Understand the root cause
Study product design, implementation and authorization mechanisms to identify new weaknesses and explain why the failure is possible.
Security research for software, hardware and connected systems. We investigate root causes, examine how weaknesses interact and validate their impact through controlled proof of concept, giving your team evidence it can act on.
Speak with us through a Voxfor sales ticket
Led by Netanel Siboni in collaboration with NetanelAI
From a single component to the security of the whole system
Voxfor provides penetration testing, advanced vulnerability research, PoC development and exploit validation for software products, websites, APIs, infrastructure, cloud environments, operating systems, hardware, firmware, embedded systems, blockchain and AI agents.
The research goes beyond identifying known vulnerabilities. We examine architecture, business logic, permissions and trust boundaries, including how individual weaknesses combine into multi-stage vulnerability chains. Findings are connected to their root cause and validated impact within the agreed research scope.
Study product design, implementation and authorization mechanisms to identify new weaknesses and explain why the failure is possible.
Look across components, identities and trust boundaries to understand how separate weaknesses can change the risk to the wider system.
Use controlled validation, documented conditions and evidence so engineering and security teams can distinguish a confirmed finding from a hypothesis.
A focused assessment for one product or an investigation across connected environments. The technology and the question you need answered determine the method.
Assess websites, SaaS products and APIs with a focus on business logic, separation between users and tenants, and authorization for actions and data. Research also examines the relationship between the public interface and the systems behind it.
Examine cloud configuration, service identities, delegated access and resource permissions. Research focuses on separation between environments and the business impact of misplaced trust, excessive privileges or an unintended connection.
Penetration testing and security research for operating systems, network services, protocols, containers and virtual machines. We assess permissions, isolation and dependencies between services as part of the infrastructure’s wider security model.
Assess hardware products and embedded systems across physical components, firmware and software. Research covers trust mechanisms, interfaces, secure boot, update integrity and separation within the product, with a research environment suited to the equipment.
Assess the system around a model, not only its responses. Research covers external inputs, access to data, tool permissions and agent identities, and how automated actions affect connected business systems.
Security research for smart contracts, protocols, cross-chain bridges, nodes and signing mechanisms. We examine trust between on-chain code, off-chain services and hardware-backed security components, including HSMs where relevant to the product.
Commission research before a launch, after a significant architectural change or around a difficult engineering question. We investigate product behavior and trust boundaries to identify previously unknown weaknesses that routine testing may miss.
More than two decades of designing, building and operating production systems inform the work. From bare-metal servers to operating systems and virtualization, we understand the infrastructure through hands-on engineering as well as security research.
Research examines how containers and virtual machines enforce permissions and separation, including their relationship to the kernel and hypervisor. The question is whether a failure remains contained or affects another environment or the host.
Hardware and firmware research connects physical interfaces, memory architecture, update mechanisms and secure boot. It examines how trust is established in the product and what a failure means for the layers that depend on it.
A weakness can have a different impact when combined with another component’s permissions or behavior. We investigate these cross-layer relationships to understand system-wide risk and identify where remediation can break the chain. Controlled validation and its evidence remain within the agreed scope.
The research supports both the people fixing the system and those making business decisions. Deliverables and their depth are agreed before the engagement.
Controlled proof of concept establishes the impact of a finding rather than relying on a scanner label. The authorized client team receives technical evidence, the conditions assessed and the agreed validation material.
Root-cause analysis, affected components, technical and business impact, and prioritized recommendations. The report connects the evidence to the actions your development and security teams need to take.
On request, map findings, evidence and remediation to relevant controls and methodologies, including ISO 27001, PCI DSS, OWASP and internal security requirements. This supports Security, Risk, Compliance and procurement reviews.
Validate agreed fixes against the relevant version and conditions. Retesting revisits the original finding and the effect of the change on related components, with the coverage defined in the engagement.
Control mapping supports your compliance work; it is not a certification or a substitute for an independent compliance audit.
Voxfor provides Red Team assessments that evaluate an organization’s detection and response capabilities against an agreed objective. The focus is not only whether a weakness exists, but whether the defense team recognizes the activity, understands its significance and acts before the exercise reaches its objective.
An objective may relate to a sensitive internal application, a privileged account or a production environment. The exercise connects relevant applications, identities, cloud systems, endpoints and infrastructure under defined rules of engagement, coordination and stop conditions.
Compare the exercise timeline with actual detection. Distinguish an event recorded in a log from an alert raised and an activity the defense team noticed.
Assess whether the team connected the signals, recognized the affected systems and identities, and understood their significance to the business objective.
Review escalation, response and containment against the exercise timeline. Identify gaps in monitoring, incident handling and coordination between teams.
The outcome: a report connecting exercise observations to alerts and defensive actions, showing what was detected, when a response occurred and where gaps remain, with targeted improvements and agreed follow-up testing.
Discuss a Red Team assessmentNetanel Siboni personally leads the engagement, bringing production infrastructure experience together with independent security research. Your research objectives, interpretation of findings and final deliverables have a named point of responsibility.
His research experience includes authorized Bug Bounty and Vulnerability Disclosure programs on international platforms. This work involves vulnerability research, root-cause analysis, vulnerability chains, impact validation and controlled proof of concept under each program’s scope and rules.
