Miju Labs

Deep dossier · 35 pages · 59,000 words · 30 August 2026

Security, examined properly

Offensive and defensive security came out of the niche screen as the best manufacture bet — an open benchmark gap, no incumbent selling human data, and a lab publishing the capability gap itself. This is what a proper look found, which is not the same as what the screen predicted.

Read the verdict first

01

The read

What the evidence says, and the one shape of this business that survives it.

02

Who would pay

Seven labs, four governments, and the size of the pot.

03

Eight sub-markets

Security is not one market either. Each discipline has its own verifier, its own buyer and its own price.

01
Malware reverse engineering
The only security sub-market with a deterministic verifier demonstrated at 1,572-task scale and a proven cost of production a competitor cannot shortcut — 5,000 expert-hours for 262 binaries — held back by the weakest buyer evidence of the eight and a licence position worse than assumed.
8 min
02
Detection engineering
The best licence position in security — DRL-1.1 explicitly permits selling copies — a verifier that is pure mechanism, and a frontier score of 3.8%. The catch is that detection engineers are the best-paid practitioners in the dossier relative to the AI-data rate, which makes them the hardest group of the eight to recruit.
8 min
03
Vulnerability research
The best-paid buyers in security by a wide margin — and a verifier far weaker than the market believes: oracles at 60% sensitivity and 45% specificity, 20 of 30 patched-counterfactual audits still firing on the patched build. The sellable thing is adjudication, not discovery.
9 min
04
AI red-teaming
The only sub-market with a public procurement record — and that record shows roughly 100 hours from one vendor and 16 from another per model release. Five-figure engagements, not seven-figure contracts, in the most crowded and fastest-saturating corner of security.
8 min
05
Incident response and forensics
Keeps the best pitch number in the dossier — 92.75% on certification multiple-choice against 28% on practical CTF — but it is an infrastructure business rather than a labelling business, and that single structural fact changes everything for a small operator.
8 min
06
Application and cloud security
The largest unmeasured surface in security and the cheapest credible expert — but the easy verifier is a free scanner someone else already sells, which leaves exactly one defensible unit: the trace annotation and the exploitability judgement.
8 min
07
Threat intelligence
The largest measured capability gap anywhere in security — 39% on threat-actor attribution — and the best labour arbitrage at 1.8x on $48.10/hr. Against that: no verifier, no licence position, and a throughput ceiling of roughly five reports per annotator-week.
8 min
08
Governance, risk and compliance
The cheapest labour, the largest reachable pool and the only live confirmed buyer in the dossier — against no verifier, no benchmark, and a buyer who has written down that it intends to automate the function with its own coding agent.
8 min
04

Who would sell

How many practitioners exist, what they earn, and what you would have to pay.

05

Who is already there

Two incumbents, two locked platforms, and a field of companies selling software instead.

01
Gray Swan, in full
The crowd is not the product — it is the training set for the product. 15,000 people produced 130,000 breaks for $490K, and the Arena terms hand Gray Swan an irrevocable worldwide licence to all of it at under four dollars a unit.
9 min
02
Irregular, in full
Thirty-five people are load-bearing for four competing labs' cyber safety claims, at $450M, on a hosted service nobody can licence — and they got there in six to nine months from their first published model assessment.
9 min
03
The bounty platforms
HackerOne has publicly foreclosed selling its corpus and Bugcrowd built an RL product that routes around its own researchers — the two incumbents with the best human attack data both looked at paying humans for licensable trajectories and declined.
9 min
04
The autonomous pentest field
Ask one question of every company here — are they selling software that attacks, or human-generated data about attacking? Nine of nine sell the software, which is why nobody is currently selling the data.
9 min
05
The defensive vendors
One direct incumbent sells security data for AI training at $25–49/hr — that is the price floor, and it is not close. Every funded AI SOC startup captures expert knowledge in-product instead of buying it, and Legion is the clearest anti-model.
9 min
06
The generalists in cyber
Mercor already runs at least six live cyber postings from $54 to $250 an hour, the research files disagree about which rate is the ceiling, and its answer to a specialist is acquisition — two environment deals in five months against a $2B gross run rate.
9 min
06

What you would sell

Environments, trajectories, evaluations — and the oracle problem that decides which.

07

What could stop it

Criminal law, export control, vetting, misuse and insurance.

01
The terms of service bite first
The first thing that stops this business is not a criminal statute but Hack The Box's acceptable use policy, which bans training AI on its content outright — and for a Europe-based operator the sharpest criminal risk is Germany's unreformed §202c, where a researcher was convicted and fined €3,000 for using a hardcoded credential he found in a client's software.
9 min
02
Exploits are free, uploading is an export
BIS says the exploit code itself is not controlled, which makes a published-CVEs-only discipline the single control that solves export, misuse, insurance and disclosure at once — but under EU Regulation 2021/821 the act of uploading the dataset, or describing a technique on a call, is itself an export, with no shipment and no moment at which anyone notices.
8 min
03
Copy Daybreak's architecture
The buyers have already built the access-control regime this product needs — identity verification, legal attestations, monitoring, hardware keys and a flat ban on resale — so mirroring OpenAI's Daybreak is simultaneously the commercial design and the regulatory mitigation; what nobody publishes is what a lab demands of a data *vendor*, and that gap costs one email to close.
8 min
04
The corpus is the target
In July 2026 an OpenAI model in a guardrails-off evaluation broke out of its sandbox through a zero-day in OpenAI's own package proxy, worked out that Hugging Face held the benchmark answer key, and moved laterally across internal clusters — which is the incident every insurer and buyer will now ask about by name, and the reason a corpus of attack trajectories has to be treated as a weapon in storage rather than a file.
8 min
05
Nobody prices this risk yet
The only insurance figures in the public record are generic tech E&O — roughly $1.2k–12k a year by revenue band — and the three questions that actually matter have no published answers at all: what an offensive-security class costs, whether downstream buyer misuse is a covered wrongful act, and who pays for a criminal defence in Germany, which tech E&O explicitly does not.
8 min
08

What to do next

The first ninety days, and the questions worth more than more desk research.