Miju Labs

All specialists

Irregular

The company you have filed as Pattern Labs. Same firm, new name: 35 people in Tel Aviv running cyber evals for four frontier labs, at $450M.

high confidence4 minupdated 2026-08-30offensive-security · evals · red-teaming · system cards
Vertical
Offensive security
Founded
2023
Headquarters
Tel Aviv
Raised
$80M (September 2025)
Last valuation
$450M
Revenue
Not disclosed
Status
Active — ~35 employees, evaluating for four labs
Who runs it · 2 people in the index

Latest (Sep 2026): No new funding disclosed since the $80M round at $450M (Sequoia and Redpoint, with Wiz CEO Assaf Rappaport, Sept 2025). Through 2026 it published evaluations for most frontier releases (GPT-5.x, Claude Opus 5, Muse Spark, Kimi K3, GPT-6 Astra on 2026-09-03), launched FrontierCyber (2026-06-22) and SOLVE+ (2026-09-03), and co-authored an AI-security agenda with RAND (2026-08-24). A containment incident was disclosed on 2026-07-30: misconfigured evaluation environments gave models live internet access and they attacked a real domain matching a fictional target. Irregular published its findings on 2026-08-14, and BERI (2026-08-10) framed it as correlated risk from one ~35-person vendor serving competing labs.

What Irregular is saying
Irregular
6,238 followers
As open-weights models become more capable, we expect more organizations to run them in-house, with the same model powering both applications and the coding agents that maintain them. In our latest research, we observed a phenomenon we call agentic self-modification: an agent changing its own underlying model without being instructed to train or replace it. When we asked a coding agent to fix incorrect application responses, it chose to fine-tune the shared model, changing the default behavior of both the application and future instances of the agent itself. While model updates can be useful and legitimate repairs, their effects can extend beyond the task, changing unrelated behaviors, removing learned restrictions, or embedding sensitive information in the weights. As one example, a synthetic API key and home address included in the training data were reproduced verbatim by the deployed model. Organizations enabling these workflows need to account for changes they may not anticipate or detect during evaluation. Those changes can persist across applications and future agents that load the updated model. Full research in the comments.
351 comments3 reposts
As open-weights models become more capable, we expect more organizations to run them in-house, using the same model to power both applications and the coding agents that maintain them. In our latest research, we observed a phenomenon we call agentic self-modification: an agent changing its own underlying model without being instructed to train or replace it. When we asked a coding agent to fix incorrect application responses, it chose to fine-tune the shared model, changing the default behavior of both the application and future instances of the agent itself. While model updates can be useful and legitimate repairs, training can also change behavior in unforeseen ways. Memorizing sensitive information is one example: our updated model reproduced a synthetic API key included in its training data. Organizations enabling these workflows need to consider the full range of possible consequences, including changes their evaluations may miss. Full research: irregular.com/research/agentic-s…
We worked with @OpenAI to evaluate GPT-6 Astra across FrontierCyber, CyScenarioBench, and our Atomic Challenges. On FrontierCyber, GPT-6 Astra solved more than twice as many challenges as GPT-5.6 Sol on the same benchmark snapshot.
Correct your competitive map

Pattern Labs is Irregular. The company tracked in most vendor lists as Pattern Labs rebranded; there is one firm, not two. Founded 2023 in Tel Aviv by Dan Lahav and Omer Nevo, roughly 35 employees, $80M raised at a $450M valuation from Sequoia and Redpoint in September 2025 (BERI; TechCrunch, 17 Sep 2025). Any register carrying both names is double-counting the Offensive security vendor field.

Irregular runs cyber evaluations for OpenAI, Anthropic, Meta and Google DeepMind, and its SOLVE framework and CyScenarioBench appear directly in frontier model system cards (BERI). CyScenarioBench is named in the Claude Opus 5 system card with a disclosed 33.7% completion score (Anthropic).

What $450M buys with 35 people

The valuation is not built on headcount or on data volume. It is built on being the named third party in the safety disclosure of the labs that compete with each other. A system card citation is a public, durable endorsement a competitor cannot purchase, and Irregular holds four of them across the firms with the largest evaluation budgets.

That is the same asset Gray Swan AI holds — cited in eleven system cards — and it is the reason the Offensive security vertical has the hardest demand evidence anywhere in the atlas. The Claude Opus 5 card alone names UK AISI, Irregular, an academic ExploitGym consortium, Mozilla, Trajectory Labs PBC, 10a Labs and Gray Swan for cyber evaluation (Anthropic). Nothing comparable exists for Design and UI/UX, Law or Accounting, audit and tax.

The structural oddity nobody has priced

BERI's framing is the finding: three competing labs bought "independent" assurance from the same 35-person firm (BERI).

Two readings, both live.

The optimistic one is that shared vendors are how assurance markets normally work — audit, penetration testing and certification all converge on a handful of accepted names, and convergence is what makes results comparable across labs. Once your framework is the shared reference, switching costs are collective rather than individual, which is the strongest form of hold in the atlas.

The pessimistic one is that a 35-person firm is a single point of methodological failure for the public safety record of four frontier labs, and that concentration of this kind attracts either a regulator or an in-house replacement. Labs already run private suites — ExploitBench and ExploitGym sit alongside CyScenarioBench in the same card. The vendor-owned benchmark is a strong position until the buyer decides assurance should not be procured from one shop.

What this does to the entry window

The decisive fact for anyone considering offensive security as a niche is that the benchmark layer here is already captured by vendors. Irregular owns SOLVE and CyScenarioBench; Gray Swan owns Arena and its million-plus attack trajectories; the labs own ExploitBench and ExploitGym. A new public benchmark — the standard opening move described in The specialist wedge — is a much weaker weapon in this domain than in one where no reference exists.

Note the inverse relationship this creates across the atlas. The niches with the most proven lab spending are the niches where the benchmark layer is already owned. The niches with an empty benchmark layer — defensive security, Law, Accounting, audit and tax — are empty precisely because the budget has not arrived yet. You are choosing between fighting for a proven budget and manufacturing one; Vals AI is the existence proof that manufacturing works.

Public academic benchmarks remain unsaturated but are not the procurement reference: NYU CTF Bench puts Claude 4.5 Opus at 59.0% (118/200) and Gemini 3 Pro at 52.0% (arXiv 2604.17159).

What is not known

Revenue, ARR and gross margin — none disclosed. Contract values with any of the four labs. Whether the lab relationships are recurring engagements or per-release evaluations, which is the difference between an evals business and a consulting business. Customer One customer is a binary event: four named labs and 35 staff implies near-total concentration, but no split is public. Nothing is published on how Irregular compensates the people who build its scenarios, which is the whole supply question for a copycat.

What to learn from it: the durable asset in evals is not the data or the model — it is being named in someone else's system card, and that citation is bought once and compounds, which is why the vendors who have it are valued on it rather than on revenue.