Calif
Calif is a Palo Alto-based boutique cybersecurity firm that combines elite human security researchers with frontier AI models (Anthropic Claude Mythos, OpenAI) to perform penetration testing and vulnerability research for enterprise technology clients.
- Company typePrivate
- Founded2020
- HeadquartersSunnyvale, United States
- Headcount51–100
- GTM typeB2B
- OfferingServices
What Calif does
Calif is a Palo Alto-based cybersecurity consulting firm specializing in AI-assisted vulnerability research and penetration testing for enterprise technology clients. Founded by Thai Duong (former Google security engineer and co-discoverer of the BEAST, CRIME, and POODLE SSL attacks) and An Trinh, the firm combines elite human security researchers with frontier AI models — notably Anthropic's Claude Mythos and OpenAI's GPT models — to identify critical vulnerabilities in widely deployed software. Its two branded service lines are "attack.sh" (AI-augmented vulnerability discovery and exploit development) and "defend.sh" (translation of vulnerability findings into production-grade defensive systems).
The firm operates a professional services model with quote-based enterprise pricing, engaging directly with clients on red team engagements, penetration tests, and vulnerability research collaborations. Its named customer roster includes Google, Anthropic, OpenAI, CoreWeave, Wiz, Cursor, Chainguard, Lightspark, Cresta, and a portfolio of Vietnamese financial institutions. Calif is a core partner in OpenAI's Daybreak/Patch the Planet initiative and Anthropic's Project Glasswing, and is an initial recipient of OpenAI's $10 million Trusted Access for Cyber API credits program.
Calif has no disclosed venture funding and operates as a founder-led boutique firm in the 11-50 employee range. Its market positioning rests on individual researcher credibility (multiple Pwnie Awards, advisory relationships with Michał Zalewski and Parisa Tabriz), high-profile public vulnerability disclosures including the 29-year-old Squid Proxy flaw (Squidbleed/CVE-2026-47729) and the first Apple M5 kernel Memory Integrity Enforcement bypass, and co-development relationships with frontier AI labs. Go-to-market is hybrid: enterprise field sales for paid engagements layered with community-led content marketing via technical blog posts, conference talks, and earned media that drives inbound demand.
Calif firmographics
Firmographics- Name
- Calif
- Legal name
- Calif
- Website
- https://calif.io
- Company type
- Private
- Founded year
- 2020
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- Calif is a Palo Alto-based boutique cybersecurity firm that combines elite human security researchers with frontier AI models (Anthropic Claude Mythos, OpenAI) to perform penetration testing and vulnerability research for enterprise technology clients.
- Ownership category
- akta.pro rank
Calif industry classification
Industry- Product category
- Cybersecurity Consulting and Penetration Testing Services
- NAICS
- Security Systems Services (56162), Investigation and Security Services (5616), Scientific Research and Development Services (5417)
- SIC
- Services-Engineering, Accounting, Research, Management (8700), Services-Engineering Services (8711)
- akta.pro primary industry
- Penetration Testing Platforms (PTaaS) (HDADAHAG)
- akta.pro secondary industries
- Breach & Attack Simulation (BAS) (HDADAHAD), Application Security Engineering (DevSecOps, AppSec Remediation) (BPAEAFAI)
Keywords
Where Calif is headquartered
LocationHeadquarters
- HQ city
- Sunnyvale
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Calif business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales
Revenue model
- Security Assessment and Penetration Testing Services: Professional red teaming and security assessment engagements for enterprise clients. Testimonials indicate high-value, specialized security testing engagements with top-tier clients including Google, financial institutions, and AI companies.
- Vulnerability Research Partnerships: Collaborative vulnerability research initiatives with AI companies (Anthropic, OpenAI) and major open-source foundations to discover and remediate security flaws in critical infrastructure.
Go-to-market motion2 records
Distribution channels1 record
Marketing channels6 records
Calif product offering
Product offeringCore offering
Calif is a security research firm offering two integrated professional services: attack.sh for AI-assisted vulnerability discovery and proof-of-concept exploit development using frontier AI models, and defend.sh for translating findings into hardened production defenses. The firm performs red team engagements, penetration testing, and collaborative vulnerability research for enterprise technology clients.
Product overview
Calif is a security research firm offering two integrated services: attack.sh for AI-powered vulnerability discovery using frontier models from Anthropic and OpenAI, and defend.sh for translating findings into hardened defenses. The company conducts red team and penetration testing engagements, focusing on frontier vulnerability research that identifies critical flaws in widely-used software before malicious actors can exploit them.
Differentiator
Problem solved
Functional benefit
Products and services
- attack.sh
Quantifiable outcome
- Over 10,000 vulnerabilities discovered in open-source software using AI-augmented research
- +4 more outcomes
Companies that use Calif
Customer profileNamed customers9 records
Segments2 records
Ideal customer profiles2 records
Calif technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability3 records
Feature3 records
Calif partnerships and signals
Strategic signalPartnerships
Six partnerships are on record, tiered core and secondary.
- OpenAIcoreCalif participates in OpenAI's Daybreak cybersecurity initiative and Patch the Planet program as a security engineering partner. They contribute vulnerability research expertise alongside Trail of Bits and provide triage and coordinated disclosure support for open-source projects including cURL, Python, Go, Sigstore, and others. Calif also received API credits through OpenAI's Cybersecurity Grant Program as part of the Trusted Access for Cyber initiative.
- Trail of BitscoreCalif co-founded the Patch the Planet initiative with Trail of Bits as part of OpenAI's Daybreak program. Both companies provide security engineering support, with Trail of Bits contributing human expert review alongside AI-assisted vulnerability research to help open-source maintainers identify and remediate security flaws.
