Skip to main content
Comparison · Horizon3 NodeZero

Horizon3 is strongest where the test starts inside your network

NodeZero runs an internal pentest from a free Docker host or a virtual appliance you stand up yourself, and a thirty-day self-service trial lets you run one without speaking to anybody. That is what they are best at, and it is conceded here in the opening paragraph rather than at the foot of the page. What differs is the rest: which classes each product covers, what has to stand inside your network for an authenticated application test, and what each of us publishes as a price.

Their published position was last read on 2026-09-14. Every claim below carries the page it came from and the date it was checked.

What Horizon3 sells

NodeZero, and the four tiers it is sold in

Their account of their own product comes first. A comparison that opens by characterising somebody else has already lost the reader who came here to check it.

NodeZero is autonomous penetration testing sold in four named tiers — Flex, Core, Pro and Elite — running from episodic testing at the entry tier to risk-based exposure management at the top. No dollar figure is published against any of the four. Twelve modules sit in every tier including the entry one, among them internal and external pentesting, external asset discovery, cloud pentesting, Kubernetes pentesting, an Active Directory audit, phishing impact testing, endpoint security effectiveness and fix actions with verification. Web application testing is the exception: NodeZero WebApp was released on 29 July 2026 and is sold as an add-on on top of whichever tier you hold, in an episodic and a continuous variant. Pentera announced web application penetration testing on the same day, in beta — which says something about where this category is going, and nothing about either announcement being a reaction to the other. One more thing worth knowing before any comparison is drawn: their compliance page offers expert human analysis by Offensive Security Certified Professional pentesters alongside the platform, so they are not a software-only vendor in a deal where a filing wants a person to sign it.

The packaging

What is in every tier, and what is sold on top

Read from their own pages on 2026-09-14. The tier names are public; no price is, so none is quoted here.

What it isWhat they publish
Four tiers, by name NodeZero Flex, Core, Pro and Elite — episodic testing, continuous testing, precision threat detection with emerging threat intelligence, and risk-based exposure management. No dollar figure is published against any of them.
horizon3.ai/pricing/, read 2026-09-14.
In every tier, entry included Internal and external pentesting, external asset discovery, cloud pentesting, Kubernetes pentesting, an Active Directory audit, phishing impact testing, endpoint security effectiveness, fix actions with verification, reporting, a vulnerability management hub and an MCP server.
Twelve modules, listed on the same page. horizon3.ai/pricing/, read 2026-09-14.
Sold on top, in two variants NodeZero WebApp pentesting — episodic beside Flex, or continuous beside Core, Pro and Elite. It is listed separately from the twelve rather than inside them, so a buyer at the entry tier does not have web application testing until they add it.
horizon3.ai/pricing/, read 2026-09-14.
Delivered by people, not the platform Expert human analysis by Offensive Security Certified Professional pentesters, offered beside NodeZero on their compliance page. Any comparison that treats them as software-only is wrong in a compliance-driven deal.
horizon3.ai/compliance/, read 2026-09-14.
Where each run happens Internal tests run from something you stand up inside your own network. External tests run inside their infrastructure, on dedicated, ephemeral resources in an isolated virtual private cloud network, in their words, with nothing placed in yours.
horizon3.ai/nodezero/, read 2026-09-14. An earlier internal note of ours had this second half wrong, and the row states it the way their platform page does. That page was read on external testing; where a cloud test executes is not stated here, because no sentence of theirs was read that says.

Four tiers, by name

What they publish
NodeZero Flex, Core, Pro and Elite — episodic testing, continuous testing, precision threat detection with emerging threat intelligence, and risk-based exposure management. No dollar figure is published against any of them.

horizon3.ai/pricing/, read 2026-09-14.

In every tier, entry included

What they publish
Internal and external pentesting, external asset discovery, cloud pentesting, Kubernetes pentesting, an Active Directory audit, phishing impact testing, endpoint security effectiveness, fix actions with verification, reporting, a vulnerability management hub and an MCP server.

Twelve modules, listed on the same page. horizon3.ai/pricing/, read 2026-09-14.

Sold on top, in two variants

What they publish
NodeZero WebApp pentesting — episodic beside Flex, or continuous beside Core, Pro and Elite. It is listed separately from the twelve rather than inside them, so a buyer at the entry tier does not have web application testing until they add it.

horizon3.ai/pricing/, read 2026-09-14.

Delivered by people, not the platform

What they publish
Expert human analysis by Offensive Security Certified Professional pentesters, offered beside NodeZero on their compliance page. Any comparison that treats them as software-only is wrong in a compliance-driven deal.

horizon3.ai/compliance/, read 2026-09-14.

