Resource / Blogs /

We didn't change who we are. We finally said it out loud.

By
Murtuja Bharmal
October 5, 2026
4 min
Get Tested
Device, firmware and APIs scoped as one system.
Talk to an Expert
White arrow pointing diagonally upward to the right on a black square background.White arrow pointing diagonally upward to the right on a black square background.

For most of our history, the answer to "what does Payatu do?" depended on who you asked. Our testers would talk about the last engagement. Our researchers would tell you about a bug they were still chasing. Someone in the hardware lab would show you a board with its casing off.

None of them were wrong. But our website told only one of those stories.

This week we moved from payatu.com to payatu.ai. I want to explain why, because this is not a fresh coat of paint. It is us finally describing the company we have been for a long time.

It started with a community, not a company

Before Payatu existed, a few of us were already running Nullcon, bringing researchers together to share what they were breaking and how they were breaking it. Payatu grew out of that community in 2011. Aseem, Antriksh and I started it with one belief: the honest way to learn how to protect a system is to break it first.

That is research. It was there before our first client engagement, and it has shaped every one since.

We grew. The way we presented ourselves did not.

Over fifteen years, the company widened. We co-founded hardwear.io. We built a research team that finds and reports vulnerabilities in software and devices used around the world. We became CERT-In empanelled. We set up a hardware lab and had it accredited to ISO 17025. We founded EXPLIoT for the hardware security community offering tools and trainings needed to become an expert. Today we work with banks, manufacturers, healthcare companies and product firms in India and abroad.

We worked through each of these because there was a real need for it. What we never did was stop and ask whether our public face had kept up. It hadn't.

Someone who met us at a conference saw a research company. Someone who found us through a search saw a testing vendor, one of many. Neither picture was complete, and the second one was the one most people saw.

The question we had never asked ourselves

When we started the redesign, the first conversation wasn't about design. It was a question: what is Payatu, in one sentence every team here would agree is true?

It took us longer to answer than I expected. That alone told me the exercise was overdue. Two answers kept coming back.

  1. Research-led
  1. AI-native

Research is in our DNA

We have a team who is encouraged and assisted to go and find what nobody has found yet. They have reported vulnerabilities in widely used software and connected devices, and they present their work at Black Hat, DEF CON, Nullcon, hardwear.io, and many other national and international stages.

We fund this work deliberately, because it is where our methods and tools come from. The lab, the training. and the conferences all exist for the same reason. They are where we learn before we advise anyone else.

What we hadn't done well was talk about it. Most of it lived in conference slides and internal discussions. On the new site, research has its own home, and we will publish our findings, talks and tools as they happen.

We were working with AI before it became the headline

New technology has always pulled us in. We were taking apart connected devices when most people still saw IoT as a novelty, and AI was no different. Our team was testing AI/ML models long before AI security appeared on anyone's list of services. That work was our AI security assessment, which covers models, agents, and the systems built around them.

We also started putting AI and automation into our own processes well before the rest of the market caught on. This isn't limited to our technical teams. Sales, marketing, HR and finance at Payatu each have rebuilt parts of their work around it. That is the difference between a company that offers AI and a company that runs on it.

Why should that matter to you? Attackers adopt these tools quickly, and the skill needed to mount a serious attack keeps dropping. Defenders who don't keep pace fall further behind. We would rather learn how these systems behave on our own work first, so we already understand them when we're working on yours.

Why we moved to payatu.ai

We could have kept payatu.com and added a page about AI. We chose not to. A domain is the shortest sentence a company writes about itself, and ours needed to convey the right thing.

The .ai is not a pivot. The testing, red teaming, hardware and compliance work you know us for is all still here, done by the same people. What the name tells you, before you read a word, is how we work and where we are headed. It is also a commitment: once it is in the name, it can't be treated as a side project.

AI will now get you more coverage in your assessments with us and our expert researchers will lead the way.

What this means for you

If you already work with us, nothing about your engagement changes. Your contacts, engagements, and reports stay exactly as they are. You will simply see more of our research and thinking, published openly and more often along with AI giving you a wider coverage.

If you are looking at us for the first time, the new site is the most complete picture of Payatu we have ever put in one place.  

We didn't become a different company this year. We just finally said out loud what we had grown into.

Welcome to payatu.ai.

‍

‍

‍

Get Tested
Device, firmware and APIs scoped as one system.
Talk to an Expert
White arrow pointing diagonally upward to the right on a black square background.White arrow pointing diagonally upward to the right on a black square background.
Author
Murtuja Bharmal
Co-founder & Director
Red arrow pointing diagonally upward to the right.Red arrow pointing diagonally upward to the right.

Keep Reading

For Security Leaders
Agentic AI Security: The Hidden Attack Surface Beyond Prompt Injection
August 25, 2026
10 min
For Security Leaders
Research & disclosures
Binwalk Path Traversal Vulnerability: Turning Firmware Analysis into Code Execution
August 26, 2026
8 min
Guides & tutorials
For Security Leaders
An Introduction to Smali
August 26, 2026
8 min
Dark scene with vertical thin orange lines resembling distant illuminated bars or streaks against a black background and a faint horizontal red glow near the bottom.