Dreadnode
Scorecard
Offensive-security firm named by Google DeepMind as an external expert on Gemini testing.
VC-backed, Remote. Vendor / red-team co.; listed with commercial and first-party. Confidence low. Domains: cyber.
Conditional floor 7/8 evidenced under the standard policy Scores by preset: Lab procurement 42; Regulator or auditor 42; Public trust 44; Equal weights 43. Weakest evidenced dimension: governance 1/4. At least one evidenced dimension at 1: usable with conditions the card names.
What would move the score. Published engagement terms and a first public report.
- Funding 2 to 3: score 47
- Governance 1 to 2: score 44
- Access depth 1 to 2: score 48
Dissent, lower. Publication rights (1 to 0). Nothing from the Gemini engagement has reached the public: no summary, no finding, only the firm's name in Google's launch post and a spokesperson's sentence to Time. A name mention is not a lab-edited summary. Anchor 0 reads 'no publication, or lab approval required', and on the documented record there is no publication at all.
Dissent, higher. Access depth (1 to 2). Google's external-testing programme shares pre-release models with selected experts for structured testing over a period before launch, and Dreadnode was named for both Gemini 2.5 Pro and Gemini 3. If the engagement ran for weeks against a pre-release checkpoint, that is extended-time access, anchor 2, rather than a one-off pre-release API test.
Each value is the tightest admissible cap or, with no cap, the highest admissible floor, under RULES.md. The binding signal is highlighted. A dash means no admissible signal sets a bound under the standard policy.
- Lab-paid engagements. caps at 2 by F.3binding“obtained independent assessments from industry experts like Apollo, Vaultis, Dreadnode and more”
Gemini model documentation, external testing (Google DeepMind, 2025) tier 3 self (google)unverifiable A new era of intelligence with Gemini 3 (Google, 2025-11-18) tier 3 self (google)confirmed2026-09-14
- Venture-backed; no published COI policy found. caps at 1 by G.2binding“announced its $14 million Series A funding round, led by Decibel”
Gemini model documentation, external testing (Google DeepMind, 2025) tier 3 self (google)unverifiable Dreadnode Secures $14M to Build AI Systems that Advance the State of Offensive Security (Dreadnode, 2025-02-25) tier 3 self (dreadnode)confirmed Offensive AI Startup Dreadnode Secures $14M to Stress-Test AI Systems (SecurityWeek, 2025-02-25) tier 4 press (primary)confirmed2026-09-14
- Undisclosed. caps at 2 by P.5not counted under standard
Gemini model documentation, external testing (Google DeepMind, 2025) tier 3 self (google)unverifiable2026-09-14
- Named by Google DeepMind as an external cyber expert on Gemini testing. floors at 1 by A.1binding“obtained independent assessments from industry experts like Apollo, Vaultis, Dreadnode and more”
Gemini model documentation, external testing (Google DeepMind, 2025) tier 3 self (google)unverifiable A new era of intelligence with Gemini 3 (Google, 2025-11-18) tier 3 self (google)confirmed Exclusive: 60 U.K. Lawmakers Accuse Google of Breaking AI Safety Pledge (Time, 2025-08-29) tier 4 press (primary)confirmed2026-09-14
- Scope set by lab. caps at 2 by S.2binding“a “diverse group of external experts,” including Apollo Research, Dreadnode, and Vaultis”
Gemini model documentation, external testing (Google DeepMind, 2025) tier 3 self (google)unverifiable Exclusive: 60 U.K. Lawmakers Accuse Google of Breaking AI Safety Pledge (Time, 2025-08-29) tier 4 press (primary)confirmed2026-09-14
