The Firm

Incorporated 2026 · New York · Austin · Los Angeles

,

§ A — Mandate

We push the horizons of how data is interpreted, analyzed and shaped. In an era where OSINT moves in minutes, due diligence must be faster, sharper and more defensible than ever.

§ B — Footprint
  • NYC New York City, New York
  • ATX Austin, Texas
  • LA Los Angeles, California
  • INC Incorporated 2026 · Delaware LLC

§ 01Philosophy

We model risk the way the cerebellum models movement.

The cerebellum does not move the body. It predicts what movement should feel like, compares that prediction against reality, and corrects before the error repeats. Cerebellum Intel Group works the same way: risk, entities, relationships and outcomes held in one living model, refined by feedback, surfacing deviation before it becomes damage.

We are not data vendors.

We are knowledge vendors.

Our product is predictive correction.

§ 02Genesis

Early work regularly paid for itself by catching problems before money moved.

Case study
§ A — Founders

Cerebellum was started by former redteamers and independent offensive-security researchers who moved to the defensive side. The same tradecraft once used to find weaknesses is now applied to protect clients, map adversarial research paths, and harden counterparties before capital moves.

§ B — First mandate

The firm was originally formed to deliver due diligence and audit support for a collector acquiring seven-figure assets. The mandate was simple: verify trustworthiness, quantify financial-loss risk, and give the decision-maker confidence before the wire left.

§ 03Bench

Principal
18+ YRS

WORMWOOD

AKA ANTHONY ORTIZ
Principal · Offensive & Defensive Cyber

18+ years across advanced red team operations, offensive cyber and enterprise risk management. Extensive coordinated-disclosure record, including critical-severity findings reported through authorised vulnerability disclosure programmes. Advises boards and security leadership on adversary exposure, and works across real estate, financial and asset management and offshore structuring, where counterparty exposure and beneficial ownership must be established before capital moves.

RED TEAMOFFENSIVE CYBERTHREAT INTELRISK MGMTRECOVERYOFFSHORE ADVISORY
LinkedIn
Standing

Publicly endorsed by senior offensive-security leadership in the vulnerability research community. Extensive global relationships across law firms, legal partners, cybersecurity practitioners and incident response teams.

Principal
14+ YRS

ENGRAM

AKA JEREMIAH WELLS
Principal · Intelligence & Research

14+ years across cyber intelligence and fraud defense at global financial scale, including 11 years at Visa. Built and led detection programs operating at enterprise scale. Traces adversaries through their infrastructure and automates the hunt. Former intelligence team lead. Corporate speaker on risk, adversary tradecraft and operational resilience.

INTELLIGENCEMILITARY CYBERTHREAT ANALYSISFRAUD DEFENSERED TEAMRISK MGMT

§ 03.1Composition

01OSINT
Business intelligence

Analysts trained in the collection, validation and synthesis of open-source, commercial and proprietary data. They bring a structured discipline to entity resolution, risk mapping and the detection of hidden relationships that conventional screening cannot replicate.

02ADV
Threat intelligence

Professionals who mapped adversarial infrastructure, fraud networks and attack patterns at scale. Their work informs how we assess counterparty exposure, attribute behavior and anticipate the paths a researcher or adverse party will take before they take them.

03IDD
Due diligence

Professionals who have built and run diligence programs for transactions, appointments and disputes. They know how to stress-test a narrative, protect source provenance and deliver findings that hold up in boardrooms, negotiation rooms and administrative proceedings.

04NET
Research network

Analysts and verified field researchers across the Americas, EMEA, the Gulf and Asia-Pacific. Inquiry is conducted lawfully, on the record where possible, and always with the client's exposure protected.

§ 03.2Alliance

ThreatCanary

Cerebellum maintains an active partnership with ThreatCanary, a next-generation cyber AI platform that replaces static, CVE-bound scanning with dynamic, AI-driven vulnerability research and adversarial security analysis. We are an authorised product vendor and reseller of ThreatCanary services and products.

The relationship is publicly endorsed by ThreatCanary and by Matt Flannery, Co-Founder of ThreatCanary and A/Director of Offensive Security for the New South Wales Government, whose work spans red-team offensive cyber operations, APT-level threat detection, government-sponsored vulnerability research and global security leadership. The endorsements are visible on the LinkedIn profile of principal WORMWOOD.

§ 04Standing

US
Delaware LLC
Registered · Principals disclosed

A registered firm, with named principals and no opaque layers.

Legal entity
Cerebellum Intel Group is a limited liability company registered in the State of Delaware and in good standing. Certificate of formation, registered agent details and jurisdictional filings are provided on request during onboarding.
Named principals
Every principal of the firm is disclosed on the registration. Work names are used publicly for operational discretion, but beneficial ownership is fully documented and shared with clients and counsel under NDA.
Vendor and counterparty screening
We apply the same standard to ourselves that we apply to a subject: every vendor, subcontractor and research partner is onboarded through identity verification and public-record review before any engagement data is shared.
Delaware incorporation
View our active Delaware filing on OpenCorporates. We publish this record because clients and counterparties should know exactly which legal entity they are engaging.

We believe in absolute transparency about who we are, how we are structured and how we obtain what we report. Clients are entitled to know the entity they are contracting with, the people accountable for the work, and the provenance of every finding delivered.

§ 05Intelligence tooling

AI usage is limited to observational and industry-standard practices.

Cerebellum employs machine-assisted collection and synthesis only as an extension of analyst judgment. Models are constrained to observational, publicly available inputs and industry-standard practices, augmented by proprietary optimizations and maintained by state-of-the-art developers. Every machine-generated signal is validated against source provenance before it enters a client deliverable.

§ 06Principles

  1. 01

    Interpretation over accumulation

    Data is everywhere. We shape it into structured knowledge instead of noise.

  2. 02

    Curated and QC'd

    Every finding is graded, corroborated and placed in actionable context.

  3. 03

    Referential ontology

    Entities, relationships and signals connected across jurisdictions and datasets.

  4. 04

    Speed without sacrifice

    Pace with international events, without losing defensibility or discretion.

  5. 05

    Redefining diligence

    Static reports replaced with living, recursive risk analysis.

§ 07Standards

Confidentiality
Compartmentalized engagements. Minimum-necessary case teams.
Data handling
Encrypted at rest and in transit. Contractual residency and destruction.
Methodology
Written per engagement. Confidence-graded, explicitly sourced findings.
Ethics
No deception, misrepresentation of identity, or unlawful access.
Independence
Never both sides of a dispute. Conflicts cleared before scoping.
Compliance
Public regulatory and enforcement records monitored continuously via open sources.

We turn data into knowledge.

Standing guidance to analysts
Engage