Back to home

Careers

Work on the browser security problem

There are over 300,000 extensions we keep track of. Most organisations have no visibility into what they are running. We are the team fixing that.

We analyse extensions at scale - real-time network behaviour monitoring, and continuous supply chain scanning across a database of hundreds of thousands of Chrome Web Store extensions. Our analysis pipeline runs advanced agentic AI workflows with human expert verification to produce findings that are accurate enough to act on.

Our research roots go deep - the founding team includes published academic security researchers and engineers who have spent years finding vulnerabilities in browser extensions. That depth shows in the product.

The stack

LanguageTypeScript end-to-end
FrontendNext.js, React 19, Tailwind
Edge runtimeCloudflare Workers
API layertRPC
DatabasePostgres
Analysis pipelineAdvanced agentic AI workflows + human expert review
Monitoring infraContinuous discovery across major extension stores

Everything runs at the edge. No traditional servers, no cold starts, no infrastructure to babysit. The analysis pipeline runs separately from the customer-facing product and is designed to scale horizontally as the extension database grows.

What the engineering looks like

The discovery pipeline picks up extension updates and version changes in near real-time and feeds them into analysis automatically. The analysis runs agentic AI workflows that reason about extension behaviour across versions - detecting meaningful changes, not just permission diffs.

The fleet monitoring product gives enterprise security teams a live view of every extension across their managed devices, with configurable policy enforcement that pushes through their existing MDM. The API is public and documented, and customers build on top of it for SIEM ingestion and custom alerting workflows.

There is interesting unsolved work in detection accuracy, pipeline latency, and the scoring methodology. If that kind of problem interests you, there is plenty of it here.

Open roles

No formal listings right now. We are interested in people who are exceptional at any of the following.

Security research / threat analysis

You have found vulnerabilities in real software. You understand what malicious JavaScript looks like at the AST level, how obfuscation techniques work, and what makes a finding actionable vs. noise.

Full-stack engineering (TypeScript)

You care about performance, type safety, and clean API boundaries. You have shipped production SaaS and you are comfortable owning a feature from database schema to UI.

Security-focused sales / GTM

You understand the enterprise security buying cycle. You can run a technical proof of concept, navigate procurement, and talk credibly to both CISOs and the engineers who report to them.

Interested?

Send us a note about what you have built and what you are looking for. No recruiters, no cover letters.

Get in touch