Help open up security AI_
Security research and engineering. New York-based, remote-friendly.
Written first.
Specs, decisions and post-mortems live in the repository. If it isn't written down, it didn't happen.
Remote-friendly, New York-based.
We work across time zones and meet in New York when it helps.
Ship, then say so.
What lands gets a changelog entry. Nothing on the site should claim to exist before it does.
We run it on real code.
Everyone runs the product on real work; that is where the roadmap comes from.
Break and fix cryptographic code in the wild, then teach the workflows to find what you found.
ApplyFind soundness bugs in circuits and proof systems, and build the workflows that find them at scale.
ApplyRun the platform against real targets. Validate what it finds. File every miss as a fix.
ApplyAuthor the first EVM workflows and build EVMbench. Find what the audits missed.
ApplyFind bugs in open-source web applications and APIs, disclose them, and turn the patterns into workflows.
ApplyBuild the bench: datasets, contamination checks, scoring, statistics, disputes.
ApplyRun the experiments that decide how workflows and profiles are built.
ApplyAuthor registry workflows across stacks, build part of the bench, publish what you find.
ApplyOwn the run pipeline: sandboxes, the mirror, credits and billing, the API — and build the CLI.
ApplyTurn research into writing people read, and be the voice of the registry as it opens.
ApplyEvery role publishes. Every role runs the product on real code.
Send a note and something you built or found.
Two conversations, one of them technical.
A paid, scoped project on a real problem, then a decision.