Gatofox Lab

Independent security research

Offensive security research, carried to demonstrated impact.

Gatofox Lab is an independent research practice working authorized vulnerability discovery across web applications, APIs, and payment infrastructure. Every finding is reproduced on purpose-built instrumentation and disclosed through the coordinating program that authorizes it.

Practice

Where the research is focused

The lab works the classes where a flaw crosses a real boundary — identity, tenancy, money, or the host — rather than surface-level issues.

  • Authentication, session and federation boundaries
  • Authorization and multi-tenant isolation
  • Payment flows and business-logic integrity
  • Parser and protocol evasion
  • Browser, client and API attack surface
  • Cloud, container and supply-chain exposure

Verification

An independently verifiable record

The lab's work is disclosed through Intigriti, a European coordinated-disclosure platform. Accepted findings are exclusively Critical and High severity. The researcher profiles below are public and maintained by the platform, not by us — they are the record, and they can be checked directly.

Method

Instrumentation built for reproduction

A finding is only worth reporting if it can be reproduced exactly. The lab builds and maintains its own instruments so a reproduction behaves like the session it models — at the transport layer, in the browser, and across out-of-band channels.

Instrumented browser

A purpose-built Chromium under programmatic control, so findings are reproduced in a real rendering and JavaScript environment rather than a synthetic client.

Request-fidelity HTTP client

TLS and HTTP/2 fingerprint parity with real browsers, so a scripted reproduction is indistinguishable at the transport layer from the session it reproduces.

Out-of-band interaction capture

Self-hosted multi-protocol callback infrastructure across HTTP, DNS, SMTP and TLS, correlated per canary — the basis for verifying blind and asynchronous classes.

Agent-assisted research harness

A fleet of task-scoped language-model agents composed from a versioned prompt library, each operating under an explicit, externally anchored authorization contract that bounds what it may touch.

Authorization and disclosure

Research inside an explicit mandate

Offensive capability is only legitimate inside the permission that authorizes it. The lab treats that boundary as a hard operating constraint, not a disclaimer.

  • Testing is performed exclusively against assets named in the published scope of a program that authorizes the engagement, under its rules of engagement.
  • Findings are disclosed through the coordinating platform and are never published, traded, or disclosed to third parties.
  • Access obtained during research is limited to what demonstrates the vulnerability, and data encountered is never retained beyond the evidence a report requires.
  • Every automated component of the harness inherits the same scope boundary as the researcher operating it, anchored to a written authorization artifact rather than an assumed permission.

People

Who runs the lab

Both principals are named, identifiable researchers with an indexed academic record that predates the lab.

Alice Sippert
Security Research Lead

Conducts the lab's vulnerability research and builds and operates the platform it runs on — the instrumented browser, the request-fidelity client, the out-of-band infrastructure, and the agent harness.

Psychoanalyst. Degree in Psychology from the Federal University of Rio Grande do Sul (UFRGS), with psychoanalytic training at the Associação Psicanalítica de Porto Alegre.

Bruna Rabello de Moraes
Organization & Research

Responsible for the lab's organizational side — engagement administration, and the commitments the practice makes to the programs it works with.

Psychologist (Universidade de Passo Fundo, 2016). MSc in Psychoanalysis: Clinic and Culture (UFRGS, 2019). Doctoral candidate in Social and Institutional Psychology at UFRGS, and a certified specialist in Clinical Psychology (Federal Council of Psychology, 2022).

Academic record

Prior to the lab, both principals published in peer-reviewed psychology journals, as co-authors of one another. The work is indexed and permanently resolvable by DOI — it is offered here as an identity and provenance anchor, not as a security credential.

Contact

Get in touch

For coordinated disclosure, program invitations, or questions about the lab's research practice.