- Evaluation terms and results are not public. caps at 2 by R.3binding“a “diverse group of external experts,” including Apollo Research, Dreadnode, and Vaultis”
Gemini model documentation, external testing (Google DeepMind, 2025) tier 3 self (google)unverifiable Exclusive: 60 U.K. Lawmakers Accuse Google of Breaking AI Safety Pledge (Time, 2025-08-29) tier 4 press (primary)confirmed AIRTBench: Measuring Autonomous AI Red Teaming Capabilities in Language Models (arXiv (Dreadnode authors), 2025-06-17) tier 3 self (dreadnode)confirmed2026-09-14
- Methods and results are closed; no public methodology. caps at 1 by M.2binding“obtained independent assessments from industry experts like Apollo, Vaultis, Dreadnode and more”
Gemini model documentation, external testing (Google DeepMind, 2025) tier 3 self (google)unverifiable A new era of intelligence with Gemini 3 (Google, 2025-11-18) tier 3 self (google)confirmed2026-09-14 - Publishes AIRTBench, an AI red-teaming benchmark with open code (Apache-2.0) and results on Claude 3.7 Sonnet, Gemini 2.5 Pro and GPT-4.5; the Gemini engagement itself remains closed. floors at 3 by M.1“challenges from the Crucible challenge environment on the Dreadnode platform”
AIRTBench: Measuring Autonomous AI Red Teaming Capabilities in Language Models (arXiv (Dreadnode authors), 2025-06-17) tier 3 self (dreadnode)confirmed dreadnode/AIRTBench-Code (GitHub (Dreadnode), 2025-06) tier 3 self (dreadnode)confirmed2026-09-15
- Sells offensive-security products. caps at 2 by X.1 (second sentence)binding“two new products — Strikes and Spyglass — that form the core of its platform”
Gemini model documentation, external testing (Google DeepMind, 2025) tier 3 self (google)unverifiable Dreadnode Secures $14M to Build AI Systems that Advance the State of Offensive Security (Dreadnode, 2025-02-25) tier 3 self (dreadnode)confirmed Offensive AI Startup Dreadnode Secures $14M to Stress-Test AI Systems (SecurityWeek, 2025-02-25) tier 4 press (primary)confirmed2026-09-14
Values under each evidence policy
| Dimension | Leads included | Standard | Against interest | Verified spans | Primary only |
|---|---|---|---|---|---|
| Funding | 2 | 2 | 2 | 2 | – |
| Governance | 1 | 1 | 1 | 1 | – |
| Personnel | 2 | – | – | – | – |
| Access depth (lab-granted) | 1 | 1 | 1 | 1 | – |
| Scope control | 2 | 2 | 2 | 2 | – |
| Publication rights | 2 | 2 | 2 | 2 | – |
| Method transparency | 2 | 2 | 1 | 2 | – |
| Role incompatibility | 2 | 2 | 2 | 2 | – |
| Score, Lab procurement | 43 Conditional floor, 8/8 | 42 Conditional floor, 7/8 | 40 Conditional floor, 7/8 | 42 Conditional floor, 7/8 | – Unevidenced, 0/8 |
| Score, Regulator or auditor | 43 Conditional floor, 8/8 | 42 Conditional floor, 7/8 | 39 Conditional floor, 7/8 | 42 Conditional floor, 7/8 | – Unevidenced, 0/8 |
| Score, Public trust | 45 Conditional floor, 8/8 | 44 Conditional floor, 7/8 | 43 Conditional floor, 7/8 | 44 Conditional floor, 7/8 | – Unevidenced, 0/8 |
| Score, Equal weights | 44 Conditional floor, 8/8 | 43 Conditional floor, 7/8 | 39 Conditional floor, 7/8 | 43 Conditional floor, 7/8 | – Unevidenced, 0/8 |
Traced money and ties
no inflow rows yet. Confirmed rows: 0 of 0. Dollar sums: confirmed + unaudited USD rows only; imported figures are not re-derived and never summed. Second hop traced for 0 of 0 sources. Ties: none within two steps recorded. Bounded negatives on file: 0.
Ledger
No rows yet. Add one in data/ledger/.
Funding graph, focused
Neighbours at full strength, everything else faded. Hover any name to move the focus; click a name to open its page.