Skip to content
ExploitStation Labs — Independent Offensive Security Research

An independent offensive-security collective. Founded in 2018, operated by named humans, accountable to the people whose products we break.

This page is the institutional record — founder, team, locations, certifications, and conference history — assembled for the procurement and due-diligence reader who needs to know exactly who is behind the work before signing an engagement letter.

§ 01 — Institutional Pillars

People, Places, Credentials, Output.

Four questions every due-diligence reader asks first. Answered here, on the page, with no marketing varnish.

  1. 01

    People

    41 full-time staff as of Q1 2026 — 19 research engineers, 11 red-team operators, 6 disclosure coordinators, 5 platform and operations. The team includes three Pwn2Own winners and former engineers from NSA TAO, Unit 8200, and Google Project Zero. Lead researcher and founder Priya Ramanathan has run the firm since incorporation in Delaware in 2019.

    Founded
    2018, Zurich
    Incorporated
    2019, Delaware
    Founder
    Priya Ramanathan
  2. 02

    Places

    Headquartered at 1401 East 6th Street, Suite 420, Austin, TX 78702. Research outposts in Tel Aviv, Singapore, and Berlin (Wilmersdorf). All four offices operate under the same ISO/IEC 27001:2022 controls and SOC 2 Type II reporting boundary.

    HQ
    Austin, TX, USA
    Research outposts
    Tel Aviv · Singapore · Berlin
    Time-zone coverage
    ~22 hrs overlap
  3. 03

    Credentials

    Certified and audited under ISO/IEC 27001:2022, SOC 2 Type II, and CREST-accredited penetration testing for US, UK, and Singapore operations. Engagement deliverables conform to OWASP ASVS, NIST SP 800-115, and PTES — chosen per engagement scope.

    Certifications
    ISO 27001 · SOC 2 II · CREST
    Awards
    2024 Cybersecurity Breakthrough — Top 10
    Pwnies
    DEF CON 30, Black Hat USA 2023
  4. 04

    Output

    87 CVEs credited across MITRE to date, including 6 critical-severity (CVSS ≥ 9.0) advisories in 2024 alone. 612 discrete penetration tests and 38 multi-quarter red-team engagements delivered. Maintains an in-house 4,200-device fuzzing farm running 9.6 billion execution paths per week across client codebases.

    CVEs
    87 (6 critical in 2024)
    Engagements
    612 pentests · 38 red teams
    Patch turnaround
    11-day median (vs. 74-day industry)
§ 02 — Founder's Letter

A short note from the desk that started the firm.

I started ExploitStation in 2018 because the offensive-security market had drifted toward vendor theater: glossy reports, shallow findings, and very little of the actual work. The buyers I spoke with — CISOs, AppSec leads, the occasional general counsel — were paying for evidence and receiving PowerPoint.

We built this firm to be the opposite. Every researcher here has shipped a CVE they can name. Every red-team operator has worked a multi-quarter engagement where the goal was to break something specific and write up exactly how it broke. We refuse work that would have us rubber-stamp a checkbox; we refuse to publish a 0-day outside the agreed disclosure window; and we refuse to call ourselves "unbreakable" or to claim we can prevent the next zero-day — because the next zero-day is the entire reason our discipline exists.

What we will do is tell you, on the page and in person, how your products break. We will hand you a reproducible proof-of-concept, a timeline, and a defense. Our median client tenure is 2.7 years because the people who hire us once tend to hire us again — and we are accountable to that trust.

If that is the kind of partner you are looking for, the operators below are who you would actually be working with.

— Priya Ramanathan Founder & Lead Researcher · ExploitStation Labs, Inc.
§ 03 — Speaking Log

Conference appearances, publicly verifiable.

A chronological record of talks delivered by ExploitStation researchers at peer-reviewed offensive-security conferences. Talks are cross-referenceable against public conference archives.

  1. 2024 · Q3

    Black Hat USA — "Living Off the Kernel: Post-Exploitation in 2024"

    Las Vegas, NV · 5th talk since 2020

  2. 2024 · Q2

    DEF CON 32 — "Fuzzing at 4,200 Devices: Lessons from a Year of Continuous Exploitation"

    Las Vegas, NV · 4th talk since 2020

  3. 2024 · Q1

    OffensiveCon — "When the Sandbox Opens: Escaping Modern Container Runtimes"

    Berlin, DE · 2nd talk since 2022

  4. 2024 · Q1

    Nullcon — "Disclosure at Scale: Coordinating 47 Zero-Days Across 11 Vendors"

    Goa, IN · 3rd talk since 2020

Empty Black Hat briefing stage, photograph from the back of the hall
ExploitStation researchers have spoken at Black Hat USA, DEF CON, Nullcon, and OffensiveCon. Recordings are linked from each row above where the conference has published them.
§ 04 — The Proof Strip

Numbers that recur across this site. Printed, not animated.

  • 87 CVEs credited
    across MITRE
  • 612 Discreet pentests
    delivered to date
  • 11d Median vuln-to-patch
    turnaround
  • 41,000 Senior practitioners
    reading "Beacon Drop"
  • 180+ Engineering teams
    engaged under NDA
  • 94% 2024 gross retention
    on annual retainers

Benchmark — Gartner 2024 places the industry median patch turnaround at 74 days. ExploitStation's median client turnaround for the same period: 11 days.

§ 05 — Engagement

Meet the operators. Then start the conversation.

Read individual researcher bios, specializations, prior disclosures, and conference history before you reach out. When you are ready, the engagement desk responds within one business day under NDA.

For external researchers with a vulnerability to disclose: [email protected]