Where each run happens

What they publish
Internal tests run from something you stand up inside your own network. External tests run inside their infrastructure, on dedicated, ephemeral resources in an isolated virtual private cloud network, in their words, with nothing placed in yours.

horizon3.ai/nodezero/, read 2026-09-14. An earlier internal note of ours had this second half wrong, and the row states it the way their platform page does. That page was read on external testing; where a cloud test executes is not stated here, because no sentence of theirs was read that says.

Where Horizon3 is stronger

Internal network testing is the thing they do best

Said before any point of difference, because it is true and because a page that concedes nothing is a brochure with a comparison table stapled to it.

Horizon3 runs an internal pentest from a free Docker host or a preconfigured virtual appliance you stand up yourself, and the requirements for it are published in full — operating system, container runtime, processor cores, memory, disk, down to the instruction not to run endpoint detection on that machine. A thirty-day trial is genuinely self-service: a company email, verified once, and you can run a real internal pentest against your own network without ever speaking to a salesperson. That is a strong offer and it is why they win evaluations. What runs on top of it is harder than it looks from outside: real credential attacks, password spraying, Zerologon and remote-access implantation, executed against live production networks without taking them down, with the more than 6,500 organisations named in their 29 July 2026 release behind that attestation. If internal network testing is the first line of your requirement, they are strong there.

The rest of the concession

Five more things Horizon3 is better at, named

Each of these is theirs. None is hedged here with something of ours in the same breath.

Coverage we do not have

Kubernetes

NodeZero tests live, running clusters for RBAC misconfigurations, container escapes and secret exposures, and it sits in every tier including the entry one. B-52 has eleven coverage classes and Kubernetes is not one of them. If Kubernetes testing is on your list, Horizon3 covers it and we do not.

Authorisation of the platform

A United States federal authorisation, assessed by an outside body

NodeZero Federal carries a high-impact United States government authorisation, reviewed by an accredited third-party assessment organisation and announced on 15 May 2025. It is an outside judgement on their product rather than their own statement about it, and it opens federal procurement. We have no equivalent.

Breadth at one price point

More named modules on their sheet

Internal, external, external asset discovery, cloud, Kubernetes, Active Directory audit, phishing impact testing and endpoint security effectiveness all sit in the entry tier. A buyer counting line items across those categories will see more of them on their sheet than on ours, and that impression is accurate.

Automation surface

A documented API, and a command-line tool for it

A single GraphQL endpoint schedules tests and returns weaknesses, hosts, credentials and attack paths; the h3-cli tool wraps it; and setup guides are published for Jira, ServiceNow VR, Splunk Cloud and Microsoft Sentinel. A platform team can wire Horizon3 into the tooling it already runs without buying professional services.

Market position

Scale, and the money behind it

Their July release puts NodeZero in more than 6,500 organisations and names the NSA, CISA and four of the Fortune 10. An EMEA head office opened in Amsterdam in June and a Series E round closed in August. In a room where nobody is criticised for choosing the funded leader, that counts, and pretending otherwise would be the weaker argument.

Where the two diverge

Seven differences, each one checkable

Their column is what they publish, with the page and the date on the row beneath it. Ours is what B-52 publishes and can be held to.

Horizon3, as publishedB-52
Coverage classes Twelve modules in every tier: internal, external, external asset discovery, cloud, Kubernetes, Active Directory audit, phishing impact testing, endpoint security effectiveness, fix actions with verification, reporting, a vulnerability management hub and an MCP server. Web application testing is an add-on beside them. Eleven coverage classes: web application, mobile app, API, thick client, external network, internal network, cloud, Active Directory, social engineering, secure code review and LLM applications. Physical, hardware and wireless are out of scope for the platform, in every class.
horizon3.ai/pricing/, read 2026-09-14.
Mobile, thick client, code review, LLM Not named as modules on their pricing page. API endpoint discovery appears inside the web application add-on rather than as a class of its own. Four of the eleven classes. Mobile, thick client and secure code review are three of the five classes the self-serve card flow reaches; LLM application testing is scoped with us.
What stands inside your network Their documentation states that a NodeZero Runner with network connectivity to the target is required in order to use the credentials, and that applications behind a VPN or a private network are tested through one. Unauthenticated, internet-reachable applications need no such machine. A credential for each role you want exercised, and nothing standing in your network. That holds for authenticated testing across the five application classes.
docs.horizon3.ai/portal/test_types/webapp/, read 2026-09-14. This is the difference that survived re-verification, and it is about authenticated testing specifically.
Where the control plane runs A portal they operate, with United States, European Union and Australian portal domains named in their network documentation. NodeZero Federal is described as secure software as a service with enforced single sign-on. On-premise, or inside your own virtual private cloud, both available today. Residency in India, the European Union, the United States and Singapore.
Their cloud pentesting page also carries the sentence “NodeZero is deployable both on-prem and in the cloud”. It is printed here rather than left for you to find. Both pages read 2026-09-14.
The route into a build pipeline CI/CD appears in one place on their site: the MCP server page, where “security validation in CI/CD pipelines before deployment” is named, in their words, as a use for agents consuming exploitability data. The GraphQL API and h3-cli are the documented automation surface. Four systems in production: GitHub Actions, GitLab CI, Jenkins and Azure DevOps. A result can fail a build on a severity threshold you set.
horizon3.ai/nodezero/mcp-server/ and docs.horizon3.ai/api/graphql/, read 2026-09-14.
The published price Four tier names, and no figure against any of them. $500 for one scan of one application or target, and a paid trial at $299. Above that the ladder is not published: a larger scope is a scoping call.
horizon3.ai/pricing/, read 2026-09-14.
Whose signature the report carries Offensive Security Certified Professional pentesters, offered beside the platform on their compliance page. Three delivery models — fully autonomous, autonomous expert verified, and human led. All three cover all eleven classes; in the two with a senior auditor in them, every finding is verified and the report carries Security Brigade’s signature, empanelled by CERT-In since 2008.

