Research is a responsibility, not a feature.
Research has been part of RunSybil from the beginning.
Our founders came from two research traditions, AI research and offensive security, and built RunSybil around one belief: if you're working at the frontier, you should help move it forward.
Research is part of our responsibility as a technical company.
Security advances because researchers investigate systems, challenge assumptions, disclose what they find, and share new methods.
AI advances the same way, through experimentation, evaluation, publication, and a willingness to share what works and what does not.
RunSybil sits at the convergence of both fields, so we believe we should participate in both.
That means original vulnerability research, studying how AI models perform on real security problems, building rigorous evaluations, and responsibly disclosing what we find.
Some of that work makes Sybil better. Some of it may never become a product feature. Both are worth doing.
We research because the field should move forward.
Commercial research teams are tempted to judge every project by whether it maps to the roadmap. We don't think that's enough.
Some of the most useful security research starts with curiosity: an unexpected behavior, a questionable assumption, a bug that hints at something bigger.
Our researchers have the freedom to follow those questions, across entire classes of applications and assumptions the industry treats as settled.
When that turns up something real, we disclose it responsibly so maintainers, vendors, and users can benefit.
Good research should leave the ecosystem better than we found it.
We research the systems we build.
Building AI for security creates its own obligation. It's easy to claim what a system can do. It's much harder to measure it rigorously.
We build our own measurement infrastructure and maintain evolving ground truth.
We test whether a new model actually improves discovery, whether a change trades recall for precision, and whether gains in a controlled environment hold up in the real world.
The goal is to make hypotheses testable, rather than lean on public benchmarks that may be contaminated or a poor match for the product.
It is not enough to know a system appears to work. We want to know why, where, and how well it works, and where it fails.
We learn from the people doing the work.
RunSybil's vulnerability researchers aren't downstream reviewers of the product. Their expertise is part of the research system itself.
When a researcher catches a miss, spots a false finding, develops a new technique, or notices a pattern, that creates knowledge.
We capture it and use it to sharpen our understanding of both offensive security and AI-assisted vulnerability discovery.
Vulnerability operations establish ground truth for Sybil's performance, including findings from evaluation ranges and research engagements.
That expertise can improve Sybil, and it also shapes the research questions we pursue next.
We believe in publishing the work.
Research that stays entirely inside a company has limited value to the field.
When appropriate, we publish: responsible disclosures, technical blog posts, conference talks, evaluation research, and open methodologies.
Publishing matters because it makes our work inspectable. It invites disagreement and replication.
It gives defenders knowledge they can use, and it forces our claims to survive scrutiny outside our own walls.
We want RunSybil to be known not only for what we build, but for what we discover and contribute.
Research makes Sybil better.
There is also a real commercial consequence to all of this.
Original research shows us what sophisticated discovery looks like. Evaluations tell us whether Sybil is improving.
Human triage gives us high-quality ground truth, and customer testing shows how the system behaves in real environments.
That data feeds future tests, validation, and models, drawing on runtime behavior, outputs, triage expertise, and customer disposition.
research leads to discovery, to knowledge, to the community, to product, to new questions, back to research
We don't conduct research because it's a product strategy.
We conduct it because we believe it's part of being a serious security and AI company.
That it also makes our product better is one of its most valuable consequences.