Research is where we publish what our own engagement records actually say — grounded in what we find, not in what is easy to write. Two kinds of thing live here.

Findings research

Articles built on our own data: every finding we have recorded since our platform went live, counted. Nobody else can publish these, because they come from our engagement records rather than from a survey or a threat feed. They carry a date because they describe a dataset as of that date.

  • What 890 security engagements actually find
    \n6,643 findings, counted. What penetration testing actually turns up, why the findings that fill a report and the findings that endanger a business are almost different sets, and why authorization is the class no tool will hand you.
  • \n

  • We checked 1,237 fixes. One in four was not fixed.
    Our clients sent 1,237 fixes back to us for verification and 307 failed. Only 42% are right the first time we look. Why security fixes fail — addressing the proof rather than the flaw, and recording mitigated as fixed — and why neither is visible without a retest.

Reference pages

The definitive version of something we are asked about constantly — one page per subject, maintained rather than dated. There will never be many. A page earns a place here only if it is the best account of that one thing we can produce, and if we have the engagement evidence to back it.

  • Broken Authorization: Why It Is the Finding That Matters Most
    The largest class of serious finding we report — and 55% of them are high or critical, against 16% of findings generally. What the class actually contains, why no scanner will hand you one, how we hunt them, and the one way an authorization fix usually fails.
  • Prompt Injection: What We Find, and What Actually Stops It
    What prompt injection looks like in production systems we have tested, ordered by how often we find each thing — agents given capabilities instead of menus, authorization enforced on the user but not the agent, models that can fetch a URL — with the controls that do not work stated as plainly as the ones that do.

In progress

  • Supply chain. Dependencies, build pipelines, editor extensions and AI tool plugins — the routes into an organisation that do not touch its perimeter.

For everything else there is the blog, where the shorter dated write-ups live.

\n\n