Coverage classes

Horizon3, as published
Twelve modules in every tier: internal, external, external asset discovery, cloud, Kubernetes, Active Directory audit, phishing impact testing, endpoint security effectiveness, fix actions with verification, reporting, a vulnerability management hub and an MCP server. Web application testing is an add-on beside them.
B-52
Eleven coverage classes: web application, mobile app, API, thick client, external network, internal network, cloud, Active Directory, social engineering, secure code review and LLM applications. Physical, hardware and wireless are out of scope for the platform, in every class.

horizon3.ai/pricing/, read 2026-09-14.

Mobile, thick client, code review, LLM

Horizon3, as published
Not named as modules on their pricing page. API endpoint discovery appears inside the web application add-on rather than as a class of its own.
B-52
Four of the eleven classes. Mobile, thick client and secure code review are three of the five classes the self-serve card flow reaches; LLM application testing is scoped with us.

What stands inside your network

Horizon3, as published
Their documentation states that a NodeZero Runner with network connectivity to the target is required in order to use the credentials, and that applications behind a VPN or a private network are tested through one. Unauthenticated, internet-reachable applications need no such machine.
B-52
A credential for each role you want exercised, and nothing standing in your network. That holds for authenticated testing across the five application classes.

docs.horizon3.ai/portal/test_types/webapp/, read 2026-09-14. This is the difference that survived re-verification, and it is about authenticated testing specifically.

Where the control plane runs

Horizon3, as published
A portal they operate, with United States, European Union and Australian portal domains named in their network documentation. NodeZero Federal is described as secure software as a service with enforced single sign-on.
B-52
On-premise, or inside your own virtual private cloud, both available today. Residency in India, the European Union, the United States and Singapore.

Their cloud pentesting page also carries the sentence “NodeZero is deployable both on-prem and in the cloud”. It is printed here rather than left for you to find. Both pages read 2026-09-14.

The route into a build pipeline

Horizon3, as published
CI/CD appears in one place on their site: the MCP server page, where “security validation in CI/CD pipelines before deployment” is named, in their words, as a use for agents consuming exploitability data. The GraphQL API and h3-cli are the documented automation surface.
B-52
Four systems in production: GitHub Actions, GitLab CI, Jenkins and Azure DevOps. A result can fail a build on a severity threshold you set.

horizon3.ai/nodezero/mcp-server/ and docs.horizon3.ai/api/graphql/, read 2026-09-14.

The published price

Horizon3, as published
Four tier names, and no figure against any of them.
B-52
$500 for one scan of one application or target, and a paid trial at $299. Above that the ladder is not published: a larger scope is a scoping call.

horizon3.ai/pricing/, read 2026-09-14.

Whose signature the report carries

Horizon3, as published
Offensive Security Certified Professional pentesters, offered beside the platform on their compliance page.
B-52
Three delivery models — fully autonomous, autonomous expert verified, and human led. All three cover all eleven classes; in the two with a senior auditor in them, every finding is verified and the report carries Security Brigade’s signature, empanelled by CERT-In since 2008.

One class, three situations

What has to exist before an application can be tested

The sharpest difference between the two products is not what gets tested. It is what must already be standing before the test can run — and it changes situation by situation, so it is read here from their documentation rather than asserted in one line.

