Cipher · An AI security engineer

Security review at development speed. Without losing depth.

Cipher finds real risk, proves it's exploitable, and hands you the fix. Continuous, autonomous review at machine speed, with human judgment where it matters.

Cipher Platform · review preview Reviewing
Inputs
{} Source 312
~ Cloud 48
# IaC 28
/ APIs 17
@ IAM 61
Docs 24
Δ PRs 14
History 91
Living security graph
Phase 04 · Evidence · 1 critical reproduced
Evidence
Critical CPHR-EXP-04821
Authenticated admin escalation via signed webhook replay
Path s3:vendor-feedapi-gatewaypayments-svc prod
Repro cap-3c4a71 · 14:22:08 · sbx-a19f
High CPHR-EXP-04816
PHI leak through debug flag following request context
Path auth-svclog-pipelinevendor-export prod
Repro cap-3c4b09 · 14:23:51 · sbx-a19f
+ 3 validated · 12 hypotheses triaged
Built by operators & AI researchers

As attackers, defenders, and AI researchers, we know what matters, what's noise, and how to prove it.

i
Led security at
AWS
Coinbase
ii
Top researcher at
Cobalt
Independent pentest research.
iii
Senior AI researchers at
LinkedIn SentinelOne
Applied ML at scale & AI-driven threat detection.
iv
Disclosed at 100+ high-value targets
Apple
Google
Microsoft
PayPal
United Airlines
Yahoo
Bitfinex
Mbed TLS
Netherlands
Among the internet's most-attacked surfaces.

advisories

We found these in software the world already runs.

Reported upstream and fixed, each with its public advisory. A selection is below; the full ledger runs longer.

See all advisories →
100M+ lines evaluated across production estates and open source
0 false positives every finding ships with a working repro
675+ exploitable vulnerabilities proven by execution, not pattern matching
Sector reach

We go where the blast radius is largest.

One engine, pointed at the systems where a single exploited path becomes a headline. Where the work is public, the plate names it.

Cloud & Data Infrastructure
RCE → CVE

Cloud & Data Infrastructure

Operators, control planes, multi-tenant data stores.

Telecom & 5G
CVE · fixed upstream

Telecom & 5G

Core network, packet handling, signaling paths.

Fintech & Payments
Takeover chain proven

Fintech & Payments

Auth chains, ledgers, money-movement flows.

Aerospace & Space
CVE · fixed upstream

Aerospace & Space

Flight software and ground-segment systems.

Energy & Critical Infra

Energy & Critical Infra

Grid control, ICS, and OT protocols.

Crypto & Web3
Exposure proven

Crypto & Web3

Wallets, mints, and on-chain settlement logic.

Six sectors shown. Every finding we can name is in the ledger. See the disclosure ledger →
Why now

Engineering moves at machine speed. Security reviews don't.

The gap is widening every week.

AI-assisted development changed software velocity. Teams ship more code, more surfaces, more often. Most of it is business logic that scanners can't reason about.

Traditional security still runs on a quarterly cadence:

  • Scannersgenerate noise.
  • Pentestsgenerate reports.
  • Teamsgenerate triage queues.

Real breaches come from multi-step logic that pattern matching can't see. Cipher reviews every change, continuously, at machine speed, with an attacker's depth.

read the reasoning-gap argument in full →
The familiar gap

Code compounds. Review capacity stays flat.

AI copilots multiply your team's commits. The AppSec team doesn't scale with them, and shouldn't have to.

Engineering headcount doubled this year. AppSec did not.
The pattern across customer interviews
The hidden cost

Most real risk is multi-step, and most scanners don't reason.

Business-logic flaws, auth-chain weaknesses, and vendor-path compromises are where real breaches come from. Pattern matching doesn't see them.

The SAST stack was green. The bug that mattered was a four-step logic flaw between two services.
The pattern across customer interviews
How Cipher works

Context, first. Then reasoning. Then proof. Then fix.

Six steps, run continuously. Each loop feeds the next. Every engagement makes the next review smarter about your system.

01 · Build context

Read the whole system.

Code, cloud, APIs, docs, tickets, and tribal knowledge, built into a living security graph.

in · sourceout · graph
02 · Reason

Map attack paths.

Trust boundaries, privilege transitions, multi-step abuse flows. Prioritized hypotheses, not a list of lints.

in · graphout · threat model
03 · Plan

Plan, then adapt.

Open with a plan, then run the loop: execute, learn from the environment, revise. Evidence sharpens it.

in · hypothesesout · living plan
04 · Validate

Actually execute.

Code-aware inspection and authenticated runtime checks against the real system. Only exploitable findings pass.

in · planout · validated exploit
05 · Remediate

Evidence + fix, together.

Attack-path context, reproduction steps, and a remediation diff. Audit-ready from the start.

in · proofout · fix
06 · Learn

Every review, smarter.

Findings and fixes write back to the graph. Every run picks up where the last left off, and compounds.

in · all of itout · memory
Cipher Baseline

Know where you'd stand if the best attackers came at your stack.

A one-time, end-to-end assessment of your hardest environment. Autonomous, and led by our experts, reasoning the way the best do: adversarially and architecturally. No platform to onboard. Define the scope, agree a flat price, and get back validated, exploitable findings, each one proven.

01 Define scope The environment and objectives that matter to you.
02 Flat price A fixed price, agreed before anything runs.
03 End-to-end run The whole environment, worked end to end the way an adversary would.
04 Exploit-proven Validated findings, each reproduced, with the fix.

