Independent security research
Sentinel Zero
A research workflow for turning suspected vulnerabilities into reproducible evidence—or discarding them when the evidence does not hold.
Research position
Do not guess. Prove.
The method begins with a system invariant rather than an automated scanner result. A finding survives only when controlled testing shows a repeatable violation and the report explains both impact and remediation.
This work includes local tooling, audit notes, proof-of-concept tests and remediation reports across web APIs and smart-contract or consensus review exercises.
Validation sequence
From hypothesis to defensible report
- 01
Define the invariant
State the security property that must always hold—ownership, authorization, accounting, contract state or consensus correctness.
- 02
Create a controlled mutation
Change one relevant variable at a time and retain a valid baseline for comparison.
- 03
Test repeatability
Reject findings that cannot be reproduced or whose observed difference does not violate the invariant.
- 04
Build a proof artifact
Use a focused test, code-level demonstration or structured request comparison that another reviewer can inspect.
- 05
Write remediation
Explain the missing control and propose a bounded fix without overstating business impact.
Artifacts in the private research archive
- Invariant and scope notes
- Static-analysis and manual-review records
- Foundry and Python proof tests
- False-positive review
- Severity rationale
- Remediation guidance
Need a security-minded systems review?
Radbit can review authorization boundaries, data handling and workflow risks as part of application architecture. This is scoped separately from certified penetration testing.
Discuss the system boundary