Offensive security research & advisory
A defense you haven’t tested is only a belief.
Arquebus helps teams understand where applications, APIs, and AI agents can fail—and what it takes to fix them. Led by Aidan Vasconi, the practice brings security leadership and hands-on research to the same table.
Authorized testing. Reproducible findings. Practical remediation.
Leadership
Aidan Vasconi
Security leader & researcher
Aidan leads security teams, products, and engagements, connecting technical findings with the decisions teams need to make. His work spans secure code review, technical due diligence, and independent vulnerability research, with a focus on authorization, APIs, and AI agent trust boundaries.
Research & practice
A public record. A considered approach.
Independent research informs the work. Explore Aidan’s public profile and the tools and disclosure practices behind an assessment.
Bugcrowd researcher profile
Aidan’s researcher profile provides a public point of reference for the work and activity published by Bugcrowd.
View Aidan’s profileBuilt around the evidence
In-house tooling supports scope checks, authorization review, evidence organization, and remediation validation. Its purpose is to make research easier to inspect and repeat.
Coordinated by default
Research follows written authorization or an applicable program policy. Findings go through the affected party’s disclosure channel; confidential details remain private.
Security contactMethod
A finding has to survive scrutiny.
A suspicious response is a starting point. A finding needs reproducible behavior, meaningful controls, and evidence of the security boundary that failed.
Reproduce the behavior and record the environment, permissions, and preconditions it depends on.
Compare the result with expected behavior and a known-working test path. Repeat the observation to check alternative explanations.
Separate demonstrated impact from hypotheses. Explain what the evidence establishes, where it stops, and what a fix needs to change.
Expertise
Where the work goes deepest.
Authorization & business logic
Access control, tenant and role boundaries, identity, sessions, and the workflows that connect them. We assess whether users can reach data or actions beyond their intended permissions.
AI application & agent security
Assistants, retrieval systems, and tool-using agents, assessed at the boundaries between users, data, models, and actions.
- User permissions carried through to tools
- Untrusted content and indirect prompt injection
- Sensitive data and cross-user isolation
Vulnerability research & exploitability
Root-cause analysis, reverse engineering, and controlled validation to establish whether a weakness is exploitable, how far it reaches, and whether a patch closes the demonstrated path.
Red teaming & adversarial simulation
Scoped engagements that test how preventive controls, detection, and response hold up against an agreed objective.
Security leadership & advisory
Secure code review, technical due diligence, and guidance that helps product and engineering teams prioritize remediation.
Engagement
Clear scope. Evidence you can act on.
Scope & authorization
Agree on the systems, permitted actions, testing window, and handling of sensitive data. Establish written authorization before testing.
Investigation
Investigate how the system is built and used, with focused manual testing and purpose-built tooling.
Validation
Reproduce candidate findings, run relevant controls, and document both the impact and the limits of the evidence.
Reporting
Deliver technical evidence and practical remediation guidance. Severity follows the demonstrated impact.
Remediation review
Retest fixes within the agreed scope and window, then record whether the demonstrated path is closed.
What a finding contains
- Affected behavior — the component and the assumption that fails
- Reproduction — the steps and preconditions
- Evidence — the artifacts, and the controls the result rests on
- Impact — the access or consequence demonstrated
- Limits — what the result does not establish
- Remediation — what a fix has to change
- Status — retested and closed, or open and why
Contact
Security work starts with a conversation about scope.
Share what you’re building, the question you need answered, and your timeline. We’ll discuss fit, scope, and the evidence you need to move forward.
Assessments & advisory
hello@arquebus.aiReport a security issue
For a vulnerability affecting Arquebus, contact security@arquebus.ai.