XtrinelXTRINEL

About

Built for researchers. Open by default.

Xtrinel exists for independent security researchers, bug bounty hunters, and penetration testers who work at the frontier of AI security. We build free, open-source tools first — and commercial products for those who need more.

Research-first, always

Xtrinel started as a research project and that remains our center of gravity. Every detection we ship is paired with a public writeup. Every finding comes with a minimal repro script. Every offensive engagement requires written authorization. These are not marketing claims — they are the three rules that determine whether work ships at Xtrinel.

Open source as proof of work

HYDRACUDA — our runtime policy enforcement engine — is fully open source and MIT-licensed. The Seideray, Hekacy, and Fraegis benchmark series is open source and grounded in real disclosed incidents. These are not loss leaders for an enterprise upsell. They are tools we built because we needed them, released because the community needs them too.

VAAST — when you need more

VAAST is our desktop platform for AI security testing — prompt injection, tool-call abuse, RAG poisoning, and agentic pipeline flaws, all delivered as reproducible finding scripts. The free tier covers the basics. Pro unlocks the full offensive toolkit for individual practitioners. Enterprise adds team management for organizations that need it.

Get in touch

Headquartered in Columbus, Ohio. Working with researchers across North America and Europe.