Cybersecurity Research
GreyTheory Research
A learner-first, local and human-governed Security Research Operating System for AI-native bug bounty and authorised testing.
Outcome
Guides a researcher from explanation through safe local practice, evidence and human assessment while keeping programme authority, public intelligence and eventual live execution structurally separate.
Media
Select any frame to enlarge
Guided research workbench
Mission Control starts with a bounded learning objective, explains what the advisory coach can and cannot do, and keeps the Apache-2.0 Research Preview and LOCAL_FIXTURE boundary visible throughout.
AI-native learning
Each topic owns its complete lesson context. Selecting Prompt-injection boundaries replaces the note, principles, traditional and AI lenses, checks, roadmap and official learning sources together. The four-stage route moves from spotting the boundary to mapping instruction flow, running paired local controls and explaining the evidence limit. Self-attestation is visibly separated from mastery.
Read-only intelligence
OSV, CISA KEV, FIRST EPSS, NVD and GitHub Advisories are mapped behind identifier-only, read-only contracts. Bug-bounty account connectors remain dark and no provider request is enabled.
Research ledger
The earlier Research Ledger remains a first-class case view inside the broader learner-first workbench rather than being discarded as the interface evolves.
Project identity
The repository-owned gate mark expresses the product boundary: authority is checked before research can proceed. The older GreyTheory AI social banner was deliberately excluded because its framing is no longer current.
Case study
The problem
Security research repeatedly blurs what a programme authorised, what a tool observed, what an experiment proved and what a person or model merely believes follows. GreyTheory makes those distinctions structural so automation can accelerate reasoning without turning fluent inference into evidence or authority.
Three planes, one research path
Authority compiles programme rules into versioned contracts and blocks out-of-scope work. Signal organises assets, observations and falsifiable hypotheses. Judgement plans controlled experiments, validates receipts, assembles evidence and links every report claim back to support. Each session must end in evidence, a report or a reusable lesson rather than an untraceable chat conclusion.
What is implemented
The repository contains the offline trust kernel, programme registry and multi-source compiler, structured research records, a complete synthetic two-account training slice, a raw/redacted evidence vault, validator-issued receipts, a claim-evidence report matrix, 12 versioned vulnerability cards, an acyclic skill graph and transparent hypothesis ranking. The learner-first workbench now exposes 24 interactive trajectory lessons, topic-owned beginner-to-transfer roadmaps, thirteen navigable journeys, a safe local case and identifier-only public-intelligence contracts without enabling external requests.
Why it stays human-governed
A model may organise rules, propose hypotheses, challenge weak claims and draft from supported evidence. It cannot verify scope, reinterpret a denial, create proof, contact a programme, submit a report or disclose a vulnerability. Approval remains bound, expiring, single-use and owned by the researcher.
Where it is now
GreyTheory is an Apache-2.0 open-source research preview with an interactive learner-first shell and an offline authority/evidence kernel. The current next product gates are sequential-keyboard acceptance, same-origin persisted-path verification and clean-user Windows packaging. The posture remains LOCAL_FIXTURE: external intelligence fetching, accepted Ubuntu passive-worker operation, VPS deployment, live target interaction, findings, disclosure, submission and bounty outcomes remain unavailable or unclaimed.
Verified architecture
System map
Technology
- Python
- React
- Apache-2.0
- AI security
- Security research
- Provenance
- Deterministic validation
- Public intelligence contracts
- Skill graph
- Local-first
Scope and boundaries
The offline authority, research, evidence, reporting, learning and transparent-ranking layers are implemented under a LOCAL_FIXTURE ceiling. Ranking orders unproven hypotheses; it is not probability, severity, proof or authority to execute. Network workers, live target testing, submissions and bounty outcomes are not built or claimed.