Kairo works with OpenAI through Daybreak, which gives security research teams access to frontier models for security research under a defined set of conditions. The research question is narrow and increasingly urgent: what does an application look like to an attacker who has an agent, rather than an afternoon?
The research
Agentic attackers do not behave like scanners. They read documentation, chain endpoints that are individually harmless, use a product’s own automation against it, and give up on dead ends far faster than a signature-based tool ever does. Modelling that behaviour is the difference between a report full of known CVEs and a report describing how your application specifically comes apart.
The constraints
- Every environment tested is one a customer has authorised in writing.
- Simulations run against a shadow environment, not production.
- Findings are private to the organisation that owns the system.
- Capability research does not leave the programme as a published attack tool.
The output that reaches a customer is deliberately unglamorous: a reproduced finding, on the line of code that causes it, in the pull request that introduced it.