01 Situation one

Reachable from the internet, no login

What their documentation says
Nothing is needed. An unauthenticated, internet-reachable application is tested without anything of theirs standing in your network.
What B-52 needs
Nothing. The same picture, from the other side.
What differs
Nothing differs at this row, and a comparison page that invented a difference here would deserve the checking it got.
02 Situation two

The same application, behind a login

What their documentation says
A NodeZero Runner with network connectivity to the target. Their own words are that it is required in order to use the credentials at all.
What B-52 needs
A credential for each role you want exercised. Nothing of ours is placed in your network for it.
What that costs you
Standing something up with network reach to the target, and keeping it there, in order to test an application your customers reach over the public internet.
03 Situation three

An application reachable only from inside

What their documentation says
The same Runner, with network connectivity to the target.
What B-52 needs
A deployment — on-premise or inside your own virtual private cloud. Where an application cannot be reached from outside at all, this is the internal case for both products.
What differs
Very little. This is the row where the two are shaped the same way, and it is worth saying so plainly rather than leaving it out.

What each side can show

Evidence, rather than adjectives

Their column is sourced in the table at the foot of this page. Ours is what B-52 publishes about itself and can be held to.

The questionHorizon3B-52
How each was measured against people An account in their launch release: during beta, a broken access control flaw in a critical component, found in a customer application and missed by human reviewers. Early access ran with 95 customers. B-52 was run in parallel with Security Brigade’s expert assessment team on the same targets. Both sets of findings were pooled into one denominator with each item counted once, and B-52 reached 90–95% of that pooled set.
What arrives with a finding Fix actions with verification, and reporting, named as modules in every tier. The request as sent and the response as returned, steps that reproduce it, a CVSS v4.0 vector and the CWE. Every finding, in all three delivery models.
How quickly a run comes back Their external pentesting page states that tests can be set up within minutes and executed as often as required. In the fully autonomous model, an observed median of one to three business days. It is a median rather than a service level, and no figure is published for the other two models.
Who can sign it Expert human analysis by Offensive Security Certified Professional pentesters, offered beside the platform on their compliance page. Security Brigade has been CERT-In empanelled since 2008 and is ISO 27001 certified, and the two models with an auditor in them produce a report carrying that signature.
Which customers can be named More than 6,500 organisations in their dated 29 July 2026 release, with the NSA, CISA and four of the Fortune 10 named on it. None. No named customer references are published, and the worked examples on this site are anonymised composites. Every engagement since Security Brigade started in 2006 was worked inside Lemon, which is what trained the models.
Their homepage carries what appears to be a live counter, which read higher on 2026-09-14. The dated release figure is the one quoted here because it does not move.
How you try it A 30-day free trial, self-service, with a company email verified once; the account returns to read-only afterwards. A paid trial at $299. The self-serve card flow reaches the five application classes: web, mobile, API, thick client and secure code review.

How each was measured against people

Horizon3
An account in their launch release: during beta, a broken access control flaw in a critical component, found in a customer application and missed by human reviewers. Early access ran with 95 customers.
B-52
B-52 was run in parallel with Security Brigade’s expert assessment team on the same targets. Both sets of findings were pooled into one denominator with each item counted once, and B-52 reached 90–95% of that pooled set.

What arrives with a finding

Horizon3
Fix actions with verification, and reporting, named as modules in every tier.
B-52
The request as sent and the response as returned, steps that reproduce it, a CVSS v4.0 vector and the CWE. Every finding, in all three delivery models.

How quickly a run comes back

Horizon3
Their external pentesting page states that tests can be set up within minutes and executed as often as required.
B-52
In the fully autonomous model, an observed median of one to three business days. It is a median rather than a service level, and no figure is published for the other two models.

Who can sign it

Horizon3
Expert human analysis by Offensive Security Certified Professional pentesters, offered beside the platform on their compliance page.
B-52
Security Brigade has been CERT-In empanelled since 2008 and is ISO 27001 certified, and the two models with an auditor in them produce a report carrying that signature.

Which customers can be named

Horizon3
More than 6,500 organisations in their dated 29 July 2026 release, with the NSA, CISA and four of the Fortune 10 named on it.
B-52
None. No named customer references are published, and the worked examples on this site are anonymised composites. Every engagement since Security Brigade started in 2006 was worked inside Lemon, which is what trained the models.

Their homepage carries what appears to be a live counter, which read higher on 2026-09-14. The dated release figure is the one quoted here because it does not move.

How you try it

Horizon3
A 30-day free trial, self-service, with a company email verified once; the account returns to read-only afterwards.
B-52
A paid trial at $299. The self-serve card flow reaches the five application classes: web, mobile, API, thick client and secure code review.

Choosing between them

Which shortlist each product belongs on

If the requirement reads internal network, Active Directory and Kubernetes bundled at one price, with a United States federal authorisation behind the platform, Horizon3 answers it better than we do, and nothing else on this page changes that. If it reads web application, mobile, API, thick client, secure code review or LLM applications — tested with a credential for each role and nothing of ours standing in your network, with a senior auditor verifying every finding where a filing asks for a signature, and with the control plane on your own premises or inside your own virtual private cloud — that is the shape B-52 was built to. Where both lists matter, the honest answer is that these are two products with a narrower overlap than either data sheet suggests, and the buyers who end up happiest with one of them knew which half of their requirement was load-bearing before they started.

