Capabilities
Everything traces back to evidence.
Offensive research, delivered inside an environment that remembers the work and can prove each step. Explore the capabilities that make that possible.
Offerings
How we engage.
Application & API assessment
Authorized testing of web and API surfaces, scoped per engagement, evidenced throughout.
Attack-surface mapping
External surface discovery and analysis, mapped into the knowledge graph rather than a flat report.
Cloud & infrastructure review
Configuration and privilege review against least-privilege, with findings tied to concrete artefacts.
Continuous research retainer
An ongoing engagement where organizational memory compounds instead of resetting each cycle.
Engagement tiers
Scoped to the work.
Assessment
Fixed scopeA single bounded engagement with a defined target and window.
- One engagement, one scope
- Evidence-backed report
- Remediation guidance
Programme
RecurringA standing research programme where memory and graph compound over time.
- Multiple engagements
- Persistent knowledge graph
- Mission Control access
- Remediation tracking
Embedded
CustomThe platform and researchers embedded alongside your security team.
- Everything in Programme
- Custom authorization profiles
- On-prem model gateway option
Questions
Before you ask.
Does the AI act on systems?
No. Assistants are read-only: they describe, question and recommend over authorized context. Every consequential action waits for explicit human approval.
How is scope enforced?
Every target is checked by the scope engine on each action and the result — allowed or denied — is written to the audit log. It is a boundary the system enforces, not a policy the operator promises.
What happens to model credentials?
They are encrypted at rest and write-only: the dashboard shows only whether a slot is filled and its last four characters. All model calls leave through a single audited gateway.
Can it run without sending data to a third party?
Yes. A fully local model provider is supported, in which case nothing leaves the machine. Human-only research is also a first-class mode.