Skip to content
Services
How it works Scope & safety Findings Review desk Blog Write to us
HomeServicesOur approach
Our approach

Autonomy in research.
Accountability in delivery.

Our AI agent model supports the investigation. Our researchers own the final technical validation, impact judgment and approval of what we deliver.

INSIDE THE ASSESSMENT
Research moves. People decide.Scoped research produces evidence. Human technical review precedes delivery to the customer.Agreed scopeDefine the boundariesAI investigationCollect supporting evidenceHuman reviewValidate and approveDeliveryExplain findings and limitsAPPROVAL GATE
Research moves. People decide.
ResearchHuman validationDelivery
01 / Who does what

A defined scope.
A traceable handoff.

ContextScopeAccessBEFORE INVESTIGATION
DEFINE

Agree what the work
is meant to answer.

Customer context determines which systems and workflows belong in the engagement.

Customer input
Assets, architecture, relevant roles, intended behavior and operational constraints.
Team responsibility
Confirm technical fit, authorization, exclusions and the proposed deliverables.
Checkpoint
Testing begins only within the access and actions agreed for the engagement.
QuestionResearchEvidenceDURING INVESTIGATION
INVESTIGATE

Explore hypotheses.
Collect observations.

Our AI agent model supports research across the authorized workflows.

Research input
Scoped accounts, environments and designated test resources.
Research focus
Understand behavior and compare observations against the intended boundary.
Checkpoint
Unknowns and testing limitations remain explicit rather than becoming unsupported conclusions.
EvidenceReviewDeliveryBEFORE CUSTOMER HANDOFF
VALIDATE

People approve
what reaches your team.

Our researchers own final technical validation, impact judgment and delivery approval.

Review input
The mechanism, reproduction context and supporting evidence.
Team responsibility
Evaluate what was established, what remains uncertain and how impact should be described.
Checkpoint
The delivered report communicates reviewed findings, limitations and remediation guidance.
02 / Interpreting observations

Different evidence.
Different conclusions.

How assessment evidence is communicated
Evidence stateWhat it meansHow it is communicated
Supported findingWhat it meansThe reviewed evidence supports a specific mechanism and observed result.How it is communicatedAffected scope, preconditions, impact and relevant limitations are explained.
Open questionWhat it meansThe available observations do not establish the proposed conclusion.How it is communicatedUncertainty is identified; it is not converted into a confirmed finding.
Testing limitationWhat it meansAccess, environment or operational constraints prevented a particular check.How it is communicatedThe report identifies the coverage gap rather than implying a clean result.
Simulated conditionWhat it meansA controlled test uses constructed or adjusted conditions.How it is communicatedThe constructed conditions and the boundaries of the resulting claim are stated.
03 / Controlled research resources

Resources extend the research.
Scope still sets the limits.

Designated infrastructure supports approved workflows. Capability does not replace authorization.

  1. 01

    Domains & servers

    Assigned DNS records on our domains and designated test servers support controlled scenarios.

    OWNED RESOURCES
  2. 02

    Test identities

    Dedicated email accounts support registration, verification and sign-in in agreed workflows.

    DESIGNATED ACCOUNTS
  3. 03

    Web3 wallets

    Assigned wallets with small balances support approved transactions within defined environments and limits.

    EXPLICIT TRANSACTION SCOPE

Physical-device testing is in development and is not a current service. Research resources are not unrestricted access to customer systems.

04 / What you receive

An accountable handoff.
A useful engineering conversation.

A human approval gate matters only if the final output helps the customer understand and act on the evidence.

Explore assessment deliverables ↗
ILLUSTRATIVE STRUCTURE · NOT A CUSTOMER REPORT
ENGAGEMENT OUTPUT

Context. Evidence.
A useful next step.

01

Scope record

What was included, excluded and constrained by available access.

02

Reviewed findings

Mechanism, preconditions and the observations supporting the conclusion.

03

Impact judgment

Demonstrated consequences separated from uncertainty and assumptions.

04

Follow-up context

Remediation guidance and retest terms where agreed.

05 / Before we start

Practical questions.
Clear expectations.

Bring your technical constraints and buyer requirements to the scoping conversation.

What does the AI agent model do?

It supports investigation and evidence collection within the agreed scope, including designated authenticated workflows and test infrastructure. This is not a claim that the service is an unreviewed autonomous scanner.

What does your team do?

Our researchers own final technical validation, impact judgment and approval of the material delivered to the customer.

Can a test result be inconclusive?

Yes. Inconclusive observations and untestable areas should be identified. They are not proof that an issue exists or that a system is secure.

Do you perform disruptive testing?

Disruptive actions are not assumed to be in scope. Any such requirement needs an explicit discussion of authorization, operational impact and whether the engagement can support it.

Does this process guarantee every vulnerability will be found?

No. Every assessment is limited by agreed scope, access, environment and time. Methodology describes how the work is approached, not a guarantee of completeness.

LET’S DEFINE YOUR ENGAGEMENT

Bring us your scope.
We’ll discuss the next step.

Share your system, priorities and target date.
Please do not include credentials or sensitive findings.