
Security research and consulting firm offering audits, cryptography review

Security research and consulting firm offering audits, cryptography review
The Entire Cybersecurity Market, One Prompt Away
Connect your AI assistant to ... tools and ... vendors. Ask anything about the cybersecurity market.
Trail of Bits is a security research and consulting firm founded in 2012 that performs security audits and builds open-source security tools. The company works across application security, cryptography, blockchain, AI/ML, low-level systems, and software supply chain security. Engagements include code review, penetration testing, and cryptography assessments, with findings manually validated by engineers rather than generated purely from automated scans. Reports typically explain the root cause of each finding and a path to remediation, and many are published publicly. Engagements often include custom tooling, such as Semgrep or CodeQL rules and fuzzers, intended to help clients catch similar issues in the future. Trail of Bits maintains over 100 open-source projects, including Slither, Echidna, and Manticore for smart contract and program analysis, as well as the Building Secure Contracts guide. The company also developed iVerify, a mobile security tool, and contributed to osquery, an endpoint monitoring tool later moved to the Linux Foundation. The firm has participated in DARPA programs including the Cyber Grand Challenge and the AI Cyber Challenge (AIxCC), where it built autonomous vulnerability discovery and patching systems. It has also worked with government-related entities such as ARPA-H and the UK's Frontier AI Taskforce, and has been referenced in Forrester's cybersecurity consulting market reports. Clients span sectors requiring security assessments of software systems, blockchain protocols, and AI/ML systems. The company operates as an independent consulting firm and does not appear to be part of a larger corporate group.