Last night we joined OWASP® Foundation's Peterborough chapter meet-up at The Brewery Tap. Thanks to the OWASP Peterborough chapter for having us. Harry Wetherald talked through the road from AI prototype to production, and the questions from the room were exactly the sharp, inquisitive kind we hoped for. Also a pleasure sharing the bill with ☁️ Francesco ☁️ Cipollone of Phoenix Security | ASPM. Good talks, good crowd, good drinks. See you at the next one.
About us
Maze uses AI agents to investigate vulnerabilities across code and cloud using a unified engine. Maze agents understand your environment and prove which findings across code and cloud are exploitable. Once a vulnerability is confirmed exploitable, agents generate a fix and route it to the developer or AI agent who owns that code. Learn more at mazehq.com.
- Website
-
https://mazehq.com/
External link for Maze
- Industry
- Computer and Network Security
- Company size
- 11-50 employees
- Headquarters
- London
- Type
- Privately Held
- Founded
- 2024
Locations
-
Get directions
5 New Street Square
London, EC4A 3TW, GB
Employees at Maze
Updates
-
Join Harry Wetherald and Ryan Winstanley at OWASP® Foundation's Peterborough meet-up tonight. Harry is going to share many of the things we've learnt over the last two years at Maze.
Looking forward to OWASP® Foundation Peterborough's Cyber meet-up tonight with Ryan Winstanley! My talk is on building AI agents, sharing many of the things we've learnt over the last two years at Maze. In other words, trying to help you all avoid the many pitfalls that come up when you try take an agent from looking good in a demo to production scale/accuracy. Link the comments for any last minute sign ups.
-
-
Maze reposted this
This week, OpenAI halved GPT-6 prices and Anthropic released Opus 5.5 at 20% below Opus 5. The newest, best models are now launching cheaper than the ones they replace. But what are the implications for cyber SaaS products? The frontier labs take most of the revenue but don't have much choice because open-weight models now carry most developer tokens. This trend might be hard to revert as hyperscalers are getting close to serving open/close models side by side and keep adding inference capacity, making quotas less of an issue. The popular read is that cheap inference kills SaaS because customers will build it themselves. I think it's the opposite. Cheap inference is available to everyone, customers included, so it can't be what you sell. If your product is a thin layer over a model, every price cut makes it easier to replace. However, even with free inference, a single company can't reproduce what you learn from investigating the same vulnerability across many different environments. That's how you find the rare conditions that make a CVE exploitable, learn where investigations go wrong, and see which fixes work and which backfire. Cheaper inference also changes what you can afford to do: run over much larger data sets, pull in more context per asset, and spend more reasoning on the hardest cases. Staying model-agnostic matters even more now, because frontier and open models leapfrog each other every few months. Teams with good evals and a harness that can swap models in a day get the new edge first, while teams that fine-tuned a snapshot are left maintaining it. Cheap cloud computing didn't kill software companies, it created a lot more of them, and I think cheap inference will do the same.
-
Are you building with or thinking about building with AI? If so, you don't want to miss this webinar next week!
Working with agents is one of those things where almost anyone can get to something that looks good, fast. That early success is often kinda misleading. The usual story: "We got a working version in a couple of weeks, so the rest is just minor improvements." That's really where the actual work starts. Your prototype nails the handful of test cases you built it around. Then in prod you get pummelled with edge cases, stale data, eval requirements, model drift, blah blah blah. We know because we lived it. And the hardest problems weren't the ones we expected going in. On September 29th (11:00–11:45am ET), Santiago Castiñeira is walking through the hardest challenges we solved building Maze. If your team has a working AI prototype right now, or is about to start one, these 45 minutes will save you some expensive lessons. Registration link in the comments.
-
Maze reposted this
In seven months, the amount of code shipped per engineer at Maze increased by nearly 4x. The hardest part wasn’t technology or tooling, it was working with the team on a common approach. Some engineers worried they were being left behind as colleagues accomplished more with coding agents, while others could barely stop working. They had more ideas than ever, and suddenly each one was cheap enough to build and test. I'm convinced the human side is where most of the time goes, and it's the part that's easiest to underestimate when you're focused on the tooling. For us that meant sharing real workflows, talking honestly about what wasn't working, and pairing people who were at different stages of the transition. The improvement now shows up everywhere we look: code shipped, number of PRs, but also how fast features reach customers. Adopting coding agents is a group alignment problem. The day-to-day looks very different now, but we're still the ones deciding what to build and whether it's good enough.
-
-
Ask an AI tool the same question twice and you might get two different answers. For security teams, that gap matters as much as the raw intelligence. Harry Wetherald joined Mariana Padilla on the Spill It Podcast (from Harmonic Security) to discuss why the right answer is only right when you get it every time. Link to the full episode is in the comments.
If an AI tool gets a task wrong 50% of the time, and you can't verify it's work, is that unethical? Had some fun recording this episode of the Spill It Podcast (from Harmonic Security) with Mariana Padilla where we covered this topic and a lot more. I recommend checking out the show in the comments!
-
Maze Code found a key confusion bug in the most downloaded JWT library in Python (590 million monthly downloads), PyJWT. Are you affected? Find out, link in comments.
We found a new key confusion bug in PyJWT that lets an attacker forge login tokens using nothing but your public key. PyJWT is the most downloaded JWT library in Python. Over 590 million downloads a month. This vulnerability stayed hidden for over a decade because no tool was capable of finding it. Bugs like this won’t stay hidden anymore. It’s getting easier and cheaper to find novel vulnerabilities like this one, and defenders need to find them and patch them before attackers do. Read about how Maze Code agents found it during a routine scan of PyJWT. Full blog in the comments.
-
-
Maze reposted this
Both things can be true: 1) Leaders of AI labs are genuinely worried about the pace of progress and what the next few generations of models will be capable of 2) It's good for business when the leaders of AI labs terrify everyone about AI risks You can argue that recent news about AI is exaggerated, but what frontier models are starting to do in cyber, biotech, and elsewhere is obviously dangerous. Dismissing AI risk because 'AI labs are self-interested' is just as misguided as dismissing the upside potential of AI because 'it's just fancy auto-complete'. AI is solving Millennium Prize problems and hacking real businesses without human instruction, and the debate we're having is about regulatory capture? There are and will continue to be games being played on all sides, but we can't let that distract us from the real problems. Too much is at stake for us to dismiss AI risks just because the AI Labs stand to gain by talking about them.
-
Join the Maze team in Denver for food, fun, and and a talk on building reliable AI tools. RSVP using the link in the comments.
Come join Joseph Barringhaus and I at Dave & Buster's in Denver for the OWASP Denver meet-up this Thurs 5:30 - 8:30pm MDT! There will be food, drinks, and arcade games, plus a talk on the hardest problems we've solved while building Maze. Come for the security conversation, stay to beat us at air hockey. Registration link in comments.
-
-
Arriving early to the Gartner Security & Risk Management Summit? Join Will Patterson, Manifold Security, CyberForce Global, and 20 of your peers at ROKA Canary Wharf for a Japanese robatayaki tasting menu with sake pairing. Reserve your spot using the link in the comments.
In London for the Gartner Security & Risk Management Summit? Come a night early and have dinner with us! Manifold Security, Maze and CyberForce Global are taking over the terrace at ROKA Canary Wharf on September 21st. It's a Japanese robatayaki tasting menu with sake pairing, shared with about 20 security leaders. Seats are limited, so register early at the link in the comments.
-