Every claim, sourced

What was read, and when

Competitive claims go out of date, and this page has a date on every one of them so you can tell how far. Where a row has aged past what you would rely on, check it against their own site — that is where each of these was read.

What Horizon3 publishesVerified
Four packaging tiers are published by name — NodeZero Flex (“Autonomous Episodic Penetration Testing”), Core (“Continuous Autonomous Penetration Testing”), Pro (“Precision Threat Detection and Emerging Threat Intel”) and Elite (“Risk-Based Exposure Management”). No dollar figure is published against any tier. 2026-09-14
Read at https://horizon3.ai/pricing/
Every tier, including the entry tier, includes Internal Pentesting, External Pentesting, External Asset Discovery, Cloud Pentesting, Kubernetes Pentesting, Active Directory Audit, Phishing Impact Testing, Fix Actions with verification, reporting, the NodeZero MCP Server, a Vulnerability Management Hub, and Endpoint Security Effectiveness. 2026-09-14
Read at https://horizon3.ai/pricing/
NodeZero WebApp Pentesting is sold as an add-on rather than as part of any base tier, in two variants — episodic alongside Flex, or continuous alongside Core, Pro and Elite. 2026-09-14
Read at https://horizon3.ai/pricing/
Internal pentests run from a customer-deployed machine: “Internal tests are run from a free Docker host or open virtualization appliance (OVA) that you can set up in minutes.” The machine is free; the licence is paid. 2026-09-14
Read at https://horizon3.ai/nodezero/
External tests are executed in the “Horizon3 cloud” using “dedicated, ephemeral resources” in “an isolated virtual private cloud network”. Nothing is placed in a customer network for external testing. 2026-09-14
Read at https://horizon3.ai/nodezero/
NodeZero Host requirements are published in full: Ubuntu 20.04 LTS or later or RHEL 9+; Docker 20.10 or later, or Podman 4.0 or later; 2 processor cores minimum and 4 recommended; 8 GB memory minimum and 16 GB for heavy workloads; 40 GB free disk, 80 GB solid state preferred; git and bash. The documentation instructs: “Do not install or configure any EDR (Endpoint Detection and Response) services on the NodeZero host.” 2026-09-14
Read at https://docs.horizon3.ai/quickstart/setup_host/manual_host/host_requirements/
The NodeZero Host needs outbound HTTPS and HTTP (443, 80) to region-specific Horizon3 endpoints, with separate domain sets for the EU and AU portals. Inbound requirements are internal-network only; there is no inbound requirement from Horizon3. 2026-09-14
Read at https://docs.horizon3.ai/quickstart/network_requirements/
The internal pentesting product page states: “With a SaaS architecture, there’s no hardware or software to maintain and no required agents to install.” 2026-09-14
Read at https://horizon3.ai/nodezero/internal-pentesting/
Internal pentesting names credential attacks and dumping, man-in-the-middle, password cracking and spraying, credential phishing, OS credential dumping, Log4Shell, Zerologon and RAT implantation, aligned to MITRE ATT&CK. The page states: “Many of the attack paths NodeZero executes don’t involve exploiting any CVEs.” 2026-09-14
Read at https://horizon3.ai/nodezero/internal-pentesting/
External pentesting covers ransomware exposure assessment, misconfigured third-party applications, weak and default credentials, public-facing asset vulnerabilities, hybrid cloud assets, and third-party or supply chain risk. Asset Discovery is “a passive enumeration capability that leverages DNS and other Open Source Intelligence (OSINT) gathering capabilities”. Tests “can be set up within minutes and executed as often as needed”. 2026-09-14
Read at https://horizon3.ai/nodezero/external-pentesting/
Kubernetes pentesting is in-cluster: NodeZero “deploys within Kubernetes clusters using Kubernetes Operators and Infrastructure-as-Code (kubectl)” and tests “live, running clusters” for “RBAC misconfigurations, container escapes, and secret exposures”. 2026-09-14
Read at https://horizon3.ai/nodezero/kubernetes-pentesting/
The cloud pentesting page names AWS, Azure and Kubernetes, and states “NodeZero is deployable both on-prem and in the cloud.” 2026-09-14
Read at https://horizon3.ai/nodezero/cloud-pentesting/
NodeZero Federal is delivered as “secure SaaS with enforced SSO”. No on-premise, self-hosted or air-gapped deployment option is offered on that page, including for federal customers. 2026-09-14
Read at https://horizon3.ai/vertical/federal/
NodeZero Federal is FedRAMP High Authorized under the Federal High Impact Virtualized Environment (FedHIVE), Package ID FR1802451335, announced 15 May 2025 following review by a FedRAMP-accredited Third Party Assessment Organization (3PAO). 2026-09-14
Read at https://horizon3.ai/vertical/federal/
