We find what vendors bury.
When software vendors silently patch critical flaws without telling the people at risk, we document it, translate it, and put it in front of regulators with the authority to act.
A vulnerability gets fixed in a commit. No CVE. No advisory. No notification. The vendor is safe. Everyone running the old version is not.
This is the dominant pattern in modern software security — almost entirely invisible to the people best positioned to stop it. Regulators have the authority. They lack the technical capacity to use it. Security firms have the capacity. They sell assurance to the same vendors creating the problem.
Whitenbaker exists to close that gap. We detect silent patches at scale, prove the security impact, and translate the evidence into a form that securities regulators, privacy commissioners, and consumer protection bodies can act on the day they receive it.
Selected dossiers.
Every figure on this page is anchored in active research. Below is a sampling of the public-facing record. Specific findings, attribution, and chain-of-custody material are available under engagement.
Consensus Infrastructure Compromise
A critical flaw in widely deployed consensus infrastructure renders its primary safety mechanism inoperative. Every downstream network inheriting this library is exposed to conditions the system was specifically designed to prevent.
Identity Provider Configuration Drift
Twenty-six confirmed findings across a single authentication codebase. Each was silently corrected upstream without notification to the operators running prior versions in production.
Defense Bypass in Secrets Platform
A previously patched defense contains a timing gap that allows the mitigation to be bypassed entirely. The vendor believed the issue was resolved. It was not.
Privilege Boundary Exposure
An exposed internal interface leaks the privilege boundaries of the platform, enabling an attacker to map the path from low-privilege account to administrative control of monitored infrastructure.
Built for the people with authority to act.
Your dependencies have secrets.
The libraries you ship contain silently patched vulnerabilities that were never publicly disclosed. Your users inherit the exposure. You inherit the liability.
Priced on TVL · From 1 basis pointYour audit passed. The exploit still happened.
70% of 2024 crypto exploits hit contracts with a clean prior audit. Not because the audit was wrong — because the vulnerability didn’t exist in any public database.
Priced on annual billings · From 50 basis pointsYou raised the round. Now secure what it built.
Investor-ready risk reporting built on upstream patch intelligence that doesn’t exist in any public database. Know what your stack is hiding before your next audit does.
Priced on last round · From 2 basis pointsYour diligence is incomplete.
The protocol’s audit is clean. Their public CVE count is zero. Their upstream dependency chain has 47 undisclosed fixes. Your thesis doesn’t account for what isn’t public.
Priced on crypto AUM · From 2 basis pointsYour models are missing half the data.
DeFi insurance premiums priced against incomplete risk databases. Protocols are financially rewarded for hiding vulnerabilities from you. We close the gap.
Priced on coverage volume · From 3 basis pointsFull dataset. Unrestricted.
Securities regulators and financial supervisory authorities receive unrestricted access to the silent patch intelligence feed. Market transparency should not be gated from the people responsible for it.
Supervisory bodies · Unrestricted accessFrom deceptive remediation to enforcement.
The work moves in three phases. Each produces an artifact the next phase depends on. Each is operational across every engagement we take.
Detect.
We find what vendors chose to bury.
Proprietary tooling monitors nine ecosystems for security patches that were never disclosed. When a vendor fixes a vulnerability and tells no one, we know.
When the evidence is reproducible and material, we have a case.
The Instrumentation
Continuous monitoring of the projects whose silent failures would compound furthest downstream.
Translate.
One finding, two artifacts, three voices.
A vulnerability report written for engineers does not move a securities regulator. A summary written for a regulator does not survive defense counsel. Both need to exist, in lockstep.
The technical brief carries the proof. The regulatory brief carries the consequence.
The Deliverable
Everything the receiving body needs to act on the day they open it.
Escalate.
From vendor inbox to subpoena power.
Most disclosure programs end at the email. The vendor patches quietly and the public record stays silent. We break the pattern by moving the destination.
We route findings to the body whose mandate is implicated, in its working language.
The Engagement
We stay through clarifying questions, supplementary filings, and where appropriate, testimony.
The arsenal.
Four instruments built for the work no off-the-shelf platform was designed to do. Each is in active use across current engagements.
Ghost Patch Scanner
Identifies security fixes that vendors buried without disclosure. Operates continuously across nine ecosystems. The output is a list of vulnerabilities your infrastructure inherited without your knowledge.
Cascade Engine
Quantifies downstream exposure when an upstream vendor silently patches. Produces a precise map of who is vulnerable, to what, and for how long. The output is the enforcement case, ready for regulators.
Hydra Deception Platform
Active defense infrastructure that responds to intrusion in real time. Built for operators who have outgrown passive monitoring and need adaptive tradecraft in production environments.
Regulatory Filing Pipeline
End-to-end workflow from vulnerability discovery to regulatory submission. Identifies jurisdiction, prepares filings in the receiving body’s working language, and tracks enforcement outcomes through to resolution.
If you have authority, we have the evidence.
Initial consultation free. All pricing published. No sales theater.
