A note from the founder
Why we are giving the writing and the audit tool away for free, and what I am actually trying to build here — a founder's note from Komal Mishra.
I should start by admitting something, because it shapes everything that follows: I am not the best hacker on this team. I am not close. I sit next to people who can read a packet capture the way other people read a menu, and I have watched one of them take apart a login form in the time it took me to refill a coffee.
What I have instead is the thing that got me into this in the first place, and has not worn off once: I find it thrilling. The moment when a system does something its builders never intended, and you can see exactly why — the assumption they made, the boundary they forgot to check — is the most fun I have ever had with a computer. I did not come from security. I came to it sideways, late, and slightly intimidated. I stayed because nothing else has held my attention like this.
The part that bothered me
The further in I got, the more I noticed how much of this field is gated — not maliciously, just structurally.
The good training costs more than a month of most people's rent. The free material is either a firehose of disconnected tutorials or a wall of jargon that assumes you already know the thing you came to learn. Certifications cost hundreds of dollars to attempt. And the labs — the part that actually turns reading into skill — are usually the most expensive piece of all.
I kept meeting people who were curious, capable, and stuck. Not stuck because they lacked the aptitude. Stuck because the on-ramp cost more than they had, or because every guide started at step forty.
That gap is the whole reason this studio exists.
What we decided to do about it
We are five people, self-funded, with no investors to answer to, which means we get to make decisions that are merely sustainable instead of aggressive. So:
- The writing is free. All of it, permanently. No email wall, no "download the whitepaper", no ten-paragraph preamble before the useful part. If we learn something worth knowing, it goes on this blog and you can read it in your browser at two in the morning without giving us anything.
- The audit tool is free. The AI Audit scores your app against the OWASP LLM Top 10 and the EU AI Act and hands you a report. It runs entirely in your browser — nothing you type reaches our servers, because we did not want "free" to quietly mean "we take your data instead".
- The books are cheap on purpose. Fourteen dollars for a field manual, twenty-nine for all four PDFs. People have told us to charge five times that. They are probably right about what the market would bear. I would rather a student in a country where the exchange rate is brutal can buy the whole shelf with one evening's work.
- The labs are not gated behind the theory. You should be able to practice the thing, not just read about it.
None of this is charity and I do not want to dress it up as such. We sell books and we sell access to the ranges, and that is what keeps the lights on. But the free tier is not a funnel with a narrow end. It is most of what we make.
What I actually believe
Two things, and they pull in the same direction.
The first is that offensive security is a way of thinking before it is a set of tools. You can memorize a hundred commands and still freeze the moment a target does not match the walkthrough. The people who are genuinely good at this are asking one question over and over — where is the trust, and how is it verified? — and everything else is a consequence. That question is free. You do not need a lab subscription to start asking it.
The second is that the defenders need this more than anyone. Every time someone learns how an attack really works, there is one more person who can spot it in a code review, push back in a design meeting, or notice the thing in the logs at 3am. Teaching the attack is how you get the defense. That is not a loophole in our ethics; it is the entire point, and it is why every chapter we write pairs the attack with how you would catch it.
A request, and an invitation
If you are new and something here reads as if it assumes knowledge you do not have — tell me. Genuinely. That is a bug and I want to fix it. The failure mode I am most afraid of is quietly becoming the thing I found so frustrating: a resource that is technically free and practically closed. I cannot see that from the inside. You can.
You can reach me at [email protected] and I read everything, even when it takes me a few days.
And if you are where I was a couple of years ago — curious, a bit outside the field, unsure whether you are allowed to find this as interesting as you do — you are. Start with the free audit on something you own, or read the next post on this blog. Then go break something you have permission to break.
That part never stops being fun. I hope you get to find that out.
— Komal