NodeZero WebApp requires customer infrastructure for authenticated or private testing: “Applications behind a VPN or private network are tested through a NodeZero Runner with network connectivity to the target,” and “A NodeZero Runner with network connectivity to the target is required in order to use the credentials.” Unauthenticated, internet-reachable applications need no such machine. 2026-09-14
Read at https://docs.horizon3.ai/portal/test_types/webapp/
NodeZero WebApp covers route discovery and crawling via headless browser automation, authenticated testing with multi-role support, parameter testing across query strings, headers, cookies and request bodies, exploitation, and attack chaining across networks. REST, SOAP and GraphQL endpoint discovery and single-page application testing are named on the product page. 2026-09-14
Read at https://horizon3.ai/nodezero/webapp/
The NodeZero WebApp launch release is dated 29 July 2026 and claims “Coverage of the OWASP Top 10”, detection of “complex access-control failures that traditional scanners routinely miss”, continuous autonomous testing of pre-production and production applications, and “Full attack-path chaining”. The OWASP Top 10 wording appears in the release rather than on the product page. 2026-09-14
Read at https://horizon3.ai/news/press-release/nodezero-webapp-launch/
NodeZero WebApp early access ran with “95 customers globally, including Fortune 10 enterprises”, and the release states that during beta “a major social media company discovered a broken access control flaw in a critical component that was missed by human reviewers”. 2026-09-14
Read at https://horizon3.ai/news/press-release/nodezero-webapp-launch/
Pentera announced web application penetration testing on 29 July 2026 — the same day as the NodeZero WebApp release — in beta, with general availability published as rolling out in Q4 2026. 2026-09-14
Read at https://pentera.io/press-release/pentera-ai-web-app-pentesting/
Homepage and platform autonomy claims: “Safely and autonomously hack your production environment”, “NodeZero® autonomously executes real attack techniques, without agents or disruption”, “NodeZero navigates through your network without scripts”, and that it “exploits weaknesses based on its discoveries just as attackers do, chaining weaknesses”. 2026-09-14
Read at https://horizon3.ai/
Social proof: the homepage reads “Trusted by NSA and 4 of the Fortune 10” with a customer counter showing 7,012 on 2026-09-14, while the dated 29 July 2026 release states “More than 6,500 organizations, including the NSA, CISA, major healthcare providers and four of the Fortune 10.” The homepage figure appears to be a live counter and moves. 2026-09-14
Read at https://horizon3.ai/
A documented GraphQL API is published at a single /graphql endpoint, supporting scheduling pentests, retrieving weaknesses, hosts, credentials and attack paths, deploying runners and creating templates. An h3-cli command-line tool is published with guides for scheduling, automating deployment, injecting credentials and monitoring pentests. 2026-09-14
Read at https://docs.horizon3.ai/api/graphql/
Third-party integrations with published setup guides: Jira, ServiceNow VR, Splunk Cloud and Microsoft Sentinel. 2026-09-14
Read at https://docs.horizon3.ai/
The NodeZero MCP Server is positioned as “The Exploitability Data Engine for Agentic Security Workflows”, claiming it “operationalizes FixOps by connecting your AI ecosystem to the exploitability intelligence it needs”. Named uses include prioritisation by proven attack path, ticket enrichment, continuous retesting, and “security validation in CI/CD pipelines before deployment”. This page is the only place CI/CD appears on their site or documentation. 2026-09-14
Read at https://horizon3.ai/nodezero/mcp-server/
A 30-day free trial is published and self-service: “Once your 30 day free trial is over, you will be placed back into read-only mode.” It requires a company information form and a valid company email verified by token, and “You can only verify a company email for a free trial once.” 2026-09-14
Read at https://docs.horizon3.ai/quickstart/register/upgrade/
The compliance page positions NodeZero against PCI DSS v4.0, SOC, DORA, GDPR, CIS, NIST and CMMC, and offers “Expert human analysis by Offensive Security Certified Professional (OSCP) pentesters” alongside the platform. 2026-09-14
Read at https://horizon3.ai/compliance/
Press releases published since 1 June 2026 include: a $250 million Series E at a stated $2B+ valuation (3 August 2026); a $20 million investment in partner-led growth (5 August 2026); a World Wide Technology partnership (27 July 2026); an EMEA headquarters in Amsterdam (29 June 2026); a Brinqa partnership (3 June 2026); and a “Rapid Response” launch (1 June 2026). 2026-09-14
Read at https://horizon3.ai/category/news/press-release/

Four packaging tiers are published by name — NodeZero Flex (“Autonomous Episodic Penetration Testing”), Core (“Continuous Autonomous Penetration Testing”), Pro (“Precision Threat Detection and Emerging Threat Intel”) and Elite (“Risk-Based Exposure Management”). No dollar figure is published against any tier.

