proof

What we've found. What we can show you.

Cliff's founder runs an active coordinated-disclosure practice. Some findings are published and named, and you can verify them yourself. Most are still under embargo with the vendor, so they appear here by class and severity only, never by target, until they're fixed. Here is the honest ledger.

the ledger

findings verifiable ones link out · embargoed ones show class only
Cross-namespace traffic redirect, tenant-isolation bypass
moderate
Multiple findings, browser security
Chrome VRP · credited
credited
Unauthenticated remote code execution
AI infrastructure
critical
SSRF → cloud metadata credential theft
AI gateway
high
SSRF → cloud metadata, incomplete-fix of a prior CVE
data platform
high
Member → owner privilege escalation
LLM ops platform
high
Authentication bypass
ML tooling
high
Cross-tenant document IDOR
agent platform
medium
dozens of proven findings · updated as embargoes lift Ask for the full ledger under NDA →

how we prove it

reachable

Exploitable, not just present.

A finding only counts if untrusted input can actually reach the flaw. We trace the path, not the version number.

reproducible

A working exploit, on our own infra.

Every claim is backed by a runnable proof we stood up ourselves. No target of yours is ever touched to make a point.

human-verified

A person signs off.

Nothing is reported until a named researcher has reviewed it. Proof, not payload, and never a false positive shipped to a stranger.

coordinated

The vendor first, always.

We disclose privately, help with the fix, and hold the details until it ships. That discipline is why this page stays honest.

Want to see what we'd find in yours?

A readiness assessment runs the same rigor against your estate, scoped and human-supervised from the first packet.

Request a readiness assessment