Mattersec Labs

The researchers who named ExploitOps.

Software changes between security engagements. Mattersec Labs introduced ExploitOps in 2026 to connect each finding to an owner, a verified fix and a check against recurrence, and built MATT, the supervisor that runs it. This page is the people and the proof behind both.

The story

Why a new discipline, and why now.

Software changes between security engagements, and since 2026 frontier models have found and exploited the gaps in hours. A finding needs an owner, a verified fix and a check that catches the same failure again, or it stays a report.

We started with measurement. SecLens, our benchmark, scored frontier models on real vulnerabilities and found two things a buyer should know: the same model rates very differently depending on who is asking, and every model misses whole classes of vulnerability. A security programme built on one model’s score inherits that model’s blind spots.

That research, and securing the first organisations against exploits of this new kind, convinced us the work needed one loop and one name. ExploitOps is the practice Mattersec Labs introduced in 2026: observe what changes, prove what is exploitable, fix it with the team that owns the code, remember the fix as a check. MATT is the product that runs it.

Blueprint drawing of a benchmark grid: twelve cells with result bars, one bar in mint.
SecLens (Halder, Saxena, Shrish and M, 2026): 406 tasks from 203 real CVEs and their patched versions, 93 open-source projects, 10 languages, 8 OWASP categories, 35 dimensions, 12 frontier models.
The founders

The two people behind it.

  • Portrait of Subho Halder

    Subho Halder

    Co-founder & CEO

    Co-founded Appknox in 2014 and led it for twelve years, first as CTO and then as CEO, building mobile application security for enterprises. Lead author of SecLens, the benchmark of how frontier models detect security vulnerabilities. In application security since 2012, with acknowledgements from Apple, Google, Facebook and Microsoft. At Mattersec Labs, Subho leads MATT: the product, the research and the engagements.

  • Portrait of Aishwarya Jain

    Aishwarya Jain

    Co-founder & CBO

    Runs the commercial side of Mattersec Labs: customers, partnerships and go-to-market. Most of AJ’s work has been in crypto and blockchain: token launches, go-to-market and ecosystem growth for Web3 projects from Dubai, and advising CredShields, the Web3 security auditor, on security. The lesson of those years, that speed without trust creates risk, is why Mattersec exists.

How we work

Six things you can hold us to.

  1. 01

    Proof, before anything else.

    A finding is a working attack path in the agreed test environment, with the request and the response attached. Where a path cannot be reproduced safely, we say so and record it as a risk with the evidence we have.

  2. 02

    Your engineers approve every change.

    Fixes are written with the team that owns the code and merged by them. The first engagement is manual by design, so the rules are understood before anything runs on its own.

  3. 03

    Rules a board can read.

    Each fix becomes a plain-English rule. Where a check can run automatically it does, on every release; where it needs a person, the rule says who and when.

  4. 04

    We say exactly what we touched.

    The audit works from read access to your repository and a test login in an agreed test environment; the engagement letter sets the scope, permissions and handling before we start. Production data, secrets and customer records stay out of scope, and the final report lists every system actually assessed.

  5. 05

    Your pentest still counts.

    Penetration tests, AppSec programmes and bug bounties feed the loop. ExploitOps carries their findings through the fix, the verification and the check that catches the regression.

  6. 06

    Incidents, in the companies’ own words.

    The Record quotes official disclosures, dates and numbers, with one neutral pattern line. What we would have caught in someone else’s breach stays unsaid.

The company, in seven lines.

Company
Mattersec Labs Inc., a Delaware corporation
Where we work
San Francisco, Dubai and Bangalore
What we make
MATT, the AI Security Supervisor for the modern software lifecycle
How it runs
ExploitOps: observe, prove, fix, remember
How it starts
A sixty-minute ExploitOps Review to agree fit and priorities, then a scoped audit, then MATT on your release cycle
Appknox
Distribution partner for MATT; the mobile application security company Subho co-founded and led
Research
SecLens and the MatterSec 50, published by Mattersec Labs
Blueprint drawing of a research desk: two monitors, a laptop, a notebook and neatly routed cables.
ExploitOps discovery call

Understand where your security loop breaks.

A 15-minute call with a MATT co-founder to understand your product and whether an ExploitOps Review is worth doing. If there is a real need, we scope one with the research team.