Researching out of the kotak.
Sandboxes, escapes, and security at the edges of isolation — small company, sharp questions.
01 — Research
Four corners of the same kotak: how things get locked in, and how curiosity gets out.
Isolation boundaries — browsers, VMs, containers, WASM, agent runtimes. What the box claims to hold, and what it actually holds.
Escape paths, privilege edges, and the quiet gaps between policy and mechanism. We study how boxes fail so builders can close them.
Practical R&D for people who live in threat models: tooling, adversarial thinking, and findings that survive contact with reality.
Adjacent oddities — new primitives, weird stacks, ideas that don’t fit a neat product roadmap but move the field forward.
02 — Approach
Short loops. Clear artifacts. Prefer a sharp demo over a long deck.
Name the boundary, the trust assumptions, and what’s at stake if it breaks.
Probe, instrument, and try to leave — then write down what held and what didn’t.
Notes, patches, and reproducible paths — useful to researchers, not just slides.
03 — Contact
Collabs, weird bugs, sandbox questions — we read mail.