Commission research

Bring THOR-SEC a hard problem

Bring the security or infrastructure problem that routine tools, audits, and vendors have not answered. THOR-SEC scopes it, researches it in an authorized environment, and returns results labeled by how strongly the evidence supports them.

Problems worth bringing

  • Agent security

    What stops an injected instruction from becoming an action

    An LLM agent or automation can send, export, or change things, and you need to know where authorization actually lives. See the control plane case study.

  • System trust

    Whether a system is what it claims to be

    Model routing, provider substitution, and identity questions where the system's own answer is not proof. See the identity verification case study.

  • Post-access exposure

    What an attacker keeps after getting in

    Lateral paths, credential reuse, and architecture that stays mappable long after initial access. See the MIAM case study.

  • Unowned risk

    The failure mode nobody owns

    A security or infrastructure problem that falls between teams, vendors, or standards and needs a researched answer rather than a checklist.

If the answer is already a standard checklist or an off-the-shelf scan, a THOR-SEC engagement is probably not the right tool.

Engagement types

  • Sponsored research

    A question, answered properly

    Fund focused research on a topic you need understood: an attack technique, a defensive design, a class of AI risk. Deliverables are a written report, reproducible artifacts, and a briefing.

  • Architecture review

    Security architecture review

    An independent read of a system design, threat model, or control architecture, with concrete findings and a prioritized path to fix them.

  • AI security

    AI and LLM security assessment

    Review of agent authorization, tool boundaries, model routing, and LLM infrastructure against the failure modes documented in THOR-SEC research.

  • Writing

    Technical writing and briefings

    Research reports, whitepapers, and executive or engineering briefings that people can act on.

How it works

  1. Send a requestUse the form below or email: the question, scope, timeline, and budget range.
  2. Scope reviewTHOR-SEC reviews the question and authorization, then arranges a short scoping discussion if it is a fit.
  3. Written proposalScope, deliverables, schedule, fee, and publication terms, agreed in writing before work starts.
  4. PaymentOnce the proposal is agreed, payment is made through a Stripe invoice or payment link. THOR-SEC never handles card details.
  5. Research and deliveryFindings, evidence, and artifacts, followed by a walkthrough with your team.

What comes back

  • A written answer to the scoped question: what was examined, how, and what was out of scope.
  • Every conclusion labeled with its evidence level: formal design, prototype, implemented and tested, or empirical. These are the same labels used in THOR-SEC case studies.
  • Reproducible artifacts where the scope allows, such as test harnesses, reference defenses, configurations, or data.
  • Limitations and open questions, stated explicitly.
  • A walkthrough with your team.

Publication, confidentiality, and IP

  • Publication is decided before work starts: public, published after a disclosure window, or private.
  • Your confidential information is not published or reused in THOR-SEC research without your written permission. Confidentiality agreements are available on request.
  • Ownership of deliverables, and of anything new invented during the engagement, is set in the written proposal before work starts. THOR-SEC's existing research, tools, and methods remain THOR-SEC's.
  • A finished engagement becomes a public case study only with your agreement, and never includes your confidential details.

These are the defaults THOR-SEC proposes. The written proposal governs, and each party should review it with its own advisers.

Ground rules

  • Work covers systems you own or are explicitly authorized to test. Written authorization is required for any hands-on testing.
  • THOR-SEC does not accept work involving unauthorized access, credential theft, surveillance of individuals, or offensive operations against third parties.

Do not include secrets, credentials, customer data, exploit code, or confidential logs in a first message. Sensitive details can be shared after scoping, through a channel agreed with you.

Start a request

Short answers are fine. Fields marked required are needed to review the request. Submitting a request is for scoping only and does not create an engagement.

Contact
Research
Terms

Prefer email? Email a research request with the same fields.