Memory-corruption bugs have a perfect oracle. Logic bugs do not. Everything worth building in security expert data sits on the far side of that line, and everything on the near side is already free.
Anthropic states both halves in the same document. For memory corruption: "tools like Address Sanitizer perfectly separate real bugs from hallucinations" — with zero false positives testing Opus 4.6 against Firefox 112, alongside 181 working exploits and 29 register-control achievements against the Firefox JavaScript engine. For logic vulnerabilities: "we do lose the ability to (near-)perfectly validate the correctness of any bugs Mythos Preview reports," with validation shifting to specification analysis (Mythos Preview).
When the oracle disappears, Anthropic buys humans. 198 vulnerability reports manually reviewed by professional human security contractors, at 89% exact severity agreement and 98% within one level. At programme scale it is larger: 26,153 candidate findings → 5,008 advanced to independent review → 4,576 confirmed valid (91.4% true positive) → 2,300 disclosed across 392 open-source projects, with triage performed by "one of six external security research firms" who "reproduce each issue, assess whether it is a real bug." Agreement with Claude's severity: 85.2% exact, 97.1% within one band, with Claude systematically rating higher and the firms discounting for project-specific context (Anthropic CVD).
That is the business. Not a corpus. A panel.
Why the line is permanent
The usual objection to a human-in-the-loop business is that the loop closes. Here it does not, for a structural reason rather than an optimistic one.
An automated verifier is what makes a security artefact scale. A sanitizer crash, a hidden flag, a canary value — each of those lets a buyer run an environment ten thousand times unattended, which is the precondition for reinforcement learning and for selling a corpus once and walking away. Where that verifier exists, the artefact is a product; where it does not, a human is attached to every unit forever. The oracle decides everything sets out the three tiers.
The commercial consequence is uncomfortable and it runs the opposite way to intuition. The tier with the perfect oracle is the tier that has already been commoditised, precisely because it scales. Bugcrowd ships "hundreds of thousands of training environments, each built from open-source software with real source code and verifiable outcomes," generated from a fuzzing corpus at effectively zero marginal cost per unit (SiliconANGLE). AIxCC ran a fully autonomous 143-hour competition validated on "crash stack traces, sanitizer signatures, and automated execution," then open-sourced all seven finalist systems (AIxCC SoK). A specialist hand-authoring memory-safety environments at $80–90 an hour is competing with a build script and with free.
The tier with no oracle cannot be commoditised by the same move, because there is nothing to automate against. You cannot fuzz your way to "is this authorisation flow actually broken, and how badly." Someone has to read the specification, reproduce the issue, and form a judgement — which is why the vendor with the strongest product story in the sector still scores its open-ended tier with "automated checks and expert review" (FrontierCyber).
No oracle means no automation, and no automation means the labour cost never falls out of the price. Every other position in this dossier is defended by scarcity that a competitor can buy — a crowd, a benchmark, a rate card. This one is defended by a property of the problem.
Who buys it
Six firms' worth of capacity, at one lab, today. That is the entire answer and it is unusually concrete.
Anthropic did not engage one contractor and did not build a team. It engaged six external security research firms and still processed only 5,008 of 26,153 candidates to human review. A single lab needing six suppliers to absorb one programme's volume is the signature of a capacity-constrained market, not a served one — and it is the only demand signal in this dossier with a headcount attached rather than a valuation.
Every other lab faces the same problem the moment its models start producing logic-bug findings at volume. OpenAI has paused its largest planned frontier RL run on cyber grounds and committed publicly to expanding third-party testing (OpenAI); The labs as buyers traces where that budget sits. UK AISI already contracts external firms by name for evaluation content — SpecterOps, Hack The Box, Crystal Peak Security and Irregular on a single GPT-5.5 assessment (AISI) — which is a procurement pattern a new supplier can actually apply to, unlike the invisible lab relationships. And ARIA's Track 2 line, ~£2–3m for roughly fourteen months of one red team, is the only precise public unit price in the sector (ARIA). See Government buyers.
The second buyer for the same panel is the defensive side, where the identical oracle problem shows up under a different name. Threat-actor attribution has no verifier at all — AthenaBench puts GPT-5 at 39.0% on attribution and 32.6% on mitigation strategy against 92.0% on knowledge questions (arXiv 2511.01144). The SSVC vulnerability-triage study had to invent synthetic organisational stand-ins for the contextual decision point because no ground truth existed, and that is exactly where models scored worst, at F1 0.43 (arXiv 2510.18508). A missing label is a product.
What it costs to staff
The scarce input is a reviewer who can reproduce an issue, not merely read a report. That is a narrower population than "security professional" and it prices accordingly.
| Input | Rate | Source |
|---|---|---|
| Offensive security and vulnerability research | $200–250/hr | Mercor |
| Blue-team incident reasoning | $85–95/hr | Mercor |
| Scenario and rubric authoring | $80–90/hr | Mercor |
| Offshore security labelling | $25–49/hr [WEAK — directory] | Enosis on Loginsoft |
| Completed pentest task | $1,750–2,150 | Himalayas |
Assume $150–250/hr fully variable for a reviewer of this grade, because the work sits between the blue-team band and the vulnerability-research band and because reproduction capability is the filter. Assume throughput is worse than it looks: CTI-HAL's human-annotated corpus managed two annotators, 81 reports, eight weeks — five reports per annotator-week (arXiv 2504.05866). That is the only published expert-annotation throughput figure in the domain and it is sobering.
