Newsroom
Hades Enterprise is now in private preview.Request access
Hades
Enterprise

Your cloud.
Your findings.
Your disclosure protocol.

Hades is an adversarial AI. It reads your software, reasons about how it breaks, runs exploit attempts in an isolated sandbox, and returns a reproducible proof of every real weakness. For enterprise, the whole system deploys inside a peered VPC in your own cloud account — code, runs and findings all stay on your side of the boundary, delivered directly to your security team on a disclosure protocol you define.

VPC peeringSingle-tenantLanguage-agnosticCustomer-owned findings
Deployment model

A sealed Hades VPC — inside your cloud org.

Hades provisions a single-tenant VPC inside your own cloud organisation — AWS, GCP, Azure, Hetzner, OVH, or any EU-sovereign provider — in the region your compliance envelope requires. Hades operates that VPC end-to-end: harness, code graph, sandbox fleet, all sealed. It peers natively to your existing workload VPCs, pulls your code across the link, and runs every sandbox locally. Data residency is automatic — your cloud, your region — and your security team keeps operating exactly as they do today.

Customer cloud org
your region · your sovereignty
Your application network
10.40.0.0/16
  • ·Your repositories + services
  • ·Your data, secrets, keys
  • ·Findings + audit trail (yours)
  • ·Nothing leaves this boundary
YOU own
↔ VPC peer
encrypted · private · audited
Hades VPC · sealed, Hades-operated
10.80.0.0/20
  • ·Harness · deterministic runner
  • ·Code graph · structured analysis
  • ·Sandbox · ring-layered containment
  • ·No public egress · CVE research built-in
WE operate
Who controls what

Every boundary has a named owner — signed before any repo connects.

YOU
Cloud + identity

Your AWS Org, Azure tenant, or GCP Org. Your IAM, KMS roots, peering approval. Hades provisions the sealed VPC inside this boundary under scoped IAM you grant.

HADES
The system

Harness, code graph, sandbox fleet. All sealed, operated by Hades end-to-end, inside the VPC we provision in your cloud.

YOU
Code + findings

Your code enters the sealed VPC for analysis and never crosses your cloud-org boundary. Findings land in a customer-owned store you nominate; audit trail follows.

JOINT
Disclosure protocol

You define it in discovery — channels, keys, SLAs, ticket format. We build the pipeline to match and sign it into the engagement.

handoff — HADES-ENT-2026-0042

>finding: HADES-ENT-2026-0042

>target: acme-internal/checkout-svc@a1f2c

>severity: CVSS 8.9 · high

|reproduced: 11/11 runs · deterministic

>wrap: kms/alias/acme-sec-kek (customer)

>channel: s3://acme-sec-findings (customer)

>recipient: sec-team (pgp 4a9f...c2e1)

|envelope sealed · customer KMS

|delivered · recipient ACK received

>ticket: acme-jira SEC-4119 (created)

>audit: acme-sec-audit log written (customer)

!raw payload: never leaves your cloud org

|

How findings reach you

Direct, encrypted, on your protocol.

No public advisory portal. No vendor dashboard. Every finding is encrypted with your keys (PGP, KMS, or HSM), delivered on the channel you specify, and written to an audit trail you own.

The whole pipeline is a contract, not a default protocol. Discovery captures your channels, keys, SLAs and ticket format; the engagement brief pins them before any repo connects.

Finding workflow

Hades fits your process — not the other way around.

Enterprise change management is the expensive part. A new tool that reports findings in its own format forces months of internal work to translate, route and triage them. Hades doesn't do that. Discovery captures how your security team already operates — taxonomy, cadence, tooling, review gates — and the pipeline is built to match before the first finding is written.

Taxonomy
We adopt your severity scale, CWE mapping and category tags in discovery. Nobody on your team has to translate a Hades rubric into yours at 2 a.m.
Ticketing
Findings land in Jira, ServiceNow, Linear, or whatever your triage rotation already uses — with the custom fields, routing rules and SLAs your process requires.
Cadence
Batched weekly, streamed per-finding, gated on your review cycles — you choose. Hades holds findings until your cadence opens the window.
Reproducibility gate
Every finding clears a deterministic reproducibility gate before it's eligible to report. We'd rather let an odd false positive through that cleared ten runs than silently filter a true one.
How a pilot runs

From first call to steady cadence.

phase 01

Discovery

Scope, compliance envelope, disclosure protocol. One call, one engagement brief signed before any repo connects.

phase 02

Deploy

Hades provisions the sealed VPC inside your cloud org, peers into your workload networks, first target agreed with your team.

phase 03

First findings

Real targets, real findings. Every finding clears the reproducibility gate and lands on your disclosure protocol.

phase 04

Review

Scope expansion, ongoing cadence, long-term terms. The pilot transitions into a steady engagement.

Questions

Questions the committee will ask.

Q01

What languages and stacks does Hades cover?

Hades is language-agnostic. The harness procedurally stands up any codebase inside a ring-layered sandbox — regardless of language, toolchain or runtime — and probes it adversarially. There's no supported-stack list to check against; the sandbox orchestration is the point.

Q02

Does anyone on your side read our code or findings?

Hades adversarially reads and probes your code inside the sealed VPC — that is the product. No human on the Hades side reads findings or customer data. Hades operations may audit the deployment itself (the stack, not the data) for incident response.

Q03

How does Hades fit our existing security stack?

Hades is an autonomous runner, not another dashboard or portal. Your SOC, triage rotation and incident response all operate exactly as they do today — Hades becomes one more powerful tool in the mix. Ticketing output is the one integration routinely scoped; anything else is discussed case by case in discovery.

Q04

Where does it run, and where does our data live?

Inside your cloud organisation, in the region your compliance envelope requires. AWS Frankfurt stays Frankfurt; Azure Enterprise France stays France; GovCloud stays GovCloud. Hades does not operate a parallel footprint your data could leak into — the system runs in yours.

Q05

Who do we contract with?

Hades Security Pty Ltd, registered in Australia. DPA-ready, sub-processors published, insurance via named partners, no US legal nexus. EU enterprise engagements can additionally contract through Germany-based enterprise AI facilitation partners where a local entity is required.

Q06

How do you secure Hades itself?

Hades runs against Hades — every release is adversarially probed by the system on our own stack before it ships. Each customer-peered VPC is compartmentalised, versioned, and isolated from every other customer and from the main Hades cloud. Tight digital hygiene, scoped personnel access, and a threat model we treat as adversarial by default.