Cybersecurity research & assurance
Independent security research for AI and modern software.
H-One helps technology teams identify, understand, and address meaningful security risks through authorized adversarial testing and focused research.
AI security evaluation
Adversarial evaluation of AI models and agentic systems, from model behavior to tools and surrounding application controls.
Learn more →02Application security research
Manual analysis of web applications and APIs with an emphasis on business logic, authorization, and practical impact.
Learn more →03Cloud and infrastructure
Assessment of trust boundaries across cloud services, identity systems, exposed infrastructure, and security-sensitive configurations.
Learn more →Explore the work
See how the security question changes by system.
Select a domain to review the questions we test and the outputs a technical team can expect.
Selected focus
Evaluate the behavior and boundaries of AI-enabled products.
Testing considers the model, application logic, tools, data flows, and user trust assumptions as one connected system.
Can untrusted content redirect the system?
Can tools be used outside intended authority?
What sensitive context can be exposed?
Threat model and test plan
Reproducible findings
Mitigation priorities
Research
Security questions at the edge of emerging technology.
We collaborate on adversarial evaluation, benchmark development, and coordinated vulnerability research involving AI systems and modern software platforms.
Explore research prioritiesApproach
Rigorous work.
Clear outcomes.
Every engagement is scoped around a concrete question and conducted with explicit authorization.
How we work →Insights
Notes on security evaluation and system design.
Evaluating tool-use risk in agentic systems
A practical framework for reviewing authority, instructions, data flow, and failure containment.
Read note →Application security · 7 minAuthorization boundaries in modern APIs
Why object checks are only one part of a broader identity and workflow problem.
Read note →Evaluation · 6 minDesigning reproducible security evaluations
How to turn open-ended adversarial testing into evidence that supports engineering decisions.
Read note →Start a conversation
Have a system or research question worth testing?
Tell us what you are building, the question you need answered, and where an independent security perspective could help.
Contact H-One