A panel of ten reviewers at half-time is roughly 10,000 billable hours a year, or $1.5–2.5M of direct labour. That is the size of the first company. It is not venture-scale on its own, which is the point of the next section.
The capital requirement is small but not zero: reproduction infrastructure, an isolated harness, ISO 27001 or SOC 2 Type II as a gate rather than a differentiator, and insurance the standard market does not yet write (Nobody prices this risk yet). The one non-negotiable is that the harness is adversarially tested before it holds anything — the July 2026 ExploitGym incident, where a model broke out of OpenAI's own sandbox through a zero-day in its package proxy and moved laterally into Hugging Face's clusters, is the reason every buyer will now ask (The corpus is the target).
What it prices at
There is no published price for this service anywhere, so the pricing has to be triangulated and stated as such.
Per report is the natural unit, because the buyer already counts in reports. At $200/hr and a plausible two to four hours per reproduced-and-severity-assessed logic-bug report, direct cost is $400–800; at a services gross margin of 35–50% that is a $700–1,500 per validated report list price. Anthropic's 5,008 reviewed findings at the midpoint would be roughly $5.5M of annual spend across six firms, or under a million each — consistent with them being small engagements, and consistent with Trajectory Labs' ~100 hours and 10a Labs' ~16 hours in the Claude Opus 5 card being five-figure work.
Per retained panel is the shape to actually sell, because it converts a variable-volume service into a subscription. ARIA's structure is the public template: a fixed-price service contract with milestone payments tied to eight-week sprints, deliverables, and acceptance criteria, explicitly on commercial services terms. £160k–£200k a month for a team is the rate that structure implies.
And the held-out evaluation set is where the margin actually is. Every validated report generates a graded artefact with a known correct answer that nobody else has. Retain a slice, never sell it, and you own a private calibration benchmark — the only structure in the data business where the customer cannot take the product in-house without destroying it, because an evaluation set that has leaked into the buyer's training data stops measuring anything. That is Irregular's entire hold, reproduced from a completely different production model. FrontierMath's contract is the drafting template: 300 problems with solutions delivered, 50 statements-only held out, producer retains the right to evaluate and publish (Epoch). Default to licence, never assignment — assignment destroys the corpus asset, which is the valuation case. What you can actually sell carries the rest of the terms.
What the first product is
One thing, shippable in a quarter, that is simultaneously the credential and the wedge.
A published calibration benchmark for logic-bug severity. Take a set of logic vulnerabilities in published, patched, open-source software. Have three independent expert reviewers assign severity against a stated rubric. Publish the inter-reviewer agreement, the model-versus-human agreement for every frontier model you can reach, and — the part nobody publishes — the disagreements, with the reasoning on both sides. Hold back a second set of the same construction and never release it.
Four reasons it is the right first artefact. It measures the exact thing Anthropic already measures internally and nobody measures publicly, so it slots straight into a conversation the buyer is already having. It is built entirely on published, patched vulnerabilities, which is the master discipline that solves export control, misuse, insurance and disclosure in one rule (Exploits are free, uploading is an export). It requires no bare-metal range, no physical device estate, and no capital — the reason to start here rather than with environments. And the private half is a saleable asset from day one, which is what Publishing the benchmark says every published benchmark needs and METR deliberately does not have.
The environments come second, as the marketing artefact and the reason a lab takes the meeting — not as the business.
What this is not, and why the corpus business is the trap
It is not a data company. The instinct is to say "we sell attack trajectories," and it fails on four counts.
The price is set at $3.77. Gray Swan AI has distributed $490,000+ across 130,000+ successful breaks and acquires "an irrevocable, worldwide license to use and share the submission for any purpose" at the door (Arena About). You cannot sell a trajectory corpus into a market where the reference price per unit is under four dollars with perpetual sublicensable rights attached.
The corpus is a one-time sale that erodes. A licensed dataset is delivered, absorbed and finished. A panel renews. The whole reason Irregular hosts rather than licenses is that the hosted form cannot be exhausted.
The two incumbents best placed to build a corpus business examined it and declined. HackerOne on contract, Bugcrowd on product shape, both in public, both documented at The bounty platforms. Whatever else that proves, it proves the corpus route is not an unnoticed opportunity.
And a corpus is the artefact that gets stolen. A stolen panel is an inconvenience; a stolen corpus of high-quality attack trajectories with reasoning is a live weapon, and the ExploitGym incident established that the storage location of an answer key is a target. The insurance market does not price that today, and the buyer will ask.
Sell judgement, retain the measurement, and let the corpus be a by-product you never lead with. The ninety-day sequence for testing whether any of this is true is at Ninety days in security; what would have to be established first is at What the dossier could not establish; and the scoring that got here is at The security read.