An independent offensive-security collective. Founded in 2018, operated by named humans, accountable to the people whose products we break.
This page is the institutional record — founder, team, locations, certifications, and conference history — assembled for the procurement and due-diligence reader who needs to know exactly who is behind the work before signing an engagement letter.
People, Places, Credentials, Output.
Four questions every due-diligence reader asks first. Answered here, on the page, with no marketing varnish.
-
01
People
41 full-time staff as of Q1 2026 — 19 research engineers, 11 red-team operators, 6 disclosure coordinators, 5 platform and operations. The team includes three Pwn2Own winners and former engineers from NSA TAO, Unit 8200, and Google Project Zero. Lead researcher and founder Priya Ramanathan has run the firm since incorporation in Delaware in 2019.
- Founded
- 2018, Zurich
- Incorporated
- 2019, Delaware
- Founder
- Priya Ramanathan
-
02
Places
Headquartered at 1401 East 6th Street, Suite 420, Austin, TX 78702. Research outposts in Tel Aviv, Singapore, and Berlin (Wilmersdorf). All four offices operate under the same ISO/IEC 27001:2022 controls and SOC 2 Type II reporting boundary.
- HQ
- Austin, TX, USA
- Research outposts
- Tel Aviv · Singapore · Berlin
- Time-zone coverage
- ~22 hrs overlap
-
03
Credentials
Certified and audited under ISO/IEC 27001:2022, SOC 2 Type II, and CREST-accredited penetration testing for US, UK, and Singapore operations. Engagement deliverables conform to OWASP ASVS, NIST SP 800-115, and PTES — chosen per engagement scope.
- Certifications
- ISO 27001 · SOC 2 II · CREST
- Awards
- 2024 Cybersecurity Breakthrough — Top 10
- Pwnies
- DEF CON 30, Black Hat USA 2023
-
04
Output
87 CVEs credited across MITRE to date, including 6 critical-severity (CVSS ≥ 9.0) advisories in 2024 alone. 612 discrete penetration tests and 38 multi-quarter red-team engagements delivered. Maintains an in-house 4,200-device fuzzing farm running 9.6 billion execution paths per week across client codebases.
- CVEs
- 87 (6 critical in 2024)
- Engagements
- 612 pentests · 38 red teams
- Patch turnaround
- 11-day median (vs. 74-day industry)
A short note from the desk that started the firm.
I started ExploitStation in 2018 because the offensive-security market had drifted toward vendor theater: glossy reports, shallow findings, and very little of the actual work. The buyers I spoke with — CISOs, AppSec leads, the occasional general counsel — were paying for evidence and receiving PowerPoint.
We built this firm to be the opposite. Every researcher here has shipped a CVE they can name. Every red-team operator has worked a multi-quarter engagement where the goal was to break something specific and write up exactly how it broke. We refuse work that would have us rubber-stamp a checkbox; we refuse to publish a 0-day outside the agreed disclosure window; and we refuse to call ourselves "unbreakable" or to claim we can prevent the next zero-day — because the next zero-day is the entire reason our discipline exists.
What we will do is tell you, on the page and in person, how your products break. We will hand you a reproducible proof-of-concept, a timeline, and a defense. Our median client tenure is 2.7 years because the people who hire us once tend to hire us again — and we are accountable to that trust.
If that is the kind of partner you are looking for, the operators below are who you would actually be working with.
Conference appearances, publicly verifiable.
A chronological record of talks delivered by ExploitStation researchers at peer-reviewed offensive-security conferences. Talks are cross-referenceable against public conference archives.
-
2024 · Q3
Black Hat USA — "Living Off the Kernel: Post-Exploitation in 2024"
-
2024 · Q2
DEF CON 32 — "Fuzzing at 4,200 Devices: Lessons from a Year of Continuous Exploitation"
-
2024 · Q1
OffensiveCon — "When the Sandbox Opens: Escaping Modern Container Runtimes"
-
2024 · Q1
Nullcon — "Disclosure at Scale: Coordinating 47 Zero-Days Across 11 Vendors"
Numbers that recur across this site. Printed, not animated.
-
87
CVEs credited
across MITRE -
612
Discreet pentests
delivered to date -
11d
Median vuln-to-patch
turnaround -
41,000
Senior practitioners
reading "Beacon Drop" -
180+
Engineering teams
engaged under NDA -
94%
2024 gross retention
on annual retainers
Benchmark — Gartner 2024 places the industry median patch turnaround at 74 days. ExploitStation's median client turnaround for the same period: 11 days.
Meet the operators. Then start the conversation.
Read individual researcher bios, specializations, prior disclosures, and conference history before you reach out. When you are ready, the engagement desk responds within one business day under NDA.