Proof

The capability is built, not borrowed.

When standard tooling falls short, we build the capability to turn uncertainty into proof.

Selected engineering and research
AOTP
Private AIProof

Privacy. AI acceleration. Human control.

LOCAL AIAUTHORITYEVIDENCE
Inspect →
Security Engagement Platform
EngagementStandard

One operating standard for authorized, isolated, evidence-ready delivery.

AUTHORITYISOLATIONRETEST
Inspect →
OSMAP
BrowserMail

Secure mail access for high-consequence systems.

RUSTOPENBSDLEAST PRIVILEGE
Inspect →
Browser AI Security
Page stateEvidence

Repeatable evidence for browser-AI attack paths and trust failures.

LOCAL AIBROWSER STATEREPLAY
Inspect →

Why we build

Innovation matters when it changes the outcome.

Black Bag Security writes code when it lets us test deeper, protect client information better, make evidence more defensible, or turn difficult work into a repeatable capability.

Engineering with a purpose
Test deeper

Reach the security question commodity tooling cannot answer.

Protect better

Reduce unnecessary exposure of client and campaign information.

Prove clearly

Make evidence reproducible, reviewable, and tied to the claim.

Repeat reliably

Turn hard-earned technical work into durable operating capability.

Offensive security innovation

AI can accelerate testing.
Authority stays human.

AOTP and the Security Engagement Platform are built around two problems Black Bag Security cares about deeply: keeping sensitive engagement context under control, and keeping authority, evidence, and reporting connected to the human operator.

Private capability. Controlled delivery.
Local intelligence

Campaign reasoning can stay close to the work rather than becoming another external data path.

Human authority

Scope, execution, stop conditions, material judgment, and findings remain governed by people.

Evidence-backed

Potential findings move through proof, replay, validation, and review.

Repeatable delivery

Authorization, private runtime, evidence, reporting, and retest follow one engagement standard.

Systems engineering

Security properties should survive real operation.

Our systems work explores the places where trust is often handed away too casually: browsers, mail, privileged services, AI context, rebuilds, and recovery.

Selected systems work
OSMAP

Secure mail for high-consequence systems, with least privilege and content isolation.

Inspect →
OpenBSD Mailstack

Reproducible hardening, operator control, and security that survives rebuild and recovery.

Inspect →
Browser-Safe AI Security

Local, reproducible investigation of prompt injection, source confusion, and browser-state abuse.

Inspect →

Client-specific engineering

If the proof is missing, we build the instrument.

Validators, harnesses, bounded proofs of concept, evidence collectors, and retest paths are built when the security question requires them.

Purpose-built for the security question
?
InvestigateUnderstand the unusual condition.
ResearchFind the missing mechanism.
BuildCreate the minimum useful instrument.
ValidateMake the condition observable.
DemonstrateShow engineers what must change.
RetestVerify the corrected condition.

Bring us the difficult question

Bring the problem standard tooling cannot explain.

Test deeper. Build the missing validator. Engineer the control. Produce the proof.

Choose the response the problem needs
Test deeper

Follow the attack path.

Build

Create the missing capability.

Research

Resolve the unknown mechanism.

Engineer

Turn the lesson into a durable control.