Permissive licences only
Apache 2.0 or MIT. Fork it, rebrand it, ship it inside your own product. We are not building a funnel disguised as a community edition.
A standing commitment of engineering time, published free and permissively licensed. An agentic bug bounty toolkit, a generator that builds agent skill files from public vulnerability disclosures, and a smart contract security skill library - all public repositories you can clone today.
Consultancies protect whoever can pay. That leaves out almost everybody: the clinic whose receptionist takes the fraudulent call, the school district with one part-time IT contractor, the family business that loses its working capital to a redirected invoice, the pensioner whose son’s voice was cloned.
We do not think those people are somebody else’s problem, and charity is a fragile way to solve it. Tools are not. A detection engine written once and released freely keeps working long after any individual engagement ends, in places we will never hear about. That is the most leverage we have, so we fund it deliberately rather than when there is spare time.
Permissively licensed and self-hostable. No telemetry tax, no gated tier that quietly becomes the product.
Techniques we see get anonymised and published so defenders meet them before they arrive in the inbox.
Offensive tooling is for programmes and assets you are contracted or permitted to test. We say that on every page that needs it.
CLI and agent integrations for developers and researchers who need a gate before production, not a slide deck.
Public repositories anyone can clone today. Each one came out of a problem we hit in our own work and had no reason to keep private.
AI-assisted bug bounty toolkit: recon, hunt, validate and report — CLI, agent plugin and MCP.
Drives the reconnaissance, hunting, validation and reporting loop a bounty hunter would otherwise run by hand. Standalone CLI, Claude Code plugin and MCP server. Use only against programmes you are authorised to test.
Pre-ship security gate that scans vibe-coded apps for secrets, auth flaws and injection before you ship.
A CLI and AI-agent plugin for Claude Code, Cursor and similar tools. It finds leaked secrets, broken auth, IDOR, injection, SSRF, XSS, cloud misconfiguration and AI-agent/LLM risks in code you are about to ship. It is a pre-ship gate, not a full penetration-testing platform.
Generates Claude Code skill files for eighteen vulnerability classes from public disclosures.
Turns published HackerOne reports and GitHub write-ups into working Claude Code skills. Everything it learns from is already public. It is not a scanner and not an MCP server.
Smart-contract security skill library and Foundry PoC templates for agent-assisted review.
Markdown skills for Immunefi-style hunting: bug classes, methodology, Foundry PoC templates and case notes. No product CLI. Use only on authorised scopes.
Apache 2.0 or MIT. Fork it, rebrand it, ship it inside your own product. We are not building a funnel disguised as a community edition.
Nothing phones home. Tools that analyse suspicious messages must be safe to run on the most sensitive thing in your inbox, which means they cannot send it anywhere.
Reserved engineering capacity every sprint. A tool that stops receiving security updates is worse than no tool, so we archive loudly rather than letting things rot quietly.
Feature direction comes from the help desks, community groups and fraud teams who run these day to day, not from what would look good in a sales conversation.
The most valuable contributions we receive are usually not code.
Issues are labelled by difficulty and every repository has a good-first-issue queue. Detection rules, language packs and integrations are the most useful contributions right now.
If you received something clever, send it. Anonymised samples of real lures make the detection corpus better for everyone, and we credit contributors unless asked not to.
Scams are local. Templates, playbooks and warning copy in more languages helps far more people than another detection heuristic.
Use our materials to teach a session at your school, workplace or community centre. Everything is licensed for that and we will help you prepare it.
We keep monthly capacity for schools, clinics, charities and community groups: a session, a review, or help standing up one of these tools. Tell us who you serve and we will find a slot.