⚠   RESTRICTED ACCESS PROGRAM — MAXIMUM 5 PARTNERS PER CALENDAR YEAR — NDA REQUIRED — IDENTITY VERIFICATION REQUIRED   ⚠
Noctua Labs NOCTUA LABS Request Access →
Red Team Research Division
2026 Cohort: Accepting Applications

The Noctua
Research Engine.

The engine that built Axiom Zero. A classified red-team detection platform used internally by Noctua Labs to model, test, and dismantle advanced automated browser systems. We make it available to a maximum of five qualified partners per year — under strict contract, full identity verification, and non-negotiable research output obligations.

5
Maximum Partners Per Calendar Year Access is not sold. It is granted — conditionally, permanently revocably, and with full telemetry visibility retained by Noctua Labs at all times.

The internal platform we use to build Axiom Zero's detection layers.

The Noctua Engine is not a product. It is the research and red-team infrastructure that powers all of Noctua Labs' detection research — the same system that generated every evasion case study, hardware-physicality probe, and attacker model behind Axiom Zero's 105-layer architecture. Access is granted exclusively for legitimate security research conducted on your own infrastructure. All sessions execute against your remote allocation on Noctua Labs' development servers. You never receive source code, binaries, or backend access of any kind.

01
Remote-Only Execution
All engine execution occurs on Noctua Labs' development servers. Partners receive a credentialled remote session — never a local binary, SDK, or source tree. This is a non-negotiable architectural constraint across all tiers.
02
Full Telemetry Retention
Every query, probe run, and session action is logged with sub-millisecond fidelity and retained by Noctua Labs. For academic and researcher tiers, all activity is visible to our development team in real time. Commercial partners may negotiate limited data-handling clauses.
03
Research Output Required
Continued access is contingent on published or submitted research output — peer-reviewed papers, conference submissions, or internal technical reports — that cite Noctua Engine as the research instrument. Failure to produce research within the agreed timeline terminates access without refund.
👁
Full Telemetry Visibility — No Exceptions for Non-Commercial Partners
By applying for Academic or Security Researcher tier access, you explicitly acknowledge and consent that Noctua Labs' development team can observe every action taken within the Noctua Engine in real time — including all queries, probe configurations, result sets, session durations, and behavioral patterns. This is not a monitoring clause buried in fine print. It is a stated architectural reality of how the engine operates. We built it to understand automated systems. We apply the same rigor to understanding how our research partners use it. Commercial (Red Team) tier partners may negotiate specific data-handling and confidentiality clauses as part of their commercial agreement.

Three gates. Increasing access. Increasing obligation.

All tiers share the same non-negotiables: remote-only execution, NDA, identity verification, full telemetry retention, and research output obligations. Higher tiers grant greater compute allocation and extended feature access — not fewer restrictions.

Tier 01
Academic
For department heads and tenured professors at accredited universities researching automated system detection, browser forensics, or adversarial ML. Doctoral candidates may not apply directly — applications must be submitted by a supervising professor who will be the named access holder.
Custom Quoted per institution · Annual billing
Eligibility Requirements
  • Tenured professor or department head at an accredited university
  • Active academic email domain and institutional verification letter
  • Research proposal reviewed and approved by Noctua Labs
  • IRB or equivalent ethics board approval for research involving automation detection
  • Co-signed NDA naming the institution as guarantor
  • Commitment to minimum one peer-reviewed publication per access year
Hard Restrictions

Students are never granted access under any circumstances. Access is personal and non-transferable. Engine sessions may not be recorded, replicated, or shared with students, colleagues, or other institutions. All output data must be anonymised before any publication. Remote access only — no source code, binaries, or local installation ever provided.

Apply for Academic Access
Tier 02
Security Researcher
For credentialled penetration testers, independent security researchers, and vetted threat intelligence professionals. Access requires verified professional identity, demonstrated research history, and sponsorship from a recognised security organisation or conference program committee.
Custom Quoted per researcher · Annual billing
Eligibility Requirements
  • Government-issued ID and professional identity verification (OSCP, CEH, or equivalent)
  • Demonstrated public research history (CVEs, conference talks, published papers)
  • Sponsorship letter from a recognised security organisation or advisory board
  • Background check consent and review by Noctua Labs' security team
  • Individual NDA with personal liability clause
  • Minimum one technical write-up or conference submission per access year
Hard Restrictions

All session activity is visible to Noctua Labs in real time. Engine access is strictly limited to research on infrastructure you own or have explicit written authorisation to test. Any use against third-party systems without authorisation is grounds for immediate termination and legal action. No source code, binaries, or backend access — remote execution only.

Apply for Researcher Access
Tier 03
Red Team Commercial
For professional red team organisations and commercial security labs developing and testing detection evasion capabilities in controlled, authorised lab environments. The highest access tier. Highest price. Highest obligation.
$15,000 Per month · Annual commitment required · Net-30
Eligibility Requirements
  • Registered commercial entity with verifiable red team or security research mandate
  • Full corporate due-diligence review (registration, principals, operational history)
  • Authorised officer signature on Noctua Labs' commercial NDA and acceptable use agreement
  • Proof of air-gapped or isolated lab environment for all engine-adjacent work
  • Annual technical report submitted to Noctua Labs (may be confidential)
  • Named technical contact with direct accountability to Noctua Labs
Commercial Telemetry Terms

Commercial partners may negotiate specific data-handling and confidentiality clauses as part of their commercial agreement — this is the only tier where limited telemetry scope is negotiable. All other restrictions (remote-only execution, no source code, no backend access) remain non-negotiable regardless of commercial tier.

Apply for Commercial Access

Submit your credentials.
We respond to every qualified application.

Applications are reviewed by Noctua Labs' technical and legal team. We will request additional documentation during our review process. Submitting this form does not constitute an offer of access — it opens the review process.

Response time: 5–10 business days for initial eligibility assessment.

Partner Obligations — All Tiers
01 / NDA Legally binding non-disclosure agreement signed before any access is provisioned. Institution or corporate entity named as guarantor where applicable.
02 / Identity Full identity verification required. Government-issued ID, institutional affiliation confirmation, and professional credential verification before access review begins.
03 / Research Output Minimum one published, submitted, or internally delivered technical report per access year. Access renewal is contingent on demonstrated output.
04 / Telemetry All non-commercial session activity is visible to Noctua Labs in real time. By applying, you acknowledge this condition unconditionally.
05 / Scope Engine may only be used against infrastructure you own or have explicit written authorisation to test. Unauthorised use is grounds for immediate termination and legal action.
06 / Remote Only No source code, binaries, or local installation provided under any tier. All execution is remote. Backend access is never granted.
Access Application

By submitting, you acknowledge that Noctua Labs will conduct identity verification and that all activity within the Noctua Engine is subject to real-time telemetry monitoring. Review our Privacy Policy and Terms of Service. This form is transmitted over TLS 1.3.