A new dawn. A different approach to security.
We're the AI security consultancy that frontier labs call first. We hire the best hackers and do the coolest hacks.
In good company
Even security firms hire us
What we offer
We partner with frontier labs and work with our customers for the long haul. Yes, we offer AI-based red teaming, infrastructure and product security assessments. And yes, we help respond to incidents. But we also go beyond: we help grow security programs and prepare organizations for the AI era when others are still stuck in yesteryear.
Security Assessments
Red teaming, infrastructure and product reviews. We combine frontier AI models with researchers who find what everyone else misses. Every engagement is original research, not a checklist run.
Detection & Response
Your next intruder may not be a person. We deploy honeytokens across your environment at scale, so autonomous attackers give themselves away early. We're there when something gets through.
Security Engineering Programs
We stay after the report. We make vibe coding safe to ship, and we harden the agents your team now runs on.
Don't take our word for it
If there's a north star in offensive security in the age of AI, right now, it's probably Calif. I keep following along with their epic team and leadership, and keep finding that they are a fellow reliable and trustable company right now when it comes to discovering vulnerabilities with AI, but also disseminating information responsibly.
Calif successfully breached security to reach critical assets, providing us with invaluable insights to lock down our environment. I highly recommend Calif to any organization serious about identifying and fixing security flaws.
Calif's recent viral blog posts demonstrate a staggering reality: how AI can be leveraged to identify and exploit RCE vulnerabilities within the FreeBSD kernel and classic text editors like Vim and Emacs.
However, even more impressive than their use of AI is the sheer depth of their technical competence. Our team at Google has engaged with Calif on various security assessments, during which they identified weaknesses and helped us harden our mitigations. Their ability to deliver exceptionally high-quality findings makes them an invaluable partner for any high-stakes security project.
It's always a pleasure working with Thai Duong and the entire Calif team. Security testing with an unparalleled level of quality. I don't post a lot, I don't do shout outs a lot but Calif delivers top tier work worthy of recognition.
I just want to say thank you Thai Duong and Calif for consistently scaring the life out of me. This team is the most innovative penetration/security tester I have ever worked with. Over the past 5 years, they have taken 15 years off of my life with their very creative approaches to destroying my faith in any security control that exists....anywhere. Ever. If you want to know the truth, use Calif.
It's important to call out the quality security vendors when we find them. Calif does high-caliber penetration testing with world class researchers!
I rarely do shout-outs or plugs on here, but I wanted to recognize Thai Duong and the team at Calif for the excellent work they do. The security assessment and penetration testing services market is so crowded with startups and incumbents alike -- it's often difficult to find firms that have the technical skills to stand out from the rest. It's great to work with top-tier red-teamers who truly know their craft!
This is... accurate. Thai Duong and the Calif team kill it 10 times out of 10.
We just completed another great red team engagement with Calif - again outstanding work! A good red team engagement is indistinguishable from art and Thai Duong and his team are true artists.
Grateful to call Calif a partner. We've worked with their team for a while on Spark audits, and more recently on hands-on development. They've consistently brought strong technical insight and have been excellent to collaborate with. Partnerships like this make a real difference. Thanks to the Calif team; excited to keep building together. 🙌
Shout out to Thai Duong and the team at Calif 🥷. I love a good pen test to learn new things about your infrastructure 😁
In the Press
The work, as others tell it
Apple races to fix string of security flaws→
Apple struggles to keep pace with AI 'bug' hunters→
Mythos discovers "Squidbleed," a memory leak that's gone undetected since Clinton era→
New "HTTP/2 Bomb" DoS attack crashes web servers in under a minute→
Apple's security has been tough to crack. Mythos helped find a way in→