A new dawn. A different approach to security.

We're the team that industry titans call first. Even security companies call us when they need security.

In good company

Wiz Teleport ChainGuard Let's Encrypt Anthropic OpenAI Google DeepMind xAI Cursor AWS Google Cloud CoreWeave Cerebras Databricks Fly.io Figure AI Cresta AI METR Applied Compute Hark Recall AI Aurora Docker Notion Snap Netflix YouTube Android Google Maps Capital Group Jump Trading LightSpark Cubist Phantom Valor Ventures
Wiz Teleport ChainGuard Let's Encrypt Anthropic OpenAI Google DeepMind xAI Cursor AWS Google Cloud CoreWeave Cerebras Databricks Fly.io Figure AI Cresta AI METR Applied Compute Hark Recall AI Aurora Docker Notion Snap Netflix YouTube Android Google Maps Capital Group Jump Trading LightSpark Cubist Phantom Valor Ventures

What we offer

We partner with frontier labs and stay with our customers for the long haul. Half our work is securing AI. The other half is the security engineering everyone still needs, done by people who publish their research.

AI security

AI red teaming

We attack models, agents, and the systems wired around them: jailbreak, tool abuse, data exfiltration, and the plumbing that turns a prompt injection into an incident.

Capability evaluation

We benchmark what a model can actually do offensively, measured against real targets rather than capture-the-flag toys, so the claims you publish are ones you can defend.

AI-driven vulnerability research

We deploy and tune the pipelines that discover, exploit, and patch bugs at machine speed, then hand them over running inside your own environment.

Security engineering

Security assessments

Red teaming, infrastructure and product reviews that combine frontier models with researchers who find what everyone else misses. Every engagement is original research, not a checklist run.

Detection and response

Your next intruder may not be a person. We deploy honeytokens across your environment at scale, so autonomous attackers give themselves away early. We are there when something gets through.

Security programs

We stay after the report, because a finding is not a fix. We work with your team to build the controls we recommend: the guardrails, the detections, the paved paths that make a class of bug hard to reintroduce.

None of this is a claim you have to take on trust. Read the research →

Don't take our word for it

I rarely do shout-outs or plugs on here, but I wanted to recognize Thai Duong and the team at Calif for the excellent work they do. The security assessment and penetration testing services market is so crowded with startups and incumbents alike -- it's often difficult to find firms that have the technical skills to stand out from the rest. It's great to work with top-tier red-teamers who truly know their craft!

If there's a north star in offensive security in the age of AI, right now, it's probably Calif. I keep following along with their epic team and leadership, and keep finding that they are a fellow reliable and trustable company right now when it comes to discovering vulnerabilities with AI, but also disseminating information responsibly.

Calif successfully breached security to reach critical assets, providing us with invaluable insights to lock down our environment. I highly recommend Calif to any organization serious about identifying and fixing security flaws.

Calif's recent viral blog posts demonstrate a staggering reality: how AI can be leveraged to identify and exploit RCE vulnerabilities within the FreeBSD kernel and classic text editors like Vim and Emacs.

However, even more impressive than their use of AI is the sheer depth of their technical competence. Our team at Google has engaged with Calif on various security assessments, during which they identified weaknesses and helped us harden our mitigations. Their ability to deliver exceptionally high-quality findings makes them an invaluable partner for any high-stakes security project.

It's always a pleasure working with Thai Duong and the entire Calif team. Security testing with an unparalleled level of quality. I don't post a lot, I don't do shout outs a lot but Calif delivers top tier work worthy of recognition.

I just want to say thank you Thai Duong and Calif for consistently scaring the life out of me. This team is the most innovative penetration/security tester I have ever worked with. Over the past 5 years, they have taken 15 years off of my life with their very creative approaches to destroying my faith in any security control that exists....anywhere. Ever. If you want to know the truth, use Calif.

It's important to call out the quality security vendors when we find them. Calif does high-caliber penetration testing with world class researchers!

This is... accurate. Thai Duong and the Calif team kill it 10 times out of 10.

Shout out to Thai Duong and the team at Calif 🥷. I love a good pen test to learn new things about your infrastructure 😁

We just completed another great red team engagement with Calif - again outstanding work! A good red team engagement is indistinguishable from art and Thai Duong and his team are true artists.

Grateful to call Calif a partner. We've worked with their team for a while on Spark audits, and more recently on hands-on development. They've consistently brought strong technical insight and have been excellent to collaborate with. Partnerships like this make a real difference. Thanks to the Calif team; excited to keep building together. 🙌

In the Press

The work, as others tell it

Let's talk

Tell us what you're building, and what keeps you up at night.