Irregular
The company you have filed as Pattern Labs. Same firm, new name: 35 people in Tel Aviv running cyber evals for four frontier labs, at $450M.
Latest (Sep 2026): No new funding disclosed since the $80M round at $450M (Sequoia and Redpoint, with Wiz CEO Assaf Rappaport, Sept 2025). Through 2026 it published evaluations for most frontier releases (GPT-5.x, Claude Opus 5, Muse Spark, Kimi K3, GPT-6 Astra on 2026-09-03), launched FrontierCyber (2026-06-22) and SOLVE+ (2026-09-03), and co-authored an AI-security agenda with RAND (2026-08-24). A containment incident was disclosed on 2026-07-30: misconfigured evaluation environments gave models live internet access and they attacked a real domain matching a fictional target. Irregular published its findings on 2026-08-14, and BERI (2026-08-10) framed it as correlated risk from one ~35-person vendor serving competing labs.
Pattern Labs is Irregular. The company tracked in most vendor lists as Pattern Labs rebranded; there is one firm, not two. Founded 2023 in Tel Aviv by Dan Lahav and Omer Nevo, roughly 35 employees, $80M raised at a $450M valuation from Sequoia and Redpoint in September 2025 (BERI; TechCrunch, 17 Sep 2025). Any register carrying both names is double-counting the Offensive security vendor field.
Irregular runs cyber evaluations for OpenAI, Anthropic, Meta and Google DeepMind, and its SOLVE framework and CyScenarioBench appear directly in frontier model system cards (BERI). CyScenarioBench is named in the Claude Opus 5 system card with a disclosed 33.7% completion score (Anthropic).
What $450M buys with 35 people
The valuation is not built on headcount or on data volume. It is built on being the named third party in the safety disclosure of the labs that compete with each other. A system card citation is a public, durable endorsement a competitor cannot purchase, and Irregular holds four of them across the firms with the largest evaluation budgets.
That is the same asset Gray Swan AI holds — cited in eleven system cards — and it is the reason the Offensive security vertical has the hardest demand evidence anywhere in the atlas. The Claude Opus 5 card alone names UK AISI, Irregular, an academic ExploitGym consortium, Mozilla, Trajectory Labs PBC, 10a Labs and Gray Swan for cyber evaluation (Anthropic). Nothing comparable exists for Design and UI/UX, Law or Accounting, audit and tax.
The structural oddity nobody has priced
BERI's framing is the finding: three competing labs bought "independent" assurance from the same 35-person firm (BERI).
Two readings, both live.
The optimistic one is that shared vendors are how assurance markets normally work — audit, penetration testing and certification all converge on a handful of accepted names, and convergence is what makes results comparable across labs. Once your framework is the shared reference, switching costs are collective rather than individual, which is the strongest form of hold in the atlas.
The pessimistic one is that a 35-person firm is a single point of methodological failure for the public safety record of four frontier labs, and that concentration of this kind attracts either a regulator or an in-house replacement. Labs already run private suites — ExploitBench and ExploitGym sit alongside CyScenarioBench in the same card. The vendor-owned benchmark is a strong position until the buyer decides assurance should not be procured from one shop.
What this does to the entry window
The decisive fact for anyone considering offensive security as a niche is that the benchmark layer here is already captured by vendors. Irregular owns SOLVE and CyScenarioBench; Gray Swan owns Arena and its million-plus attack trajectories; the labs own ExploitBench and ExploitGym. A new public benchmark — the standard opening move described in The specialist wedge — is a much weaker weapon in this domain than in one where no reference exists.
Note the inverse relationship this creates across the atlas. The niches with the most proven lab spending are the niches where the benchmark layer is already owned. The niches with an empty benchmark layer — defensive security, Law, Accounting, audit and tax — are empty precisely because the budget has not arrived yet. You are choosing between fighting for a proven budget and manufacturing one; Vals AI is the existence proof that manufacturing works.
Public academic benchmarks remain unsaturated but are not the procurement reference: NYU CTF Bench puts Claude 4.5 Opus at 59.0% (118/200) and Gemini 3 Pro at 52.0% (arXiv 2604.17159).
Revenue, ARR and gross margin — none disclosed. Contract values with any of the four labs. Whether the lab relationships are recurring engagements or per-release evaluations, which is the difference between an evals business and a consulting business. Customer One customer is a binary event: four named labs and 35 staff implies near-total concentration, but no split is public. Nothing is published on how Irregular compensates the people who build its scenarios, which is the whole supply question for a copycat.
What to learn from it: the durable asset in evals is not the data or the model — it is being named in someone else's system card, and that citation is bought once and compounds, which is why the vendors who have it are valued on it rather than on revenue.
The specialist wedge
The bet is that one domain buys cheaper experts and faster belief, and that both advantages expire the moment you have a reference customer. What would have to be true, what the evidence supports, and the trade-off that decides which niche.
Gray Swan, in full
The crowd is not the product — it is the training set for the product. 15,000 people produced 130,000 breaks for $490K, and the Arena terms hand Gray Swan an irrevocable worldwide licence to all of it at under four dollars a unit.
The labs as buyers
Two buyers hold the money, and both have said in writing that their cyber evaluation stock is exhausted — one paused a frontier training run over it, the other published the sentence that is the whole sales pitch.
The security read
Build, still — but on worse terms than the first reading. The six firms are named, one of them already sells this exact product to at least two labs, the first contract values in the market's history are now public from UK transparency data, and the elite labour tier costs three times what the earlier estimate assumed.
Government buyers
One government agency publishes the names of the vendors it subcontracts cyber range construction to, and another published the only precise unit price in the sector — £2–3m for fourteen months of one red team.
Irregular, in full
Thirty-five people are load-bearing for four competing labs' cyber safety claims, at $450M, on a hosted service nobody can licence — and they got there in six to nine months from their first published model assessment.
The one shape that survives
AddressSanitizer separates a real memory-corruption bug from a hallucinated one with zero false positives. For logic bugs Anthropic says it loses that ability entirely — and hires professional human contractors instead. That sentence is the whole business: expert validation of logic vulnerabilities, plus the held-out evaluation content that falls out of it.
Defensive security
The widest benchmark gap found anywhere — frontier models at 23–34% on malware analysis — with a small reachable pool and the hardest data-sourcing problem in the set. Superseded: the deep dossier found the incumbent this page said did not exist.
Paying the crowd
Gray Swan buys perpetual worldwide rights to an attack trajectory for about $3.77; Mercor pays $70–95 an hour and up for the same skill. Tournament and payroll are different products, and the buyer of a dataset wants the expensive one.
Sizing the cyber pot
$25M–$120M a year, most likely $40M–$80M, for externally-sourced frontier-lab cyber evaluation content in 2026 — derived two independent ways that bracket each other, with every step of the working shown and every figure an inference.
Vals AI
$40M at $400M for building the benchmark layer in professions the labs were not yet buying for. The existence proof that a specialist can manufacture a budget rather than wait for one.
Offensive security
The strongest demand evidence of any niche in this atlas — named in system cards, with lab reqs carrying pay bands — which is exactly why two funded specialists already own the network and the benchmark.
Edison Scientific
$70M and already contracting PhD biologists to build its own benchmark. The wet-lab position is not open — it is occupied by a company that built the moat before selling anything.