The same discipline carries into private engagements: define the research question with the client, investigate the actual system, validate findings and deliver technical material that supports remediation.
Voxfor delivers the service in collaboration with NetanelAI. Voxfor and the Israeli business Netpower are both owned and operated by Netanel. The delivery combines his direct leadership with autonomous AI workers and a research workflow tailored to each project.
The workflow combines GPT-6-Astra, Daybreak Red and other models selected for the research task. Autonomous AI workers support code and architecture analysis, deeper investigation, comparison of findings and evidence organization.
Agents connect to systems we already build, operate and investigate: identities, permissions, APIs, operating systems, virtualization and external services. That engineering context matters when examining the boundary between information a model receives and actions an agent can take.
Research follows the complete business workflow, including tool access and the consequences of automated actions. AI-assisted analysis is combined with professional review and evidence-based validation; a model’s suggestion is not treated as a confirmed finding on its own.
Client-data use, permitted tools and confidentiality requirements are agreed as part of the engagement.
Commission a focused product investigation, an objective-led Red Team exercise or recurring assessments around releases. Scope follows your system and goals rather than a fixed checklist package.
Agree the product, objectives, assets, authorization, access and rules of work, including exclusions, deliverables, price and retest conditions.
Research the system and the agreed question. Material findings are communicated through the reporting process defined with your team.
Separate hypotheses from confirmed findings and document the evidence, dependencies, conditions, and technical and business significance.
Deliver the report and prioritized recommendations. After remediation, revisit the agreed findings and assess the relevant changes.
Technical depth, clear deliverables and a scope designed around the system you need to assess.
Discuss your requirementsPenetration testing assesses the security of defined assets and the impact of weaknesses. Advanced testing can examine business logic and relationships between components. Vulnerability research focuses more deeply on engineering questions and root causes, including previously unknown weaknesses in a product. An engagement can combine these approaches according to the system and research objective.
A scanner can contribute to the work, but its alerts are not the final research output. We investigate which findings are significant, under what conditions they matter and what impact they have on the system and business. The deliverable connects validated evidence with root cause and remediation, rather than handing your team an unexplained list of alerts.
Yes. Controlled proof-of-concept development and exploit validation are part of the research services. Their purpose is to establish a finding’s impact with documented evidence. The validation work, conditions and material delivered to the authorized client team are defined by the engagement and its permissions.
The organization agrees an objective and an authorized scenario. The exercise timeline is compared with alerts and defensive actions to establish when the activity was detected, whether its significance was understood and whether the response arrived in time. The level of coordination with the defense team is set in the rules of engagement.
Yes. Research can examine hardware components, firmware, embedded software, interfaces, trust mechanisms and updates across the product lifecycle. The environment is planned around the equipment, files and access needed for the particular assessment.
LLM security testing examines the system in which the model operates: information it receives, how it is used and the boundary between input and action. Agent security research also examines tool permissions, identities and effects on external systems. The focus is the complete business workflow, supported by infrastructure and AI engineering experience.
The workflow uses GPT-6-Astra, Daybreak Red and other models selected for the task, with autonomous AI workers supporting code and architecture analysis, research and review. Netanel leads the engagement, and findings are validated against evidence. Client-data processing and permitted tools are agreed with you before work begins.
Research can cover smart contracts and the protocol and infrastructure around them: bridges, nodes, intermediary services and signing mechanisms, including hardware security modules where relevant. It examines how permissions, system state and trust between on-chain and off-chain components affect operations and digital assets.
Yes. Zero-day vulnerability research aims to identify previously unknown weaknesses by studying product design, implementation and trust relationships rather than only checking a list of known issues. Findings are investigated through root-cause analysis and controlled validation. A research engagement does not guarantee that a new vulnerability will be discovered.
Depending on the product and research objective, the work may use a representative test environment, a dedicated lab or production with agreed actions and timing. Access, data handling, operational constraints and reporting are planned so findings remain relevant to the real system.
Yes. Findings, evidence and remediation can be mapped to relevant controls and methodologies, including ISO 27001, PCI DSS, OWASP and internal requirements. Agree the mapping needed by your security, risk or procurement team during scoping. The research report supports that process; it is not itself a compliance certification.
Yes. You can commission work around a launch or architectural change and agree recurring research between releases. Each cycle defines the changed components, research questions and deliverables. Retesting checks agreed fixes against the original findings and relevant dependencies.
No. Engagements can cover systems hosted with Voxfor, other providers, public cloud or on premises. The scope and authorization must cover the assets and account for any platform or hosting requirements.
Open a sales ticket with a short overview of the product, technologies, research goal and timing. We define the scope, access, deliverables and quote with you before work starts. Mention any NDA or secure-channel requirements before sharing technical material. The initial inquiry does not need credentials, source archives or customer data.
Tell us what you are building or operating, and what you need to understand. We will define the research scope and the deliverables that help your team make the next decision.
Your inquiry opens in the Voxfor client portal
Need an NDA or a secure channel? Mention it in your initial inquiry so the arrangements can be agreed before technical material is shared.