Research with operational controls
Queue hunts, assign work to workers, set budgets, and track usage and cost. Pause or steer managed jobs at checkpoints, with commands and acknowledgements recorded.
Turn open-ended vulnerability research into a traceable process. Run focused hunts, inspect every decision, and keep the evidence that matters.
For researchers, security teams, and the agents they work with.
Example Forms 2.4.1 · Permission boundary review
Negative results apply only to the tested routes, accounts and inputs.
The fixture contains private form entries. Only administrators may export them; individual entries are readable by their owner or an administrator. Test the five listed hypotheses.
Interactive hunt preview · Playback condensed to show the workflow.
Each hunt develops and tests hypotheses as the investigation progresses. These example branches show how results shape the next experiment and which candidates proceed to reproduction and review.
Example research paths
Feedback to the hunter · refine and repeat
fractureai goes beyond an API wrapper or a prompt-and-tool loop. It manages the work around the model: durable research jobs, isolated test environments, execution controls, usage tracking, and evidence that remains available after the conversation ends.
The model helps decide what to investigate. fractureai gives that investigation a place to run, a record of what happened, and a path to review the result.
Queue hunts, assign work to workers, set budgets, and track usage and cost. Pause or steer managed jobs at checkpoints, with commands and acknowledgements recorded.
Search run events, retrieve full tool transcripts, and inspect the original artifacts. Checksums connect the evidence you review to the bytes that were stored.
Use the dashboard or let Codex and OpenCode work through explicit APIs and MCP tools. Jobs, controls and research records live in the platform, so the workflow can continue across sessions.
Built on AMD GPUs
Our backend runs on AMD GPUs. fractureai brings hunt orchestration, job controls and a complete evidence trail to the research running on that infrastructure.
An update from fractureai about the hardware we use. No AMD partnership or endorsement is implied. AMD and the AMD Arrow logo are trademarks of Advanced Micro Devices, Inc.
fractureai uses Z.ai's GLM models to power its primary hunter. They help reason about code, develop hypotheses and guide tests, while fractureai preserves the tool calls, transcripts and evidence for review.
Explore Z.ai models ↗We run models entirely on our own infrastructure in the Karlcom.de data center. We also use Z.ai models hosted in German data centers for our hunts.
Z.ai is credited as the provider of the models used in this integration. fractureai is independent; no partnership, sponsorship or endorsement is claimed. Z.ai's name and logo belong to their respective owner.
Search across runs. Read the complete transcript. Retrieve the exact artifact behind a finding. fractureai keeps the details available when the interesting question is “why?”
Original bytes remain available. A summary never replaces the source.
Work in the browser, Codex, or OpenCode. The same durable jobs and explicit controls sit underneath.
“Show the failed parser tests from the last run, retrieve their evidence, and explain what changed.”
Bounded search results keep context useful. Full event payloads and artifacts are one step away.
fracture_control({"id": "<managed-job-id>", "action": "pause", "idempotency_key": "review-parser-run"})Example request. A recorded command is distinct from its acknowledgement.
What the platform does, what the model contributes, and where human judgment still matters.
You can, and for a focused question that may be enough. fractureai is built for investigations that continue beyond a single conversation: it keeps jobs, experiments, costs, transcripts and evidence together. The value is in running and reviewing the research, not simply generating a list of possible bugs.
fractureai uses model APIs and an agent execution loop. Around that it provides durable job management, isolated test environments, execution controls, searchable traces and retained evidence. Those are the capabilities to judge it on. A model response alone is not treated as a verified finding.
A hypothesis is a question worth testing. An experiment may support it, rule it out or leave it unresolved. A candidate finding needs reproduction and review, with the relevant requests, responses, source references and artifacts attached. Even a reproduced result still needs a person to assess scope, impact and disclosure.
No. Models can miss issues, misunderstand code and produce false positives. fractureai helps organize and carry out research; it does not guarantee complete coverage or a vulnerability-free result. Researchers remain responsible for authorization, interpreting evidence and deciding what to report.
The emphasis here is traceable, agent-driven research: explicit job controls, full tool transcripts and evidence that can be retrieved independently of a chat. Other tools may offer similar capabilities. Compare them on your own targets, including reproducibility, false positives, retained evidence and actual operating cost. We do not claim universal superiority.
It illustrates a permission-boundary investigation: hypotheses emerge, tests rule some out, and a supported candidate is reproduced. Playback is condensed. The displayed token usage, cost and outcome describe this example; they are not a benchmark, a price quote or a promise of results.
Yes. The platform exposes APIs and MCP tools for job management, controls and evidence retrieval. An authorized agent can use the same records and operations as the dashboard. A submitted command and the worker’s acknowledgement remain distinct, so an agent can check whether an action actually happened.
Hunts have explicit budgets and recorded usage so you can inspect spending. Token costs depend on the model and workload; a budget is not a guarantee of a finding. Research traces can contain sensitive code or output. Access is restricted, and operators must configure provider choices, permissions and retention for their deployment.
Public accounts are not open yet. Where launch notifications are enabled, you can request an email and confirm it separately. This creates no research account.
Public accounts aren't open yet.
Launch notifications will open soon.