Who we are
Research first, everything else second.
AF Digital Security started as a small group of researchers who kept finding the same thing: most security work optimizes for reports, not for whether a system actually gets harder to break. We built the company around the second thing.
01 — Principles
What we hold ourselves to
Reproduce before you report
A finding isn't real until we've triggered it ourselves, end to end, under conditions the client actually runs.
Severity is contextual
A CVSS score is a starting point. We rank by what the bug actually lets an attacker do to this system, for this client.
Disclosure is a relationship
We work with the team that owns the system, on a timeline we set together — not against them.
Publish the details
Vague advisories don't help defenders. Once a fix ships, we publish enough to actually act on.
No fix, no close
A case stays open until we've retested the original proof of concept against the shipped patch.
Independence matters
We don't sell the products we audit. Our only product is the research itself.
02 — History
How we got here
Founded
Started as an independent research collective publishing findings from personal projects and CTF-derived techniques.
First coordinated disclosures
Began formal coordinated disclosure work with open-source maintainers who had no existing security process.
First enterprise engagements
Took on our first paid offensive research engagements for infrastructure and fintech clients.
Threat intelligence practice launched
Formalized infrastructure-tracking work into an ongoing intelligence practice for existing clients.
100th disclosure
Filed our hundredth coordinated disclosure, with a 94% on-time patch rate across all cases to date.
Today
A distributed team working across offensive research, disclosure, threat intelligence, and applied cryptography for clients worldwide.
03 — Team
Who's doing the work
A small, senior team by design — every engagement is led by someone who still does hands-on research.
Founding researcher & director
Leads exploit development and sets technical direction across engagements.
Head of disclosure
Runs coordination with vendors and maintainers from first report to published advisory.
Head of intelligence
Tracks campaign infrastructure and leads early-warning briefings for clients.
Principal cryptography researcher
Audits protocol implementations and key management systems.
Senior researcher
Focuses on embedded and firmware targets.
Senior researcher
Handles patch verification and public writeups.
Want to work here?