About Yaamlabs

Yaamam is the watch of the night. Yaamlabs is an operator-led security and engineering studio: we find the vulnerabilities that matter, build the systems that resist them, and red-team the AI our clients deploy.

About Yaamlabs

Yaamam is the watch of the night. Yaamlabs is an operator-led security and engineering studio: we find the vulnerabilities that matter, build the systems that resist them, and red-team the AI our clients deploy.

About Yaamlabs

Yaamam is the watch of the night. Yaamlabs is an operator-led security and engineering studio: we find the vulnerabilities that matter, build the systems that resist them, and red-team the AI our clients deploy.

Who we are

AsmallteamofoperatorsworkingfromVellore,India,withclientsworldwide.Noaccountmanagers,nojuniorbenchtheengineerwhofindsthebugwritesthereport,andeveryfindingshipswithaworkingproof.

AsmallteamofoperatorsworkingfromVellore,India,withclientsworldwide.Noaccountmanagers,nojuniorbenchtheengineerwhofindsthebugwritesthereport,andeveryfindingshipswithaworkingproof.

AsmallteamofoperatorsworkingfromVellore,India,withclientsworldwide.Noaccountmanagers,nojuniorbenchtheengineerwhofindsthebugwritesthereport,andeveryfindingshipswithaworkingproof.

Operator-led

Everyone on an engagement is doing the work. There is no layer between you and the person at the keyboard.

Operator-led

Everyone on an engagement is doing the work. There is no layer between you and the person at the keyboard.

Small by design

We stay small so the people who scope the work are the people who run it, and the people who run it write it up.

Small by design

We stay small so the people who scope the work are the people who run it, and the people who run it write it up.

Vellore, working worldwide

Based in Vellore, India, across time zones with startups, scale-ups, banks, health networks and DeFi protocols.

Vellore, working worldwide

Based in Vellore, India, across time zones with startups, scale-ups, banks, health networks and DeFi protocols.

Our values

What we hold to

What we hold to

What we hold to

Four things we will not trade away, on any engagement, for any client.

The finder writes it up

The engineer who finds the bug writes the report. Nothing is handed to a writer who was never in the system.

Proof over severity

A rating without a reproduction is an opinion. Every finding we report ships with a proof that runs.

Dense green forest seen through mist

Nothing held back

Findings reach your channel as they are confirmed. Anything critical is reported within the hour, not saved for the last day.

Your name stays yours

NDA and PGP on request. Client names and findings stay undisclosed unless a client asks us to publish.

The finder writes it up

The engineer who finds the bug writes the report. Nothing is handed to a writer who was never in the system.

Proof over severity

A rating without a reproduction is an opinion. Every finding we report ships with a proof that runs.

Dense green forest seen through mist

Nothing held back

Findings reach your channel as they are confirmed. Anything critical is reported within the hour, not saved for the last day.

Your name stays yours

NDA and PGP on request. Client names and findings stay undisclosed unless a client asks us to publish.

The finder writes it up

The engineer who finds the bug writes the report. Nothing is handed to a writer who was never in the system.

Proof over severity

A rating without a reproduction is an opinion. Every finding we report ships with a proof that runs.

Dense green forest seen through mist

Nothing held back

Findings reach your channel as they are confirmed. Anything critical is reported within the hour, not saved for the last day.

Your name stays yours

NDA and PGP on request. Client names and findings stay undisclosed unless a client asks us to publish.

On the record

What is already on the record

What is already on the record

0+

0+

CVEs credited

0+

0+

CVEs credited

0

0

Years in the field

0

0

Years in the field

0+

0+

Engagements

0+

0+

Engagements

0

0

Case studies

0

0

Case studies

What we do

One team, three disciplines

One team, three disciplines

The same people run all three. Offensive security finds what is wrong, product engineering builds what resists it, and the AI-native work covers the systems being shipped right now.

Offensive security

Product engineering

AI-native systems

Offensive security

Web, mobile and API penetration testing. Cloud, Kubernetes and smart-contract audits. Red team engagements and source-code review.

Offensive security

Web, mobile and API penetration testing. Cloud, Kubernetes and smart-contract audits. Red team engagements and source-code review.

Product engineering

Web apps, platforms and API architecture. AWS infrastructure and CI/CD. Auth, secrets handling and detection design.

Product engineering

Web apps, platforms and API architecture. AWS infrastructure and CI/CD. Auth, secrets handling and detection design.

AI-native systems

RAG and agent architecture. LLM red teaming and prompt-injection testing. Evals, guardrails and model governance.

AI-native systems

RAG and agent architecture. LLM red teaming and prompt-injection testing. Evals, guardrails and model governance.