// WE PUBLISH WHAT WE LEARN

Research & Analysis

Original computation on public data. Experiments with reproducible setups. Novel findings when we earn them. Every piece is labeled for exactly what it is.

Analysis

7

MIN READ

Why AI-Built Apps Need a Different Pentest

AI writes code faster than anyone secures it, and the failure modes are new. Prompt injection, over-permissioned agents, secrets in generated code, and attacks on the AI assistant itself sit outside a standard pentest. Here is what testing an AI-built app should actually cover.

READ THE FULL PIECE ->

Analysis

6

MIN READ

Does SOC 2, ISO 27001, or PCI DSS Require a Penetration Test?

PCI DSS explicitly requires penetration testing; SOC 2, ISO 27001, and HIPAA do not name it but expect it in practice. A framework-by-framework answer on where a pentest is mandatory versus strongly expected.

READ THE FULL PIECE ->

Analysis

6

MIN READ

Does AI Actually Make SOC 2 Faster? We Fact-Checked the Compliance Vendors

Every compliance automation vendor claims AI makes SOC 2 dramatically faster - "50% less work", "80-90% faster evidence collection", "weeks instead of months". We compiled the quantified claims from the top-ranking pages and checked which ones disclose any methodology. Most don't. Here is what is actually substantiated, and the one thing about SOC 2 timelines that no AI can compress.

READ THE FULL PIECE ->

Analysis

8

MIN READ

Securing AI-Generated Code: What 23 Studies and 48,185 CVEs Actually Show

We reviewed 23 studies and industry datasets on AI-generated code security. Roughly one in three AI-generated code samples contains a vulnerability - a rate that has not improved across model generations - while CVE publications grew 139% in the four years AI went from writing none of our code to roughly a third of it. Here is what the evidence says actually works.

READ THE FULL PIECE ->

Analysis

6

MIN READ

Annual Pentests Would Have Missed 67% of 2025's Actively Exploited Vulnerabilities

We computed the disclosure-to-exploitation window for all 245 vulnerabilities added to CISA's Known Exploited Vulnerabilities catalog in 2025. The median window is 26 days. Under an annual pentest schedule, an expected 67.5% would never be tested before exploitation - and quarterly testing still misses 54%.

READ THE FULL PIECE ->