Offensive security engagements for teams that need to know exactly where they stand — and original research on how real systems fail, published as advisories.
Service lines
Credited CVEs · Apple, GitLab
90d
Disclosure window
AU
ABN 66 655 283 668
Scoped in writing, executed by senior researchers, reported with steps a developer can follow without us in the room.
The lab is where independent research happens: pulling apart web applications, reversing binaries never meant to be read, and mapping what the open internet already knows about a target. Every engagement inherits what the last experiment taught.
Credited CVEs, write-ups and open-source tooling from the lab. Vendors hear from us first under coordinated disclosure; the public record lands here once a fix has shipped.
CoreVanta Security is a registered business name of CP TECH SOLUTIONS PTY LTD (ABN 66 655 283 668), operating from Australia. We perform independent security research and apply that work on behalf of clients through scoped, professional engagements.
We work with security researchers, engineering teams and founders who want a frank technical assessment rather than a compliance certificate. The researchers who scope the work perform it, write the report and walk your developers through it.
We report to the vendor privately with a working proof of concept, offer a 90-day window before publication, and extend it when a fix is actively in progress. We do not sell vulnerabilities, and we do not publish anything still exploitable in the wild without a mitigation.
Vendors can reach the lab through the contact form or by PGP-encrypted email. Acknowledgement within two business days; we share drafts of any public write-up ahead of release.
Scope, timeline and target environment are enough to start. We reply within two business days. For vulnerability reports, mention "disclosure" and we will send a PGP key.
Your mail client should have opened with the request addressed to jay@corevantasecurity.com. If it did not, email us directly. Expect a reply within two business days.