We help secure the world’s most targeted organizations and products. We combine security research with an attacker mentality to reduce risk and fortify code.
We shipped post-quantum crypto to Python, watched GPT-5.5-Cyber build a zlib fuzzing lab in a day, and shared our /goal playbook for finding real bugs. Plus 9 new public reviews, mutation testing for DAML, and more. July Tribune:
We're a day-one auditor for @signalapp's new Automatic Key Verification, which depends on external auditors to confirm everyone sees the same keys.
We built our auditing software from scratch, open-sourced it, and run it as a public good.
"Until I came across Dan’s talk, we didn’t have a structured process."
@timoreilly invited our CEO @dguido to explain what it takes to make a company AI-native.
@WorkOS built an internal AI pipeline that hunts for deep logic bugs, ran 1,000+ scans with it, and surfaced multiple high-severity issues. They used our public code auditing skills as a foundation.