
Security Researchers: Digital Fighters Series
Alice: “The vulnerabilities we identify could affect billions if discovered by the wrong people”
Roey Fizitzky, VP of Security Research at Alice, explores the challenge of building practical defenses for an ever-evolving AI threat landscape as part of CTech’s Security Researchers series.
“The hardest part of the work is often forming the right hypothesis,” says Roey Fizitzky, VP of Security Research at Alice, an AI security and safety company whose research organization includes 150 cybersecurity researchers working across security, adversarial research, and threat intelligence. “AI can accelerate the process, but experience, intuition, and imagination remain central to discovering how complex systems can fail,” he explains.
Within Israel’s cyber companies are small, highly specialized teams trained to think like attackers, find vulnerabilities and stay ahead of a threat landscape increasingly accelerated by AI. In this series, we meet the individuals and teams who make up this frontline of cyber: the digital fighters.
Fizitzky’s first introduction into security started at a young age. As he recalls, “I became fascinated by how computer games were protected and spent months learning how those protections worked and trying to break them.” Today at Alice, while the majority of their security findings are confidential, Fizitzky emphasises how “many of the vulnerabilities we identify could affect billions of users if discovered and exploited by the wrong people.”
You can read the entire interview below.
ID Card
Company name: Alice (Former ActiveFence)
Founders: Noam Schwartz, Iftach Orr, Alon Porat, Eyal Dykan
Year of founding: 2018
Current number of employees: 400
Company Description:
Alice (formerly ActiveFence) is an AI security and safety company working with AI labs, enterprises, and technology platforms to make AI models, agents, and applications safer and more secure. We test AI systems against security threats, adversarial behaviors, and complex real-world risks before and after they reach production. Our solutions include red teaming, real-time guardrails, threat detection, adversarial training data, and continuous monitoring to address risks such as jailbreaks, prompt injection, data leakage, and other security vulnerabilities. Alice’s vision is to enable AI to advance safely and securely.
About Alice's Security Research Team:
Our security research organization includes 150 cybersecurity researchers working across security, adversarial research, and threat intelligence.
The team brings together a wide range of expertise, from creating realistic threats and adversarial scenarios and testing frontier models in controlled environments to identifying emerging and security risks at scale. It is a combined security research and engineering effort, where researchers and engineers work closely together to turn new threat discoveries into practical defenses. This includes developing detection methods, building and testing security controls, analyzing new attack techniques, and continuously improving protections and model alignment as AI systems and threats evolve.
What is your background in cyber, and what led you to specialize in security research?
My interest in cybersecurity started at a young age. I was always curious about how things worked and enjoyed taking them apart to understand what was happening inside. My first real introduction to security came when I became fascinated by how computer games were protected and spent months learning how those protections worked and trying to break them.
Professionally, I started in cybersecurity working on a secure sandbox for Android applications, designed to protect sensitive information and control how it could be accessed and shared. I later worked on secure devices and systems for military and government customers, combining multiple technologies into highly secure solutions.
Throughout my life, I’ve been driven by the same mindset: understand how a system works, challenge it, find where it can fail, and use that knowledge to make it better and more secure. Today, I apply that same approach to AI security and frontier models.
What does your security research team look like in action?
Our teams combine deep technical research with the ability to deliver solutions at scale. We typically work with AI labs and large enterprises that come to us with complex security and privacy challenges that often don’t have off-the-shelf solutions.
Our methodology is largely problem-driven: a partner brings us a challenge, and we design the research approach broadly enough to uncover related issues beyond the original scope. Often, the investigation reveals vulnerabilities or attack paths the partner wasn’t aware of.
Because the field evolves so quickly, we build many of our own tools. One example is Rabbit Hole, our adversarial intelligence engine, which tracks adversarial data such as emerging jailbreaks and injection techniques across sources such as Telegram, Discord, and dark web forums, isolates specific attack patterns, and tests them against leading AI models. This helps us turn new threats into research inputs quickly as the landscape changes.
Our researchers typically work across several security domains rather than specializing in one narrow area. We’ve found that experience across multiple domains helps researchers understand complex problems faster, identify connections that might otherwise be missed, and provide more comprehensive solutions to our partners.
Our work requires a unique combination of technical depth and creativity. We often approach systems as black boxes, with limited visibility into what’s happening behind the scenes. Much of our success comes from experience, intuition, and imagination: the ability to form hypotheses about how a system works internally and find creative ways to test them.
How does the research team influence your company at large?
Our research team directly shapes both our products and the way we respond to new threats. When researchers identify a new attack technique, vulnerability, or failure mode, that work can feed into detection methods, tests, and security controls. Because researchers and engineers work closely together, findings can be translated into practical defenses and used to improve how our systems are tested and protected as AI systems and attack methods evolve.
What has been your team’s most significant security discovery to date?
The majority of our security findings are confidential, so we’re not able to share the details publicly. However, the potential impact of our work is significant. Many of the vulnerabilities we identify could affect billions of users if discovered and exploited by the wrong people.
One recent example we can share at a high level involved an account takeover vulnerability in a widely used product. The vulnerability was uncovered during a security investigation by our team. Given its severity and potential impact, we immediately reported it to the relevant team.
Who or what is your 'Moby Dick'?
My “Moby Dick” is a Trusted Execution Environment (TEE). A TEE is a secure, isolated area inside a computer where sensitive code and data can run safely, protected even from the rest of the system.
I’m fascinated by how TEEs use hardware-backed isolation to protect sensitive code and data, even from privileged software. Finding a weakness in such a deeply protected environment would require creativity and a strong understanding of both hardware and software security.
How would you characterize the competition between research teams today?
I see the competition between research teams as strong but healthy, both locally and globally. Teams constantly push each other to discover new vulnerabilities and develop more advanced research methods.
Israel has a strong research community, in part because many researchers gain hands-on experience with complex cybersecurity challenges at a young age during their military service. They later bring that experience into the private sector and to research teams working on widely used products and services.
At the same time, cybersecurity is a field where collaboration and knowledge sharing are just as important as competition. Every new discovery can contribute to the wider research community and help improve security for everyone.
What is your take on the future of the human security researcher?
I believe AI will empower security researchers rather than replace them. It can help us analyze complex systems faster, automate repetitive tasks, and explore classes of attacks that would be difficult to investigate manually.
The human researcher will still be essential because the hardest part of the work is often forming the right hypothesis: understanding how a system may work internally, spotting connections that are not obvious, and finding creative ways to test them. AI can accelerate the process, but experience, intuition, and imagination remain central to discovering how complex systems can fail.














