See All Vulnerability ResearchAI for SecurityCompetitionsNewsProductOpen Source ProjectsFAQCase Study
Xint’s False Positive Rate: Methodology and Purpose
We don’t know the FP rate for the latest frontier models when it comes to AppSec. We share ours and how we arrived at it.

Why Zero Data Retention Should Be Non-Negotiable When Your Team Uses LLMs
Zero data retention (ZDR) policies for LLMs in AppSec are not the default, but here's why they belong at the top of your AI procurement checklist.

What to Ask Every AI PenTest Vendor Before You Buy
These are the 8 questions that will tell you whether a vendor is selling a pen test alternative, a faster SAST tool, or a demo that doesn’t survive production
Vulnerabilities vs. Weaknesses: Why the Distinction Matters
There's a difference between insecure code patterns and true vulnerabilities that hackers seek to exploit. Why does that matter?