Services
newt lab takes a small number of engagements at a time. The same researchers who write what you read on this site do the client work; there is no separate delivery bench. If what follows fits your problem, write to engagement@newt-lab.com with a short description of the system and the question you want answered.
Pentest
Offensive engagements at research caliber, not checklist depth. We scope by question — “can an attacker holding X reach Y” — rather than by IP count, and the report says what we tried and failed at, not only what worked.
Vulnerability research
Directed research against a product, protocol, or platform you build or depend on — external or sponsored. Findings are reported to you first; disclosure terms are negotiated at engagement time within the bounds of our disclosure policy.
Red team
Adversary-shaped exercises against your detection and response, scoped and de-conflicted with your defenders.
Reverse engineering
Firmware, binaries, protocols, and the undocumented corners of systems you have to trust. Deliverables are working notes, annotated artifacts, and reproducible tooling — not a slide deck.
Training
A first-class offering, not an afterthought. Current and upcoming deliveries are listed on the training page; inquiries go directly to training@newt-lab.com. No platform, no enrollment funnel.
Advisories
Coordinated disclosure as a practice: CVE-numbered advisories with a disclosure clock that is correct to the day, published under the 90+30 / 7-day policy.
Custom research
Retainer-style, sponsored, or direct-client research on questions that do not fit a fixed-scope engagement. The research domains we commit to are kernel (Linux focus), Android OS and framework, mobile apps, baseband, and Wi-Fi chipsets — and we are open to any widely-deployed technology in enterprise or public use.
What we don’t do
The full values framing is in the client-selection policy; the plain-language version:
- We don’t sell surveillance, and we don’t work for vendors whose business is selling it.
- We don’t broker offensive tooling, exploits, or capabilities to undisclosed customers.
- We don’t work for state actors with documented patterns of human-rights abuse, regardless of the stated purpose of the work.
- We don’t accept engagements whose terms would prevent us from warning users under active exploitation.
- We don’t run marketing funnels: no lead scoring, no gated PDFs, no “book a demo”. You write to a person, a person answers.