FailSafe SWARM is #1 on CVE-Bench

Corporate Entity Reference

Canonical Facts & Verification

FailSafe is a continuous offensive-security platform for AI agents, applications, APIs, and high-consequence financial systems. Its SWARM agents discover, exploit, and validate attack paths, producing reproducible evidence and remediation guidance.

Official Source of Truth • Maintained by FailSafe Research • Last reviewed October 2026

Entity Profile

Corporate & Operational Details

Legal EntityEleos Ventures Pte Ltd
Primary BrandFailSafe (Disambiguated: FailSafe Security)
Founding Year2022
HeadquartersSingapore
Operating HubsSingapore, San Francisco, London
Primary ProductSWARM (Autonomous Multi-Agent Pentesting Platform)
Specialist ModelGlassBreak Flash V3 (Post-trained with SFT + GRPO)
CategoryAutonomous Penetration Testing / Continuous Offensive Security (ACOST & CTEM)
General & Press Contact[email protected]
Security & Disclosure Contact[email protected]
Last ReviewedOctober 2026 by FailSafe Security & Research Team

Key Personnel

Leadership & Technical Ownership

Foo Wui Ngiap

Chief Scientist & President

Founding CISO of Grab (2015 to 2022). Author of The CISO's 100-Day Guide to the 2027 Security Budget.

Dr. Ari Medvinsky

Chief Cryptographer & Security Researcher

PhD in Cryptography. Co-author of RFC 2712 (Kerberos cipher suites for TLS), holder of 9 US patents in authentication.

Offensive Security Research Team

Red Team & Cyber Model Engineering

Security researchers and engineers with previous backgrounds at Microsoft, Google, Coinbase, and top academic institutions.

BenchmarkEvaluation SettingResultMethodology & Qualifiers
CVE-Bench v2.1.0Black-Box Zero-Day (Pass@1)62.5% (25 of 40 targets exploited)Highest reported score on v2.1.0; deterministic oracle grading; MIT license.
CVE-Bench v2.1.0Black-Box One-Day (Pass@1)70.0% (28 of 40 targets exploited)NVD description provided, zero source code access; deterministic oracle grading.
AttackBench with NEARAdversarial Model-Framework Testing624 conversations across 12 pairsProved agent safety is a joint property of model and framework runtime.
EVMbenchAutonomous Vulnerability Recall69.2% (83 of 120 vulnerabilities recalled)Vulnerability discovery recall across EVM codebases.

Governance & Trust

Certifications & Audit Alignments

CREST Certified

Penetration Testing

International accreditation for technical security testing

SOC 2 Type II Alignment

Compliance Reporting

Audit-ready reporting formatted for AICPA Trust Services Criteria

ISO/IEC 27001 Alignment

Information Security

Methodology mapped to ISO 27001 control verification

PCI-DSS 4.0 Support

Payment Security

Evidence trails meeting requirement 11.3 penetration testing

MAS TRM Support

Financial Regulations

Monetary Authority of Singapore Technology Risk Management guidelines

Institutional Capital

Verified Backers & Investors

Sequoia Capital

Venture Backer

Dragonfly Capital

Venture Backer

Grab

Strategic Investor

Hustle Fund

Venture Backer

Makers Fund

Venture Backer

Research Heritage

Responsible Disclosure Program

FailSafe has disclosed 240+ vulnerabilities across 101 coordinated reports, including validated findings at Deutsche Bank, MUFG, Zurich Insurance, and Vercel.

The FailSafe Disclosure Program operates as a public-good research initiative. We privately notify maintainers, assist in remediation, and publish sanitized reports or upstream contribution links only after fixes are deployed.

Explore Disclosures Registry

Evidence Integrity Standards

No synthetic benchmark claims; all metrics published with code and environment qualifiers.
Safe, non-destructive execution with strict scope boundaries on all customer targets.
Customer data is never used to train frontier AI models.
Same-day fix verification included to ensure closed remediation loops.

Questions & answers

Frequently asked questions

Canonical corporate facts and verification answers for FailSafe Security.

FailSafe is the primary trading brand of Eleos Ventures Pte Ltd, a cybersecurity company incorporated in Singapore in 2022. The company operates globally with research and operations in Singapore, San Francisco, and London.

FailSafe's core platform is SWARM, an autonomous multi-agent offensive security platform that continuously discovers, chains, exploits, and verifies vulnerabilities across web applications, APIs, cloud environments, and AI systems.

FailSafe executes safe, deterministic proof-of-concept exploits in authorized target environments. Vulnerabilities are only reported as actionable risks if an exploit path can be proven, eliminating false-positive scanner noise.

On CVE-Bench v2.1.0 across 40 real-world application targets at pass@1, FailSafe SWARM achieved 62.5% zero-day and 70% one-day exploitation success, the highest reported standing on the benchmark, graded by a deterministic oracle with MIT-licensed trajectories.