About

We built the environment we wanted to research in.

VULZERO exists because security knowledge kept evaporating between engagements — and because "the AI did it" is not an acceptable answer when a boundary is crossed.

Security knowledge is perishable. It lives in one researcher’s head, in a scratch file, in a chat thread — and then that person moves on and the organization relearns what it already knew. VULZERO started as a refusal to accept that.

The premise

An authorized research environment should remember, reason, verify and learn. Not scan harder — remember better. Every engagement, observation and decision is retained, linked into a knowledge graph, and backed by evidence that can be traced.

The boundary

The second refusal is just as important: "the AI did it" is not an acceptable answer when a boundary is crossed. So authorization and human approval are enforced by the system, not promised in a kickoff call. Assistants reason; humans decide.

We built the environment we wanted to research in — and then made its boundaries impossible to quietly ignore.
A scope map under authorization — every target checked, every verdict logged.
Who

The people accountable for the boundary.

Mohamed Ali

Founder & Principal Researcher

Sets the authorization model and owns the boundary between what the platform may observe and what it may do.

Research Lead

Lead Security Researcher

Runs engagements end to end, from scope definition through evidence to the final report.

Platform Engineer

Platform & Gateway

Keeps the model gateway the single egress point, and the audit chain intact.

Work with us.

We take on a small number of engagements at a time. If the way we work fits how you need to be tested, start a conversation.