We built the environment we wanted to research in.
VULZERO exists because security knowledge kept evaporating between engagements — and because "the AI did it" is not an acceptable answer when a boundary is crossed.
Security knowledge is perishable. It lives in one researcher’s head, in a scratch file, in a chat thread — and then that person moves on and the organization relearns what it already knew. VULZERO started as a refusal to accept that.
The premise
An authorized research environment should remember, reason, verify and learn. Not scan harder — remember better. Every engagement, observation and decision is retained, linked into a knowledge graph, and backed by evidence that can be traced.
The boundary
The second refusal is just as important: "the AI did it" is not an acceptable answer when a boundary is crossed. So authorization and human approval are enforced by the system, not promised in a kickoff call. Assistants reason; humans decide.
We built the environment we wanted to research in — and then made its boundaries impossible to quietly ignore.
The people accountable for the boundary.
Mohamed Ali
Founder & Principal Researcher
Sets the authorization model and owns the boundary between what the platform may observe and what it may do.
Research Lead
Lead Security Researcher
Runs engagements end to end, from scope definition through evidence to the final report.
Platform Engineer
Platform & Gateway
Keeps the model gateway the single egress point, and the audit chain intact.
Work with us.
We take on a small number of engagements at a time. If the way we work fits how you need to be tested, start a conversation.