Skip to content

EXPLOITSTATION LABS — INDEPENDENT OFFENSIVE SECURITY RESEARCH

Book a Confidential Engagement.

NDA-BY-DEFAULT · 24-HOUR RESPONSE SLA · US / UK / SG

INTake — 02 / engagement-request

Submit Engagement Request

Submissions are triaged by a human disclosure coordinator within 24 hours and treated as confidential by default. No marketing list. No resale. No surprise sales follow-up.

A disclosure coordinator will reply from [email protected] with a secure intake channel before any technical exchange begins.

By submitting, you acknowledge this channel is for legitimate offensive-security scoping. Vendors, journalists, and competitors: please use [email protected] instead.

SCOPE — 03 / intake expectations

What we need from you to scope an engagement.

To return a useful response inside the 24-hour SLA, our disclosure coordinators work from a tight intake. The four items below are the minimum. If you cannot share one of them yet, say so — we will tell you whether the engagement still makes sense.

  1. 01

    The legal entity and a verified point of contact.

    We scope under contract with a registered organisation, not an alias. A named coordinator on your side — typically a CISO, Head of AppSec, legal counsel, or red-team lead — accelerates everything.

  2. 02

    The surface class and a rough asset list.

    Cloud, web, mobile, kernel, embedded, or blended. Asset counts can be approximate. What matters is that we can match the right operators from our 19 research engineers and 11 red-team operators.

  3. 03

    The business context, in one paragraph.

    Why now. What changed. Which internal stakeholder is sponsoring the work. This shapes the statement of work more than any technical checkbox and is the single biggest predictor of a successful engagement.

  4. 04

    Constraints we must design around.

    Production freeze windows, regulatory overlays (PCI, HIPAA, FedRAMP, ITAR), in-flight M&A, prior vendor relationships, and any rules-of-engagement you have already drafted. There is no penalty for sending these with the request.

What we will not do with your submission. We do not add you to a marketing list. We do not resell or repackage the message. We do not share it outside the disclosure-coordination team without your written consent. If we cannot take the engagement, we say so within 24 hours and suggest two named alternatives where we can.

INDEX — 04 / four engagement routes

Four ways engagements typically start.

Each card is a research-journal entry, not a pricing tier. Pick the route that matches the question you are trying to answer; we will adjust scope during the scoping call.

RT-01

Red Team Operation

Multi-quarter, objective-based adversary emulation against your production estate. Average length: 14 weeks. Delivered by 2–4 senior operators with a dedicated research-engineering pod on call.

38 multi-quarter engagements to date
ER-02

Exploit Research Retainer

An annual subscription that gives your engineering team a named research engineer and prioritised access to our in-house 4,200-device fuzzing farm. Median patch turnaround across retainer clients in 2024: 11 days.

94% gross retention, 2024
DC-03

0-Day Disclosure Consultation

Coordinated disclosure for vendors who have received or suspect an externally reported 0-day. Includes vendor-side triage, patch-window negotiation, and (where appropriate) coordinated CVE assignment via MITRE.

47 responsibly-disclosed 0-days since 2019
BB-04

Bug-Bounty Triage Partnership

We act as your outsourced triage and validation layer for an existing public or private bug-bounty program, with full signal-to-fix hand-off into your engineering backlog. Paid out $1.2M to external researchers in 2024 under our managed programs.

6 disclosure coordinators on staff

PROTOCOL — 05 / post-submission timeline

From submit to statement of work — typically 9 business days.

The four steps below are what actually happens after you hit submit. No auto-responders, no nurture sequence, no “let me check with the team.”

  1. 01 T+4 business hours

    Human triage.

    A disclosure coordinator reads your submission, confirms the surface class, and flags any conflicts (existing vendor, ITAR overlay, prior disclosure). You receive a named coordinator and a secure intake channel.

  2. 02 T+48 hours

    Scoping call.

    A 45-minute video call with the coordinator and the lead operator who would actually run the engagement. We arrive having read your submission; you arrive having read nothing of ours. Mutual NDA is queued for signature before the call.

  3. 03 T+3 business days

    Mutual NDA executed.

    Our standard mutual NDA is countersigned before any technical exchange. We can also work to your paper — we have countersigned under client templates from two FAANG cloud providers, three sovereign defense agencies, and twelve Fortune 500 financial institutions.

  4. 04 T+5 business days

    Statement of work delivered.

    A fixed-scope SOW with named operators, deliverables, rules of engagement, and a kill-switch process. Pricing is per-engagement, not per-seat; we do not publish a rate card and we do not run discovery calls as a sales motion.

ESCAPE HATCH — 06 / direct contact

If the form isn’t appropriate, write to us directly.

For sovereign-defense buyers, ongoing incident response, or engagements that cannot enter a web form for compliance reasons, reach a coordinator directly. The channel below is monitored 09:00–21:00 UTC by the disclosure team.

87 CVEs credited across MITRE
612 Discrete penetration tests delivered
180+ Engineering teams under NDA
ISO 27001:2022 · SOC 2 Type II · CREST (US / UK / SG)

ExploitStation Labs, Inc. · 1401 East 6th Street, Suite 420, Austin, TX 78702, USA · +1 (512) 555-0117