Closed beta · waitlist open

Find it.
Prove it. File it.

Arbiter finds web vulnerabilities and verifies them in Chrome. Aletheia reverse-engineers binaries and proves them with Z3. Rust MCP servers for people who ship evidence, not alerts.

First 7 days free. Cancel anytime. No obligation.

See Arbiter See Aletheia

85/85
Firing Range
421
MCP Tools
2
Disclosures
100%
Rust

Used to disclose bugs in Anthropic and Cloudflare open source.

Two engines

What you get

A web testing engine and a binary analysis engine. Same discipline: infer constraints, verify the hit, export the evidence.

Arbiter logo

Arbiter

Traffic → state graph → Chrome proof → bounty report
For pentesters and bug bounty hunters

Import a HAR or proxy session. Arbiter infers authorization and ordering constraints, searches 52 vulnerability classes, verifies every hit in headless Chrome, and exports a HackerOne-ready report.

Constraint Inference Browser Verification HTTP/2 Races Bounty Reports
268
MCP Tools
52
Vuln Classes
85/85
Firing Range
100%
Chrome Verified
See Arbiter product page
Aletheia logo

Aletheia

Binary → SSA IR → typed C → Z3 witness
For reverse engineers and malware analysts

Load PE, ELF, or Mach-O. Aletheia disassembles four architectures, lifts to a 43-opcode SSA IR, decompiles to typed C, and proves 14 CWE classes with concrete witnesses and SARIF.

SSA Decompilation Concolic Proofs Hybrid Fuzzing Taint Analysis
153
MCP Tools
14
CWE Classes
100%
CTF Detection
4
Architectures
See Aletheia product page
Bring your own agent

The lab your agent plugs into.

Both engines are MCP servers. Point Claude Code, Codex CLI, Grok Build, or OpenCode at them. No second model bill — you already have the tokens. You pay for the tools.

FIG. 01 Agent → MCP → engine → evidence 421 tools · typed I/O
Why this exists

Agents can reason. They still need a lab.

Scanners spray payloads. GUIs don’t compose. The next model won’t fail because it can’t imagine a bug — it’ll fail because it can’t inspect the right state, verify the result, and stay in scope.

Structured tools

421 MCP tools with typed inputs and JSON outputs. No GUI scraping, no screenshot-and-pray. The agent spends tokens on the finding, not the plumbing.

Verification first

Chrome proof, Z3 witnesses, screenshots, SARIF. No “potential” or “likely”. If it ships, a human can replay it.

Rust, from scratch

No wrappers around Burp or Ghidra. Pure Rust, deterministic output, scope gates, audit logs. Same input, same output, every time.

The thesis: the bottleneck is no longer reasoning — it’s instrumentation, verification, and control.

Proof

Real bugs. Responsibly disclosed.

Arbiter has been used to find and report vulnerabilities in production open source. Not a demo. Not a benchmark-only claim.

Disclosure • 2026

Anthropic Open Source

Vulnerability discovered in Anthropic’s open source tooling. Responsibly disclosed and acknowledged by their security team.

Responsibly Disclosed
Disclosure • 2026

Cloudflare Open Source

Security issue identified in Cloudflare’s open source infrastructure tooling. Reported through their responsible disclosure program.

Responsibly Disclosed
Benchmark

Google Firing Range

100% detection across all 85 endpoints in Google’s XSS Firing Range — the standard benchmark for detection accuracy.

85/85 Verified
Early access

Get in before the beta opens.

First 7 days free. Cancel anytime — no obligation. Arbiter Pro $39/mo. Aletheia Pro $29/mo. Your existing agent subscription.

Questions? Want to collaborate?

[email protected]