Research Areas

Cyfinoid Research focuses on security problems where trust, automation, and attacker behavior collide. We study how modern systems are built, connected, and operated, then turn that research into public tooling, writeups, conference talks, and hands-on training.

Our current active research priorities are Software Supply Chain Security, Cloud Security, and AI usage and security. These are the areas where we are actively investing in new tools, public material, and deeper technical exploration.

Android security remains an important part of our history and previous work. We are keeping that material visible as an older research area because it produced useful tools, labs, and ideas, but it is no longer one of our primary active research pillars.

Active Research Areas

Software Supply Chain

The trust relationships that shape modern software delivery from developer workstations security, repositories, tokens, CI/CD pipelines, SAST tooling, package ecosystems, artifacts, provenance, deployment systems to cloud environments

Cloud Environments

How attackers discover, chain, and abuse trust boundaries in cloud environments across identities, storage, metadata, orchestration, automation, and service-to-service relationships.

AI: Usage & Security

How AI systems are being adopted in real workflows and where that adoption creates new security, privacy, governance, and trust problems.

Earlier Research Area

Android

Android security was one of Cyfinoid’s earlier focus areas. That work led to hands-on research, internship projects, training material, and tools that remain useful to mobile security practitioners.

While Android is no longer one of our main active research priorities, we are keeping the material available as an archive of previous work and a record of what shaped our current approach to research-driven training.

How Research Shows Up

  • Public tools and experiments
  • Blog posts, writeups, and practical notes
  • Conference talks, workshops, and training material
  • Research-informed consulting and private engagements

Research Philosophy

We prefer work that is practical, testable, and useful outside a slide deck. That often means building tools, creating reproducible labs, publishing explainers, and focusing on problems that sit at the intersection of offensive understanding and defensive decision-making.

If you want to collaborate, invite us to speak, or discuss research-led training or consulting, contact us.

Scroll to Top