Find it.
Prove it. File it.
Arbiter finds web vulnerabilities and verifies them in Chrome. Aletheia reverse-engineers binaries and proves them with Z3. Rust MCP servers for people who ship evidence, not alerts.
First 7 days free. Cancel anytime. No obligation.
Used to disclose bugs in Anthropic and Cloudflare open source.
HAR imported. PE loaded. The lab starts from evidence, not guesses.
What you get
A web testing engine and a binary analysis engine. Same discipline: infer constraints, verify the hit, export the evidence.
Arbiter
Import a HAR or proxy session. Arbiter infers authorization and ordering constraints, searches 52 vulnerability classes, verifies every hit in headless Chrome, and exports a HackerOne-ready report.
Aletheia
Load PE, ELF, or Mach-O. Aletheia disassembles four architectures, lifts to a 43-opcode SSA IR, decompiles to typed C, and proves 14 CWE classes with concrete witnesses and SARIF.
The lab your agent plugs into.
Both engines are MCP servers. Point Claude Code, Codex CLI, Grok Build, or OpenCode at them. No second model bill — you already have the tokens. You pay for the tools.
Claude Code, Codex CLI, Grok Build, and OpenCode sit on the top rail. They call 421 typed MCP tools. Those tools fan into Arbiter's state-graph engine and Aletheia's SSA engine, which converge on Chrome proofs, Z3 witnesses, and exportable reports.
Agents can reason. They still need a lab.
Scanners spray payloads. GUIs don’t compose. The next model won’t fail because it can’t imagine a bug — it’ll fail because it can’t inspect the right state, verify the result, and stay in scope.
Structured tools
421 MCP tools with typed inputs and JSON outputs. No GUI scraping, no screenshot-and-pray. The agent spends tokens on the finding, not the plumbing.
Verification first
Chrome proof, Z3 witnesses, screenshots, SARIF. No “potential” or “likely”. If it ships, a human can replay it.
Rust, from scratch
No wrappers around Burp or Ghidra. Pure Rust, deterministic output, scope gates, audit logs. Same input, same output, every time.
The thesis: the bottleneck is no longer reasoning — it’s instrumentation, verification, and control.
Real bugs. Responsibly disclosed.
Arbiter has been used to find and report vulnerabilities in production open source. Not a demo. Not a benchmark-only claim.
Anthropic Open Source
Vulnerability discovered in Anthropic’s open source tooling. Responsibly disclosed and acknowledged by their security team.
Responsibly DisclosedCloudflare Open Source
Security issue identified in Cloudflare’s open source infrastructure tooling. Reported through their responsible disclosure program.
Responsibly DisclosedGoogle Firing Range
100% detection across all 85 endpoints in Google’s XSS Firing Range — the standard benchmark for detection accuracy.
85/85 VerifiedGet in before the beta opens.
First 7 days free. Cancel anytime — no obligation. Arbiter Pro $39/mo. Aletheia Pro $29/mo. Your existing agent subscription.
Questions? Want to collaborate?
[email protected]