// ORIGINAL FINDINGS
Vulnerability Research
Our team runs independent research alongside client engagements, disclosed responsibly to affected vendors before anything is published.
How we handle disclosure
When our research team identifies a vulnerability outside a client engagement, we follow a standard responsible disclosure process: private notification to the vendor, a reasonable remediation window, and public write-up only after a fix is available or the window has lapsed.
We don't publish exploit code for unpatched vulnerabilities. Research write-ups focus on the underlying pattern so defenders can check for it, not on weaponizing the specific finding.
What we research
Current focus areas include API authorization patterns in SaaS platforms, cloud IAM misconfigurations, and supply-chain risk in common CI/CD tooling  areas where we're seeing the same classes of issues recur across unrelated client engagements.
// STAY AHEAD
Want research findings applied to your systems?
This page covers general patterns. An assessment covers what's true for your environment specifically.