Skip to main content
2 TO 8 WEEKS

Security Research

Original research into how things actually break

Research work goes deeper than assessment against a known checklist. It targets a specific piece of software, protocol, or technology and asks how it can be made to fail, using source review, reverse engineering, and fuzzing. Anything found is documented to a standard that survives scrutiny, with a working proof of concept and a disclosure process handled properly.

When you need this

  • You build a product and want it examined properly before someone else does
  • You need a proof of concept to demonstrate that a reported issue is real
  • You want independent research into a technology your business depends on
  • You need a vulnerability documented well enough to disclose responsibly

What is included

Vulnerability research

Deep examination of a target through source review, reverse engineering, and fuzzing.

Proof-of-concept development

Working demonstration code that proves the issue is real and exploitable.

Root cause analysis

Explanation of the underlying flaw, not just the symptom, so the fix addresses the real problem.

Coordinated disclosure

Responsible disclosure handled with the vendor, including CVE assignment where applicable.

Technical write-up

Publication-quality documentation of the finding and its impact.

How the engagement runs

01

Target selection

Agree the target, the research questions, and the disclosure policy up front.

02

Analysis

Source review, reverse engineering, and fuzzing to surface candidate issues.

03

Validation

Development of a reliable proof of concept and assessment of real impact.

04

Disclosure

Coordinated vendor disclosure and publication on an agreed timeline.

What you receive

  • Research report with full technical detail
  • Working proof-of-concept code
  • Root cause analysis and suggested fix
  • Coordinated disclosure handling and CVE request
  • Public technical write-up, on your timeline

Tooling

IDA ProGhidrax64dbgAFL++libFuzzerCustom tooling

Common questions

Do you follow responsible disclosure?

Yes. Vendors are contacted privately first and given reasonable time to remediate before anything is published, with the exact timeline agreed at the start of the engagement. If you are commissioning research into your own product, you control the disclosure timeline entirely.

Who owns the findings?

For commissioned research into your own product, you do. Publication happens only with your agreement and on your schedule. Credit and CVE attribution are agreed in advance so there are no surprises on either side.

Discuss a security research engagement

Scoping conversations are free and produce a fixed quote before any work begins.

Get in touch

Other services