We develop and deliver offensive capabilities exclusively to democratic governments and established brokers, under strictly defined engagement terms.

Engagement Models

Contract development. You define the target, the platform, the required entry vector and the privilege level to be reached. We conduct the research and deliver the resulting capability, along with the documentation needed to operate and maintain it.

Acquisition of in-house research. We also broker exploits produced by our own research programme. Available capabilities are disclosed only to vetted parties, after the engagement terms are agreed.

Maintenance and re-targeting. Software changes. We port delivered chains to new versions, restore reliability after mitigations are introduced, and extend coverage to additional configurations under ongoing agreements.

What Delivery Includes

  • Working, reliable exploit chain with measured success rates across supported versions.
  • Complete technical documentation: vulnerability class, primitives, exploitation strategy and failure modes.
  • Supported target matrix — versions, architectures and configurations.
  • Reproduction environment and integration notes.
  • Defined support window for maintenance and technical questions.

Terms and Vetting

Every engagement is scoped individually. Before any technical detail is disclosed, we require identification of the end user and confirmation of the intended use. We work exclusively with democratic governments and established brokers, and we decline engagements that fall outside that scope.

All work is covered by written agreement, including confidentiality terms in both directions.


Enquiries from institutional contacts only, from a verifiable corporate or government address: contact@blackstormsecurity.com