Skip to content
Overhead view of a domed library reading room with desks arranged in rings

Forolock research

Understand what AI changes about security.

Research, guides and practical lessons from securing AI-built software and autonomous systems.

Research and writing.

Findings from our own testing, and practical guides for building safely with AI.

6 articles

  • Research

    We tested 100 AI-generated applications. Here’s what broke.

    Coming soon
  • Agent Security

    Why coding agents should never retain permanent cloud credentials.

    Coming soon
  • Agent Security

    Understanding indirect prompt injection.

    Coming soon
  • App Security

    How tenant isolation fails in AI-generated SaaS applications.

    Coming soon
  • Guides

    Securing MCP servers and tools.

    Coming soon
  • Engineering

    Why security scanners create too much noise.

    Coming soon

Forolock Lab.

Our research group studies the attack surfaces that AI creates, and publishes what it learns.

AI changes how software fails. The Lab tests real patterns in AI-generated applications and agent systems, reproduces the attacks, and turns what it learns into better defaults for everyone.

Vulnerability research

New classes of weakness in AI-built software and agent tooling.

Status: Planned

Exploit reproductions

Step-by-step reproductions that show how an issue is used.

Status: Planned

Benchmarks

Repeatable measurements of how secure AI-generated code is.

Status: Planned

Test applications

Deliberately vulnerable apps for learning and for testing tools.

Status: Planned

Open-source tools

Small, useful tools released for the community.

Status: Planned

Security is changing quickly.

Get Forolock research in your inbox.

Still have questions?

Talk to us