Report
A professional report is produced, every conclusion traceable to the evidence behind it.
“Authorization and human approval are enforced security boundaries — not stated intentions.”VULZEROOperating principle
Research in the open.
Methodology, disclosures and tooling — argued and shared where researchers actually gather.
GitHub org
The tools we can open-source, the harnesses, and the issue tracker for public research.
Join PublicDisclosure feed
Every published finding and write-up, syndicated. Follow the research as it clears verification.
Join 1.2k membersResearch Discord
Open channels for methodology, disclosure etiquette, and tooling — where researchers actually talk.
Join Low volumeMailing list
Occasional long-form notes and coordinated-disclosure advisories, straight to your inbox.
JoinSee it against your own scope.
Bring one engagement and a real scope. We will show you the environment reasoning over authorized context — and refusing everything outside it.