Home / Research
What we publish
Research
Research is where we publish what our own engagement records actually say — grounded in what we find, not in what is easy to write. Two kinds of thing live here.
Findings research
Articles built on our own data: every finding we have recorded since our platform went live, counted. Nobody else can publish these, because they come from our engagement records rather than from a survey or a threat feed. They carry a date because they describe a dataset as of that date.
- What 890 security engagements actually find
6,643 findings, counted. What penetration testing actually turns up, why the findings that fill a report and the findings that endanger a business are almost different sets, and why authorization is the class no tool will hand you. - We checked 1,237 fixes. One in four was not fixed.
Our clients sent 1,237 fixes back to us for verification and 307 failed. Only 42% are right the first time we look. Why security fixes fail — addressing the proof rather than the flaw, and recording mitigated as fixed — and why neither is visible without a retest.
Reference pages
The definitive version of something we are asked about constantly — one page per subject, maintained rather than dated. There will never be many. A page earns a place here only if it is the best account of that one thing we can produce, and if we have the engagement evidence to back it.
- Broken Authorization: Why It Is the Finding That Matters Most
The largest class of serious finding we report — and 55% of them are high or critical, against 16% of findings generally. What the class actually contains, why no scanner will hand you one, how we hunt them, and the one way an authorization fix usually fails. - Prompt Injection: What We Find, and What Actually Stops It
What prompt injection looks like in production systems we have tested, ordered by how often we find each thing — agents given capabilities instead of menus, authorization enforced on the user but not the agent, models that can fetch a URL — with the controls that do not work stated as plainly as the ones that do.
In progress
- Supply chain. Dependencies, build pipelines, editor extensions and AI tool plugins — the routes into an organisation that do not touch its perimeter.
For the full catalogue of what we test — 276 named tests in 46 categories across web, Android, iOS, IoT and AI systems, each stating what it proves, how it is carried out and what has to be in place beforehand — see Attacks & Tests. For everything else there is the blog, where the shorter dated write-ups live.
Tell us what the system does and what worries you.
If a penetration test is not what you need yet, we will say so.