security research · by request
Scoped work on trust infrastructure.
Scoped security research and review for signing, release and verification systems: validate vulnerabilities, define checks and prepare coordinated disclosures.
Services are separate from the semantic LMV toolkit, which remains in private development / pre-release. Engaging on services is not access to the product, and nothing here implies a release date. Capacity is limited; scope stays realistic.
Trust infrastructure review
Security assessment of signing, provenance and authorization infrastructure.
- scopeSigstore / Cosign deployments · SLSA implementation review · CI/CD signing flow assessment · wallet and agent security review
- outputwritten findings with reproduction where possible
- disclosureall findings affecting external components go through coordinated disclosure
Architecture advisory
Scoped advisory and integration support for semantic verification in real signing flows.
- examplesinvariant design for your use cases · degraded-mode policy and threshold calibration · verification protocol review, fail-closed against fail-open · integration review and rollout guardrails
- shapekept small: defined scope, written handoff, reproducible artifacts where possible
- protocolsthe four brakes are the frame for this work — read them first
How the research is done
A vulnerability research workflow for trust infrastructure. Used in this research practice; not offered here as a public software release.
capabilities
- Automated hunting pipelinestatic analysis + semantic patterns
- Candidate validationonline checks
- Proof generationsubmission workflows
- Disclosure trackingcoordinated
focus areas
- Signature verification bypasses
- Boundary handling errors
- Authorization gaps
- Resource exhaustion risks
This workflow is used in the research practice and is separate from the private/pre-release semantic LMV implementation. The research record documents public outcomes, not a validation of the workflow itself.
Engagement model
- Initial conversation to understand needs.
- Scoping and proposal.
- Engagement with defined deliverables.
- Delivery and written handoff.
Pricing: scoped per engagement. Coordination: async-first and written; an intro call only if it is useful.
Include your system or stack, the point where a check is needed, and the risk or question to investigate. Do not send secrets, private keys or sensitive production data. The first discussion establishes applicability and scope; product access is separate.