An independent security research and analysis practice. We work on the security of AI systems, web applications, cloud infrastructure and blockchain protocols — and we publish what we find with the evidence attached.
Our work runs on two tracks.
Published research. Vulnerability analysis and incident post-mortems written for defenders — how the flaw worked, how the attack ran, and what would have caught it. Every piece ships with the primary sources: contract addresses, transaction hashes, code references, so a reader can reproduce the analysis instead of taking our word for it.
Applied security work. Security review and hardening of production systems: authorization models (row-level security, database role privileges), authentication flows, content security policy and security headers, rate limiting and abuse controls, secret handling, and pre-launch review.
Every factual claim in our research carries one of three labels, and we hold that line even when it makes a story less dramatic:
Inference does not get promoted to fact because it reads better. When we are unsure, the text says so.
We test systems we own and operate, and systems we build and operate for clients under contract. We do not test third-party systems without written authorization. Research into public incidents is conducted against public data — on-chain records, published disclosures, and source code that is already open.
If you have found a security issue in something we run, or you want to reach us about a coordinated disclosure, write to security@sirenbow.com. Machine-readable contact details are at /.well-known/security.txt.
We read every report and we will tell you plainly whether we consider it valid, and why.