Open
Source
Code from the lab, and the bar a release has to clear.
Everything released is indexed below.
Claims are cheap in this field
Code and published research are the two artefacts a buyer can evaluate without taking anyone's word for it. They either work or they do not.
The other half of that surface is the research lab, where disclosures go up with their writeups and advisories.
What gets released
Three categories, in the order they are likely to appear.
Tooling that came out of real work
Released when an engagement or a research effort produced something reusable and no adequate public equivalent existed.
Reproduction artefacts for published research
Where a harness verifies a disclosure faster than a paragraph, it ships with it.
Detection and defensive counterparts
Where a release makes an attack easier, it should also make the attack easier to see.
Evaluate the work that exists
Hold the code above, the published research and the report structure against anyone else you are considering.
Direct: hello@principlebreach.com
Elsewhere
- Research lab: disclosures with technical writeups
- Sample report: a complete 43-page fictional deliverable
- Office hours: thirty free technical minutes