Verified
2026-09-14

Read at https://horizon3.ai/pricing/

Every tier, including the entry tier, includes Internal Pentesting, External Pentesting, External Asset Discovery, Cloud Pentesting, Kubernetes Pentesting, Active Directory Audit, Phishing Impact Testing, Fix Actions with verification, reporting, the NodeZero MCP Server, a Vulnerability Management Hub, and Endpoint Security Effectiveness.

Verified
2026-09-14

Read at https://horizon3.ai/pricing/

NodeZero WebApp Pentesting is sold as an add-on rather than as part of any base tier, in two variants — episodic alongside Flex, or continuous alongside Core, Pro and Elite.

Verified
2026-09-14

Read at https://horizon3.ai/pricing/

Internal pentests run from a customer-deployed machine: “Internal tests are run from a free Docker host or open virtualization appliance (OVA) that you can set up in minutes.” The machine is free; the licence is paid.

Verified
2026-09-14

Read at https://horizon3.ai/nodezero/

External tests are executed in the “Horizon3 cloud” using “dedicated, ephemeral resources” in “an isolated virtual private cloud network”. Nothing is placed in a customer network for external testing.

Verified
2026-09-14

Read at https://horizon3.ai/nodezero/

NodeZero Host requirements are published in full: Ubuntu 20.04 LTS or later or RHEL 9+; Docker 20.10 or later, or Podman 4.0 or later; 2 processor cores minimum and 4 recommended; 8 GB memory minimum and 16 GB for heavy workloads; 40 GB free disk, 80 GB solid state preferred; git and bash. The documentation instructs: “Do not install or configure any EDR (Endpoint Detection and Response) services on the NodeZero host.”

Verified
2026-09-14

Read at https://docs.horizon3.ai/quickstart/setup_host/manual_host/host_requirements/

The NodeZero Host needs outbound HTTPS and HTTP (443, 80) to region-specific Horizon3 endpoints, with separate domain sets for the EU and AU portals. Inbound requirements are internal-network only; there is no inbound requirement from Horizon3.

Verified
2026-09-14

Read at https://docs.horizon3.ai/quickstart/network_requirements/

The internal pentesting product page states: “With a SaaS architecture, there’s no hardware or software to maintain and no required agents to install.”

Verified
2026-09-14

Read at https://horizon3.ai/nodezero/internal-pentesting/

Internal pentesting names credential attacks and dumping, man-in-the-middle, password cracking and spraying, credential phishing, OS credential dumping, Log4Shell, Zerologon and RAT implantation, aligned to MITRE ATT&CK. The page states: “Many of the attack paths NodeZero executes don’t involve exploiting any CVEs.”

Verified
2026-09-14

Read at https://horizon3.ai/nodezero/internal-pentesting/

External pentesting covers ransomware exposure assessment, misconfigured third-party applications, weak and default credentials, public-facing asset vulnerabilities, hybrid cloud assets, and third-party or supply chain risk. Asset Discovery is “a passive enumeration capability that leverages DNS and other Open Source Intelligence (OSINT) gathering capabilities”. Tests “can be set up within minutes and executed as often as needed”.

Verified
2026-09-14

Read at https://horizon3.ai/nodezero/external-pentesting/

Kubernetes pentesting is in-cluster: NodeZero “deploys within Kubernetes clusters using Kubernetes Operators and Infrastructure-as-Code (kubectl)” and tests “live, running clusters” for “RBAC misconfigurations, container escapes, and secret exposures”.

Verified
2026-09-14

Read at https://horizon3.ai/nodezero/kubernetes-pentesting/

The cloud pentesting page names AWS, Azure and Kubernetes, and states “NodeZero is deployable both on-prem and in the cloud.”

Verified
2026-09-14

Read at https://horizon3.ai/nodezero/cloud-pentesting/

NodeZero Federal is delivered as “secure SaaS with enforced SSO”. No on-premise, self-hosted or air-gapped deployment option is offered on that page, including for federal customers.

Verified
2026-09-14

Read at https://horizon3.ai/vertical/federal/

NodeZero Federal is FedRAMP High Authorized under the Federal High Impact Virtualized Environment (FedHIVE), Package ID FR1802451335, announced 15 May 2025 following review by a FedRAMP-accredited Third Party Assessment Organization (3PAO).

