Red Team Operation
Multi-quarter, objective-based adversary emulation against your production estate. Average length: 14 weeks. Delivered by 2–4 senior operators with a dedicated research-engineering pod on call.
EXPLOITSTATION LABS — INDEPENDENT OFFENSIVE SECURITY RESEARCH
INTake — 02 / engagement-request
Submissions are triaged by a human disclosure coordinator within 24 hours and treated as confidential by default. No marketing list. No resale. No surprise sales follow-up.
SCOPE — 03 / intake expectations
To return a useful response inside the 24-hour SLA, our disclosure coordinators work from a tight intake. The four items below are the minimum. If you cannot share one of them yet, say so — we will tell you whether the engagement still makes sense.
We scope under contract with a registered organisation, not an alias. A named coordinator on your side — typically a CISO, Head of AppSec, legal counsel, or red-team lead — accelerates everything.
Cloud, web, mobile, kernel, embedded, or blended. Asset counts can be approximate. What matters is that we can match the right operators from our 19 research engineers and 11 red-team operators.
Why now. What changed. Which internal stakeholder is sponsoring the work. This shapes the statement of work more than any technical checkbox and is the single biggest predictor of a successful engagement.
Production freeze windows, regulatory overlays (PCI, HIPAA, FedRAMP, ITAR), in-flight M&A, prior vendor relationships, and any rules-of-engagement you have already drafted. There is no penalty for sending these with the request.
What we will not do with your submission. We do not add you to a marketing list. We do not resell or repackage the message. We do not share it outside the disclosure-coordination team without your written consent. If we cannot take the engagement, we say so within 24 hours and suggest two named alternatives where we can.
INDEX — 04 / four engagement routes
Each card is a research-journal entry, not a pricing tier. Pick the route that matches the question you are trying to answer; we will adjust scope during the scoping call.
Multi-quarter, objective-based adversary emulation against your production estate. Average length: 14 weeks. Delivered by 2–4 senior operators with a dedicated research-engineering pod on call.
An annual subscription that gives your engineering team a named research engineer and prioritised access to our in-house 4,200-device fuzzing farm. Median patch turnaround across retainer clients in 2024: 11 days.
Coordinated disclosure for vendors who have received or suspect an externally reported 0-day. Includes vendor-side triage, patch-window negotiation, and (where appropriate) coordinated CVE assignment via MITRE.
We act as your outsourced triage and validation layer for an existing public or private bug-bounty program, with full signal-to-fix hand-off into your engineering backlog. Paid out $1.2M to external researchers in 2024 under our managed programs.
PROTOCOL — 05 / post-submission timeline
The four steps below are what actually happens after you hit submit. No auto-responders, no nurture sequence, no “let me check with the team.”
A disclosure coordinator reads your submission, confirms the surface class, and flags any conflicts (existing vendor, ITAR overlay, prior disclosure). You receive a named coordinator and a secure intake channel.
A 45-minute video call with the coordinator and the lead operator who would actually run the engagement. We arrive having read your submission; you arrive having read nothing of ours. Mutual NDA is queued for signature before the call.
Our standard mutual NDA is countersigned before any technical exchange. We can also work to your paper — we have countersigned under client templates from two FAANG cloud providers, three sovereign defense agencies, and twelve Fortune 500 financial institutions.
A fixed-scope SOW with named operators, deliverables, rules of engagement, and a kill-switch process. Pricing is per-engagement, not per-seat; we do not publish a rate card and we do not run discovery calls as a sales motion.
ESCAPE HATCH — 06 / direct contact
For sovereign-defense buyers, ongoing incident response, or engagements that cannot enter a web form for compliance reasons, reach a coordinator directly. The channel below is monitored 09:00–21:00 UTC by the disclosure team.
ExploitStation Labs, Inc. · 1401 East 6th Street, Suite 420, Austin, TX 78702, USA · +1 (512) 555-0117