NOTICE: Due to a high volume of low-quality AI submissions, verification audits may require up to 7 business days. Standard qualified advisories are processed significantly faster.

VULNERABILITY
ACQUISITION
& VERIFICATION

ZeroHawk coordinates with security researchers worldwide to acquire, verify, and transition critical vulnerability intelligence. We provide institutional partners with validated defense capabilities to mitigate global systemic threats.

// ZEROHAWK
// ZEROHAWK
SCROLL TO NAVIGATE SECTION DETAILS
01

RESEARCHER ADVANTAGES

We build long-term partnerships, not one-off transactions. ZeroHawk offers industry-leading compensation structures and exclusive programs designed to reward sustained collaboration.

Passive Income Program

Trusted long-term partners gain access to our exclusive Passive Revenue Share program. When a previously submitted vulnerability class generates recurring licensing revenue through ongoing institutional subscriptions, contributing researchers receive a continuous royalty share — creating a sustainable passive income stream beyond the initial acquisition payout.

Partnership, Not Extraction

We view every researcher as a strategic partner, not a disposable supplier. Our dedicated researcher relations team provides ongoing communication, priority review queues, exclusive access to emerging target lists, and direct input channels to our technical leadership. Long-term collaborators receive elevated trust tiers with increased payouts and streamlined verification.

02

LEGAL COMPLIANCE & TRUST FRAMEWORK

We prioritize legal safety, compliance with international export controls, and researcher risk mitigation above all else.

Legal Safe Harbor & NDA

Our dedicated internal team of international legal specialists manages licensing structures, NDA protections, and transfer frameworks. We guarantee that researchers are fully protected from legal, regulatory, and tax liabilities across jurisdictions before, during, and after the transaction is completed. By establishing formal corporate safe harbors, we ensure zero legal risks for our research partners.

Wassenaar Alignment

All verification and transition activities are fully compliant with the Wassenaar Arrangement guidelines and relevant export control regulations. We maintain rigorous compliance records to prevent unauthorized transfers and protect our research partners from compliance-related risks.

Air-Gapped Validation

Exploit models undergo technical verification inside strictly isolated, physical air-gapped lab networks. Details are never exposed to public internet gateways, preventing leakage or detection.

Multi-Jurisdictional Safe Escrow

We execute transactions across multiple international jurisdictions, enabling us to route contracts and payouts through regulatory safe zones. This ensures that transaction execution triggers no local legal exposure, compliance red flags, or tax tracking, guaranteeing absolute settlement safety.

03

VULNERABILITY SUBMISSION PROTOCOL

A strict, structured operational process governed by formal confidentiality agreements, compliance standards, and risk-mitigated technical validation.

STAGE 01 [ INITIAL HANDSHAKE ]

Encrypted Briefing

Establishing secure communications via PGP-encrypted mail or Session Messenger. Researchers provide a high-level structural advisory containing targeted interfaces and mitigation bypass parameters. To preserve researcher security, no exploit source code is accepted at this stage.

STAGE 02 [ NDA & CONTRACT ]

Legal Safe Harbor

Prior to transferring any functional code, we execute a legally binding NDA and a preliminary acquisition contract. This ensures your intellectual property, identity boundaries, and payout valuations are legally locked and protected before the PoC is delivered.

STAGE 03 [ SYSTEM AUDIT ]

Proof-of-Concept Validation

Under the full protection of the signed contract, the researcher transfers the PoC using encrypted containers. Senior verification engineers perform a technical audit inside physical air-gapped lab networks to confirm stability and mitigation bypass parameters.

STAGE 04 [ SETTLEMENT ]

Compliance & Payout

Once validated, our legal division compiles a custom acquisition contract aligned with Wassenaar Arrangement standards. Settlement terms are signed, and payouts are executed securely through the researcher's preferred digital or banking settlement channels.

04

CAREERS AT ZEROHAWK

We are expanding our core engineering and market communications teams. We offer highly competitive compensation, remote collaboration, and complex technical challenges.

