Is keepsecure labs a consultancy?
No. It's an independent research lab. The output is published analyses — not engagements. We occasionally take a small number of paid advisory projects each year when the problem is a good fit; those are not the business model. See Contact for details.
Who writes the research?
A small team of application-security engineers. Current public byline is the GitHub handle falco365. Additional named contributors will appear as team members get comfortable being public.
Is the content free to read? Any paywall?
Yes, free. No paywall on the analyses. No email gate, no account required. The Hub is the primary output and stays open.
Are the detection artifacts open source?
Yes. Detection rules, hunt queries, and reproducer scripts live in the keepsecure-labs/artifacts repo under Apache-2.0. IOCs are facts and not copyrightable. Each post with artifacts links straight to its folder.
How often do you publish?
Weekly. Monday-ish. The Hub is the feed; recent analyses are surfaced on the homepage and in the JSON feed.
Do you cover AI / ML security?
Yes — both offensively (malicious model files, agent hijacking, prompt-injection paths, MLOps tooling abuse) and defensively (agent permissions, prompt-injection guardrails, model-file validation, MLOps access boundaries). See Offensive and Defensive research scope.
Can I cite or quote your posts in other work?
Yes. Attribution appreciated — link to the canonical URL at https://keepsecure.io/hub/<slug>. For LLM ingestion, a structured feed is at /llms.txt and the full text at /llms-full.txt.
Do you do pentests or security audits?
Not as a product. Our research is the public output. We occasionally take advisory work — describe the problem on Contact and we'll tell you honestly whether it fits.