Cliff finds and proves the exploitable paths into your systems: operated by a human, inside your scope, every action logged and approved. See what a machine attacker reaches first, before one does.
Scanners hand you a pile of maybes. Cliff chains the real ones into a working, reproducible path, then stops at a human gate before anything leaves the building. Here is one finding you can verify in full, and the breadth of the rest.
In July 2026 a frontier model broke out of a lab's own sandbox and into production infrastructure on its own. That is the fear every CISO now carries into a conversation about offensive AI. So we built the leash first, and made it non-negotiable.
Cliff operates only inside a scope you define, agreed before anything starts. No surprise assets, no drift into things you didn't authorize.
Every action that touches a target crosses an approval gate a person signed. Cliff proposes; you approve; then it proves.
Stop it at any time and it stops, immediately. A hard rule: it halts at the boundary, it doesn't negotiate with a denial or route around it.
Cliff shows the exploit exists; it does not detonate it. The least action needed to prove the finding, and no more.
A complete, timestamped record of what ran and why, handed to you. Defensible to your board and your auditors, not just to us.
A researcher reviews before anything ships. Cliff is the instrument; a person is the operator of record, and stays that way.
Measured against a standard, not a promise. Cliff maps to the OWASP Autonomous Pentesting Testing Standard (APTS), human-oversight and safety-controls domains.
Autonomous vulnerability discovery stopped being hypothetical this past year. The only open question left is whether the version pointed at your estate is governed.
Cliff is built and run by Gal Ankonina — offensive research at Unit 8200, defensive security at Fortune-50 scale, product at security startups, and an active vulnerability-research practice today.
The research doesn't stop at customer estates. It goes upstream, into the infrastructure those estates are built on. The CVE listed here is in Cilium, the CNCF-graduated networking layer running underneath Kubernetes fleets. When Cliff tests your environment, it is the same practice that found bugs in the software running it.
Nothing leaves here unproven. Every finding is reproduced end to end on our own instance, with a working exploit and the minimal patch that fixes it, before it reaches the vendor or reaches you. The industry's problem is not producing findings. It is that almost none of them survive contact with the vendor. These did.
Cadence over noise: coordinated disclosures and posture research, in the open. The work builds the trust the marketing can't.
We scanned the 40 most-used open-source projects and got 30,333 scanner alerts. Then we verified them. What the security apparatus most teams trust actually catches, measured.
Cliff is in limited early access. Tell us what you'd want tested, and we'll take it from there, scoped and human-supervised from the first packet.
Security disclosures instead? security@cliffsecurity.ai