ENGINEERING // REMOTE

Kernel Security Specialist

We are seeking engineers with low-level expertise in operating system kernels (Linux, iOS, Android, macOS, or Windows). The role involves analyzing architecture structures, validating vulnerability remediation patterns, and developing testing instrumentation.

Requirements:
  • Deep understanding of memory management, IPC, and kernel internals.
  • Proficiency in debugging tools (LLDB, GDB, WinDbg) and reverse engineering.
  • Experience with modern hardware-enforced security mitigations.
RESEARCH & ML // REMOTE

Principal AI/ML Security Engineer

We are seeking a senior AI/ML research engineer to spearhead our autonomous vulnerability discovery systems. The role involves designing and scaling neural models that analyze binary trace behavior, predicting exploit vectors, and hardening models against adversarial extraction or poisoning.

Requirements:
  • 7+ years of experience in deep learning, LLMs for code, and transformer architectures.
  • Deep understanding of AI security, adversarial attack vectors, and model poisoning.
  • Expert knowledge of PyTorch, CUDA acceleration, and large-scale model fine-tuning.
INFRASTRUCTURE // REMOTE

Principal ML SecDevOps Architect

We are looking for a highly experienced DevOps engineer to build and manage our high-performance GPU cluster infrastructure. You will be responsible for orchestrating air-gapped MLOps/LLMOps pipelines, implementing zero-trust network boundaries, and securing model runtime boundaries.

Requirements:
  • 8+ years in SRE/DevOps, with 3+ years architecting secure MLOps/LLMOps pipelines.
  • Expert-level K8s (Kubernetes), Docker, Terraform, and hardware-accelerated (GPU) orchestration.
  • Proven experience setting up air-gapped development and high-compliance data isolation systems.
MARKETING // B2B

Communications & Brand Lead

We are looking for a marketing leader to define our positioning within the global cybersecurity research community. The role focuses on developing trust, maintaining discrete communication campaigns, and managing brand operations across secure B2B channels.

Requirements:
  • Proven experience in tech B2B marketing or cybersecurity positioning.
  • High comfort navigating technical developer and research ecosystems.
  • Flawless record of managing confidential corporate messaging.
05

SECURE CONTACT CHANNELS

Reach out to our compliance or engineering teams via encrypted communication standards. We respect and enforce absolute researcher anonymity at all stages.

SECURE EMAIL contact@zerohawk.io
SESSION MESSENGER Available upon request
LEGAL DIVISION compliance@zerohawk.io
PUBLIC PGP KEY
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: ZeroHawk ECC (nistp256)

mFIEahXQqBMIKoZIzj0DAQcCAwSx6LQ8GCvzrGCrc0bYzpz5OJFvMp6p1eL3mwfR
Ta64QQs3zW9fzMft4Vc4Axvyx4s+VNBxzESYa7Qz2tVav7tStB5aZXJvSGF3ayA8
Y29udGFjdEB6ZXJvaGF3ay5pbz6IlgQTEwgAPhYhBPiS0s6XD63Rf8lFQjtvIybP
qjPCBQJqFdCoAhsDBQkDwmcABQsJCAcCBhUKCQgLAgQWAgMBAh4BAheAAAoJEDtv
IybPqjPCP9cBAP8fKn3AZ7xeS+QPHpkmJPXcONHCh9thZ6b1aqrih8WqAQDeqzeH
D4yXS5h3zSXZkAtYoZj4xSYTPVZkht9iGkANHbhWBGoV0KgSCCqGSM49AwEHAgME
vbusnBN9dhQOUBzIT1dfI+w/jY91OYpq8OtfvF9DavlTy35Z13qX17d4Pbn8WhIW
ipDEx8eTxHJOjeIAOnmpJgMBCAeIfgQYEwgAJhYhBPiS0s6XD63Rf8lFQjtvIybP
qjPCBQJqFdCoAhsMBQkDwmcAAAoJEDtvIybPqjPCgtkA/1KGjzwSGevS4MUdTPUh
9hFL7hSuaIWDIsiNShgFaruMAQDtviv4pwG5Btqsl6xbDssQRhu5liEzsDY/mYvT
N8EqMA==
=jkAd
-----END PGP PUBLIC KEY BLOCK-----