Cesium is an independent group focused on security research, privacy advocacy, and open-source development. We document vulnerabilities under responsible disclosure, build useful tools, and help individuals reclaim their digital privacy.
We document vulnerabilities and run responsible disclosure research across platforms, services, and software. All findings are coordinated with vendors before publication under a 90-day disclosure window.
We build open-source tools, utilities, and applications that serve the security and privacy communities. Practical software that solves real problems — released under permissive licenses.
We provide clear, actionable information on online privacy, FOSS alternatives, and digital self-defense. No jargon — practical guides for individuals who want to take back control of their data.
Every vulnerability we find is reported to the affected vendor first. We give a minimum of 90 days for a fix before any public disclosure. Security research only improves the ecosystem when it's done with care — not for clout.
Cesium was founded by a small group of security researchers, developers, and privacy advocates who wanted to build something honest — a place to publish real research, ship useful tools, and help people understand the threats they face online.
A small, distributed group. Some of us prefer to stay pseudonymous — this is the security world, after all.
Web application security, tool development and responsible disclosure coordination. Has reported to a number of platforms under responsible disclosure.
All findings published here have been disclosed to vendors prior to publication. CVE IDs are linked where assigned.
Practical, non-commercial guides on digital privacy, FOSS alternatives, and reclaiming control of your data. No affiliate links. No sponsored content.