ARQUEBUS Contact

Offensive security research & advisory

A defense you haven’t tested is only a belief.

Arquebus helps teams understand where applications, APIs, and AI agents can fail—and what it takes to fix them. Led by Aidan Vasconi, the practice brings security leadership and hands-on research to the same table.

Authorized testing. Reproducible findings. Practical remediation.

Leadership

Aidan Vasconi

Security leader & researcher

Aidan leads security teams, products, and engagements, connecting technical findings with the decisions teams need to make. His work spans secure code review, technical due diligence, and independent vulnerability research, with a focus on authorization, APIs, and AI agent trust boundaries.

Research & practice

A public record. A considered approach.

Independent research informs the work. Explore Aidan’s public profile and the tools and disclosure practices behind an assessment.

Public profile

Bugcrowd researcher profile

Aidan’s researcher profile provides a public point of reference for the work and activity published by Bugcrowd.

View Aidan’s profile
Research tooling

Built around the evidence

In-house tooling supports scope checks, authorization review, evidence organization, and remediation validation. Its purpose is to make research easier to inspect and repeat.

Disclosure

Coordinated by default

Research follows written authorization or an applicable program policy. Findings go through the affected party’s disclosure channel; confidential details remain private.

Security contact

Method

A finding has to survive scrutiny.

A suspicious response is a starting point. A finding needs reproducible behavior, meaningful controls, and evidence of the security boundary that failed.

01 / Observe

Reproduce the behavior and record the environment, permissions, and preconditions it depends on.

02 / Control

Compare the result with expected behavior and a known-working test path. Repeat the observation to check alternative explanations.

03 / Conclude

Separate demonstrated impact from hypotheses. Explain what the evidence establishes, where it stops, and what a fix needs to change.

For AI agents, the outcome matters. A changed answer alone does not establish a security failure, and matching answers do not prove a defense. We look for an observed consequence across a trust boundary and use controls to support the conclusion.

Expertise

Where the work goes deepest.

01

Authorization & business logic

Access control, tenant and role boundaries, identity, sessions, and the workflows that connect them. We assess whether users can reach data or actions beyond their intended permissions.

02

AI application & agent security

Assistants, retrieval systems, and tool-using agents, assessed at the boundaries between users, data, models, and actions.

  • User permissions carried through to tools
  • Untrusted content and indirect prompt injection
  • Sensitive data and cross-user isolation
03

Vulnerability research & exploitability

Root-cause analysis, reverse engineering, and controlled validation to establish whether a weakness is exploitable, how far it reaches, and whether a patch closes the demonstrated path.

Red teaming & adversarial simulation

Scoped engagements that test how preventive controls, detection, and response hold up against an agreed objective.

Security leadership & advisory

Secure code review, technical due diligence, and guidance that helps product and engineering teams prioritize remediation.

Engagement

Clear scope. Evidence you can act on.

Scope & authorization

Agree on the systems, permitted actions, testing window, and handling of sensitive data. Establish written authorization before testing.

Investigation

Investigate how the system is built and used, with focused manual testing and purpose-built tooling.

Validation

Reproduce candidate findings, run relevant controls, and document both the impact and the limits of the evidence.

Reporting

Deliver technical evidence and practical remediation guidance. Severity follows the demonstrated impact.

Remediation review

Retest fixes within the agreed scope and window, then record whether the demonstrated path is closed.

What a finding contains

  • Affected behavior — the component and the assumption that fails
  • Reproduction — the steps and preconditions
  • Evidence — the artifacts, and the controls the result rests on
  • Impact — the access or consequence demonstrated
  • Limits — what the result does not establish
  • Remediation — what a fix has to change
  • Status — retested and closed, or open and why

Contact

Security work starts with a conversation about scope.

Share what you’re building, the question you need answered, and your timeline. We’ll discuss fit, scope, and the evidence you need to move forward.

Assessments & advisory

hello@arquebus.ai

Report a security issue

For a vulnerability affecting Arquebus, contact security@arquebus.ai.