A Baseline is one run, complete in itself. Keep Cipher pointed at your stack and the same engine compounds into a continuously improving brain.

Field reports

Findings from the field, names removed.

A sample from Cipher’s engagement log. Every identifier is redacted; nothing else is changed. Most cleared the scanners and pentests already in place.

  • Cipher Field Report · CPHR-FR-13 2026-06-22 · Confidential
    Reading infra and app as one system

    An internal money endpoint, open to the internet.

    1. Cipher models the end-to-end request flow, gateway to wallet ledger.
    2. A privileged credit route is published on the public gateway.
    3. The same route is missing from the gateway’s auth plugin, forwarded unauthenticated.
    4. An empty-body probe proves the backend is reachable and reveals a weak token.
    5. An anonymous credit lands as spendable wallet balance, then reverted. Repeatable, uncapped.
    Read the full field report →
  • Cipher Field Report · CPHR-FR-04 2026-03-12 · Confidential
    What Cipher paused its own run for

    A six-year compromise, wired into production.

    1. Cipher reverses the codebase and maps the live system.
    2. During testing, unauthenticated endpoints surface on the primary service.
    3. Data traces to an externally-hosted S3 bucket.
    4. Bucket is open. Records match live production data, including PII.
    5. Cipher pauses, alerts security leadership out-of-band. Authorized to continue.
    6. Investigation enters the vendor environment. Web shells across vendor paths, one wired into the customer’s production workflow. Admin escalation, auth bypasses, and HMAC signing keys in minified JS followed.
  • Cipher Field Report · CPHR-FR-11 2026-05-08 · Confidential
    Five mediums, read together

    One auth flaw to full payout control.

    1. An auth filter treats any path containing /admin as public.
    2. An unauthenticated admin route mints credentials for any tenant named.
    3. Impersonate any tenant: full horizontal auth bypass.
    4. Hijack signed payment webhooks and steal the HMAC signing secret.
    5. Outbound delivery becomes an SSRF confused deputy into the internal network (CVSS 10.0 chained).
    6. Book a transaction in another tenant’s ledger: direct money movement.
    Read the full field report →
Human + AI

Autonomous, or approval-gated. You set the mode.

Cipher runs in two modes. Let it run end-to-end, every action logged. Or gate sensitive actions behind a reviewer sign-off. You set the policy. Cipher enforces it.

Cipher · planner15:42:07
Mapped an attack path from s3://vendor-feed through the API gateway into payments-svc. Hypothesis CPHR-EXP-04821. To validate exploitability, I need a single replay request that writes to a live payments record.
Cipher · planner15:42:09
This is a tier-2 action. Approve below to continue, or request details.
Approval requested · tier-2CPHR-PLAN-11932
Issue webhook-replay · live payments-svc
Risk · writes to one live payments record · single request
Scopescoped service-account · one write · no schema change Rollbackstate captured · auto-revert on exit Kill-switch<100 ms · any reviewer
Trust & governance

Enterprise-grade from day one.

Your code trains nothing. Governance on every path that touches production. Every action logged, every connector scoped, and nothing writes to your systems outside the policy you set.

Your code

Trains nothing.

Source, configs, and findings never train a model, ours or a provider's. No exceptions.

Your source

Stays ephemeral.

A sealed, single-tenant sandbox, destroyed when the review ends. Only the graph persists: architecture and findings.

Your boundary

Your environment.

Need Cipher in your own cloud, VPC, or air-gapped environment? Talk to us. Residency requirements welcome.

SSO + lifecycle.

Enterprise SSO, SCIM deprovisioning, session policy. Federated identity in; leaver lockout automatic.

RBAC + scoped access.

Fine-grained roles for reviewers, auditors, approvers. Every connector and action scoped.

Full audit trail.

Every identity, access, connector, review, and approval: attributed, timestamped, SIEM-ready.

Connector control.

Read-only by default. Write scopes explicit and approvals-gated. No standing credentials. See what Cipher connects to.

Secrets at rest.

Credentials and network profiles encrypted with AES-256-GCM and envelope KMS. Never plaintext.

Hard-stop kill-switch.

Any reviewer, any time, halts any running Cipher task in under 100 ms. Out-of-band confirmation.

Compliance posture SOC 2 Type II · in progress ISO 27001 · in progress HIPAA GDPR

Specific compliance, residency, or deployment requirements? Let's talk.

Who's behind Cipher

The people who break it, build it.

Offense, defense, operations, and applied AI. A small senior team, with no sales layer between you and the people doing the work.

Shubham Raj The Hacker

Shubham Raj

Co-founder · offense

Leads the company hands-on: the research behind our CVEs, the architecture behind Cipher.

LinkedIn
Mredul Sarda The Operator

Mredul Sarda

Co-founder · GTM & operations

Runs go-to-market and operations: partnerships, customers, and every engagement from scope to delivery.

LinkedIn
+3 Identity protected
  • The ResearcherAI research
  • The BuilderEngineering
  • The DefenderField security
Meet the full team →
The ask

One repo. One target. One unattended review. Exploitable findings.

No slides, no sales pitch. You talk to a researcher who does this work. Point us at a system you own, even your hardest environment, and we hand back validated, exploitable findings, each one proven. If there's nothing worth your time, you'll know that too. Either way, you know where you stand.