Offer
Not a scan report — a proof.
A source-code security audit and vulnerability research engagement. We find attacker-reachable issues, ship a working patch, and leave you a reproducer plus a sealed oracle — an automated check that fails before the fix and passes after. If we cannot reproduce it, we do not report it.
- Scope
- Language is part of the scope, not a catalog. AI-assisted adversarial review — trust boundaries, complexity (including CWE-407), memory, and previously unknown issues. Patch included.
- Delivered
- Deterministic reproducer, passing-or-failing oracle, behavior-preserving patch, and the re-measured gate. You can run the artifacts yourself.
- Shape
- Fixed-scope engagement. Limited seats. US studio, US support.
A named public receipt
Most findings stay anonymized. One public advisory is listed under its own URL so researchers can cite it without scrolling a marketing page.
Python-Markdown — quadratic default-path parse →