Verified
2026-09-14

Read at https://horizon3.ai/vertical/federal/

NodeZero WebApp requires customer infrastructure for authenticated or private testing: “Applications behind a VPN or private network are tested through a NodeZero Runner with network connectivity to the target,” and “A NodeZero Runner with network connectivity to the target is required in order to use the credentials.” Unauthenticated, internet-reachable applications need no such machine.

Verified
2026-09-14

Read at https://docs.horizon3.ai/portal/test_types/webapp/

NodeZero WebApp covers route discovery and crawling via headless browser automation, authenticated testing with multi-role support, parameter testing across query strings, headers, cookies and request bodies, exploitation, and attack chaining across networks. REST, SOAP and GraphQL endpoint discovery and single-page application testing are named on the product page.

Verified
2026-09-14

Read at https://horizon3.ai/nodezero/webapp/

The NodeZero WebApp launch release is dated 29 July 2026 and claims “Coverage of the OWASP Top 10”, detection of “complex access-control failures that traditional scanners routinely miss”, continuous autonomous testing of pre-production and production applications, and “Full attack-path chaining”. The OWASP Top 10 wording appears in the release rather than on the product page.

Verified
2026-09-14

Read at https://horizon3.ai/news/press-release/nodezero-webapp-launch/

NodeZero WebApp early access ran with “95 customers globally, including Fortune 10 enterprises”, and the release states that during beta “a major social media company discovered a broken access control flaw in a critical component that was missed by human reviewers”.

Verified
2026-09-14

Read at https://horizon3.ai/news/press-release/nodezero-webapp-launch/

Pentera announced web application penetration testing on 29 July 2026 — the same day as the NodeZero WebApp release — in beta, with general availability published as rolling out in Q4 2026.

Verified
2026-09-14

Read at https://pentera.io/press-release/pentera-ai-web-app-pentesting/

Homepage and platform autonomy claims: “Safely and autonomously hack your production environment”, “NodeZero® autonomously executes real attack techniques, without agents or disruption”, “NodeZero navigates through your network without scripts”, and that it “exploits weaknesses based on its discoveries just as attackers do, chaining weaknesses”.

Verified
2026-09-14

Read at https://horizon3.ai/

Social proof: the homepage reads “Trusted by NSA and 4 of the Fortune 10” with a customer counter showing 7,012 on 2026-09-14, while the dated 29 July 2026 release states “More than 6,500 organizations, including the NSA, CISA, major healthcare providers and four of the Fortune 10.” The homepage figure appears to be a live counter and moves.

Verified
2026-09-14

Read at https://horizon3.ai/

A documented GraphQL API is published at a single /graphql endpoint, supporting scheduling pentests, retrieving weaknesses, hosts, credentials and attack paths, deploying runners and creating templates. An h3-cli command-line tool is published with guides for scheduling, automating deployment, injecting credentials and monitoring pentests.

Verified
2026-09-14

Read at https://docs.horizon3.ai/api/graphql/

Third-party integrations with published setup guides: Jira, ServiceNow VR, Splunk Cloud and Microsoft Sentinel.

Verified
2026-09-14

Read at https://docs.horizon3.ai/

The NodeZero MCP Server is positioned as “The Exploitability Data Engine for Agentic Security Workflows”, claiming it “operationalizes FixOps by connecting your AI ecosystem to the exploitability intelligence it needs”. Named uses include prioritisation by proven attack path, ticket enrichment, continuous retesting, and “security validation in CI/CD pipelines before deployment”. This page is the only place CI/CD appears on their site or documentation.

Verified
2026-09-14

Read at https://horizon3.ai/nodezero/mcp-server/

A 30-day free trial is published and self-service: “Once your 30 day free trial is over, you will be placed back into read-only mode.” It requires a company information form and a valid company email verified by token, and “You can only verify a company email for a free trial once.”

Verified
2026-09-14

Read at https://docs.horizon3.ai/quickstart/register/upgrade/

The compliance page positions NodeZero against PCI DSS v4.0, SOC, DORA, GDPR, CIS, NIST and CMMC, and offers “Expert human analysis by Offensive Security Certified Professional (OSCP) pentesters” alongside the platform.

Verified
2026-09-14

Read at https://horizon3.ai/compliance/

Press releases published since 1 June 2026 include: a $250 million Series E at a stated $2B+ valuation (3 August 2026); a $20 million investment in partner-led growth (5 August 2026); a World Wide Technology partnership (27 July 2026); an EMEA headquarters in Amsterdam (29 June 2026); a Brinqa partnership (3 June 2026); and a “Rapid Response” launch (1 June 2026).

Verified
2026-09-14

Read at https://horizon3.ai/category/news/press-release/

Run one scan for $500 — or scope the estate

One scan is one application or one target, and the entry price is $500. The paid trial is $299. Anything larger is a scoping call, because the ladder above the entry price is not published and we are not going to invent one for a comparison page.