- HackerOnesecondaryCalif collaborates with HackerOne in the Patch the Planet initiative to support vulnerability classification and coordinated disclosure for open-source projects. HackerOne provides platform capabilities for managing bug bounty programs and responsible disclosure processes.
- OpenAI Trusted Access for Cyber ProgramcoreCalif is an initial recipient of OpenAI's $10 million API credits grant program as part of the Trusted Access for Cyber initiative, alongside Socket, Semgrep, and Trail of Bits. This program provides access to GPT-5.4-Cyber model capabilities to strengthen cyber defense capabilities for under-resourced defenders.
- AnthropiccoreCalif uses Anthropic's Claude Mythos AI model (as part of Project Glasswing) for vulnerability discovery research. They demonstrated the model's capabilities by discovering a macOS kernel exploit on Apple M5 chips and a 29-year-old Squid Proxy vulnerability. Calif's research helped showcase Mythos's effectiveness in finding critical security flaws.
- GooglesecondaryGoogle's security team has engaged with Calif on various security assessments and vulnerability research. Security researcher Andy Nguyen praised Calif's technical competence and high-quality findings. The relationship is mutually beneficial for talent exchange and research collaboration.
Scale indicators3 records
Recent moves6 records
Expansion highlights5 records
Calif competitors and assessment
Company assessmentDirect peers
- Trail of Bits: Elite security research and consulting firm specializing in applied cryptography, blockchain, and AI/ML security. Direct peer to Calif — co-founded OpenAI's Patch the Planet initiative alongside Calif, both are initial recipients of OpenAI's Trusted Access for Cyber grant, and both serve enterprise technology clients with high-end security research engagements.
- Semgrep: Application security platform combining code analysis with AI-assisted vulnerability detection. Direct peer to Calif — both are initial recipients of OpenAI's $10M Trusted Access for Cyber program, both target AI-augmented code security for enterprise developer teams, and both compete for the same budget line item (AppSec / DevSecOps).
- Socket: Supply chain security company using AI to detect malicious packages and vulnerabilities in open-source dependencies. Direct peer to Calif — both are initial OpenAI Trusted Access for Cyber recipients, both focus on securing open-source ecosystems with AI, and both serve similar enterprise technology customers.
- Bishop Fox: Top-tier offensive security firm specializing in penetration testing, red teaming, and vulnerability research for Fortune 500 and enterprise technology clients. Direct peer to Calif in boutique pentesting — comparable positioning as a high-end, technically elite pen test vendor serving similar technology and financial enterprise customers.
- Cure53: Berlin-based boutique security research firm specializing in penetration testing and security audits for software, browsers, and web applications. Direct peer to Calif in elite boutique security research — both serve high-end technology clients (browser vendors, open-source foundations) and operate with small teams of world-class researchers.
- NetSPI: Large-scale penetration testing and attack surface management platform serving enterprise customers across financial services, healthcare, and technology. Direct peer to Calif in penetration testing services — broader portfolio and larger scale but competes for the same enterprise pen-testing RFPs.
- Synack: Penetration testing platform combining a vetted researcher community with platform-enabled delivery for enterprise security testing. Direct peer to Calif in elite pen-testing — both target enterprise security buyers, both emphasize researcher quality, and both compete in the security testing services category.
Broad incumbents
- NCC Group: Global, publicly-listed cybersecurity consulting firm offering a broad portfolio of services including penetration testing, red teaming, threat intelligence, and managed security. Broad incumbent peer to Calif — much larger scale and broader service mix, but competes in the same enterprise pentesting RFP market, particularly for financial services and large technology customers.
- HackerOne: Bug bounty and vulnerability disclosure platform connecting enterprises with a global community of security researchers. Broad incumbent peer to Calif — Calif collaborates with HackerOne in the Patch the Planet initiative, and the platforms compete for similar security testing / vulnerability discovery budgets at large enterprises.
- Mandiant (Google Cloud): Google-owned incident response and cyber threat intelligence firm with a large security consulting practice including red team, pen testing, and vulnerability research. Broad incumbent peer to Calif — both serve Google's security ecosystem (per Calif's customer roster) and compete for the same enterprise security testing budgets at scale.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks5 records
Key highlights7 records
Customer concentration
Calif social profiles
Digital presenceCalif financial estimates
Financial estimateRevenue estimate
Valuation estimate
Calif leadership team
Management profileNumber of profiles
Profiles4 records
Calif funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Calif M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Calif
What does Calif do?
Calif is a security research firm offering two integrated professional services: attack.sh for AI-assisted vulnerability discovery and proof-of-concept exploit development using frontier AI models, and defend.sh for translating findings into hardened production defenses. The firm performs red team engagements, penetration testing, and collaborative vulnerability research for enterprise technology clients.
Is Calif a public or private company?
Calif is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Calif founded?
Calif was founded in 2020. It employs 51 to 100 people.
Where is Calif based?
Calif is headquartered in Sunnyvale, United States, in the North America region.
How does Calif make money?
Two revenue lines are on record. Security Assessment and Penetration Testing Services are the primary driver. The others are vulnerability Research Partnerships.
Who are Calif's main competitors?
Direct peers on record are Trail of Bits, Semgrep, Socket, Bishop Fox, Cure53, NetSPI and Synack. Broad incumbents are NCC Group, HackerOne and Mandiant (Google Cloud).
Does Calif have an API?
No public API is recorded for Calif.
What industry is Calif in?
Calif's product category is Cybersecurity Consulting and Penetration Testing Services. Its primary akta.pro industry code is HDADAHAG, Penetration Testing Platforms (PTaaS), with a secondary code of HDADAHAD, Breach & Attack Simulation (BAS). Its NAICS code is 56162 and its SIC code is 8700.