Horizon3 AI website
Horizon3 AI

Horizon3 AI

Autonomous penetration-testing platform (NodeZero) that safely hacks production environments to find and fix exploitable attack paths.

Careers(81)
Horizon3 AI website preview

Overview: The company that hacks your production network so real attackers can't

Horizon3.ai starts from a blunt question that makes most security teams squirm: you spent millions on tools, so can you actually prove you're secure? Its answer is NodeZero, an autonomous pentester that safely runs real attack techniques against your live production environment, chains the weaknesses together the way a human intruder would, and shows you the exploitable paths that actually matter.

Founded in 2019 and run out of San Francisco, the company was built by a fusion of former U.S. Special Operations cyber operators, national security veterans, and frustrated industry practitioners. CEO Snehal Antani, previously CTO of JSOC and CTO at Splunk, likes to call the approach turning the map around: take the attacker's perspective, because production is where the hackers actually attack. That bet has scaled fast, past a quarter million autonomous tests run in production and thousands of customers including government agencies and Fortune 10 giants.

What They Do: Hack, fix, verify, repeat, on autopilot

NodeZero isn't a vulnerability scanner, and Horizon3 is aggressive about the distinction. A scanner tells you a flaw might exist; NodeZero proves whether it's actually exploitable by safely exploiting it, then shows the blast radius on your business. It runs without agents and without disruption, pivoting through the network, harvesting credentials, and chaining misconfigurations into full attack paths in a real-time view.

The loop is the whole pitch: hack to prove exploitability, fix what genuinely endangers the business, verify the fix worked with a one-click re-test, then repeat continuously as the environment changes. The company frames it as moving from vulnerability management to closing proven attack paths, and it leans hard on evidence over opinion-based risk scores.

Problems: Alert fatigue, checkbox security, and the pentest that's stale by lunch

Security teams drown in noise. Scanners spit out paralyzing to-do lists ranked by theoretical severity, manual pentests are expensive and go stale the moment the environment changes, and nobody can say which of ten thousand findings would actually get them breached. Horizon3 built NodeZero to cut that Gordian knot by testing what's real, not what's hypothetical.

Its founders name the pains directly: ineffective tools, false positives, alert fatigue, blind spots, a checkbox security culture, the cybersecurity skills shortage, and the lead time and cost of hiring outside consultants. The company argues AI has handed attackers unprecedented scale and speed, and that the only credible defense is to fight AI with AI and validate continuously instead of once a quarter.

How it Happens

Can't prove whether known vulnerabilities are actually exploitable
Alert fatigue and paralyzing, noisy vulnerability to-do lists
Manual pentests are expensive and go stale as environments change
Checkbox security culture that doesn't reflect real risk
Cybersecurity skills shortage and reliance on outside consultants
No fast way to verify that a remediation actually worked

Who It's For: From small school districts to the NSA and four of the Fortune 10

NodeZero was built for the people who own security posture and are tired of guessing: IT Ops and SecOps teams, in-house and consulting pentesters, and the MSSPs and MSPs who run security for others. Horizon3 sells across a wide size range, from small educational institutions to Global 100 enterprises and government agencies.

The named proof points skew high-stakes. The company says it's trusted by global governments, Fortune 10 giants, and major healthcare providers, and cites the NSA and four of the Fortune 10 among its users, exactly the environments where a test going wrong is not an option.

Ideal Customer Profiles

SecOps / IT Ops teams
  • Too many findings, no clarity on what to fix first
  • Need continuous validation, not quarterly snapshots
CISOs and security leaders
  • Must prove security posture to the board and auditors
  • Executive confidence outrunning real, validated risk
MSSPs and MSPs
  • Need to run scalable, repeatable pentests across many client environments

Products: One platform, four ways to buy the AI hacker

Everything Horizon3 sells is NodeZero, its self-directed penetration testing platform that you can set up and point at your first test in minutes, from a free Docker host or virtual appliance for internal tests, or straight from the Horizon3 cloud for external ones. It covers internal, external, cloud, and Kubernetes attack surfaces, plus Active Directory password auditing and phishing impact testing.

The platform is packaged into tiers that layer on capability: continuous scheduling, precision threat detection with auto-dropped honeytokens, emerging-threat Rapid Response backed by Horizon3's own attack team, and risk-based exposure management with high-value targeting and threat-actor intelligence at the top end. There's also a NodeZero MCP server, a nod to where the product is heading.

NodeZero
Autonomous, agentless penetration-testing platform that safely exploits real attack paths in production across internal, external, cloud, and Kubernetes surfaces, then guides and verifies fixes.
NodeZero Rapid Response
Emerging-threat intelligence and zero- and N-day early alerting backed by Horizon3.ai's expert attack team, so customers can validate exposure to new threats fast.
NodeZero Tripwires
Auto-dropped honeytokens and security-controls validation that catch exploitable exposure with proven downstream business impact.
AD Password Audit
Continuously verifies the effectiveness of Active Directory credential policies by surfacing easily compromised and exposed credentials.

Business Model: Tiered SaaS, from episodic tests to always-on exposure management

Horizon3 sells NodeZero as enterprise SaaS with unlimited-scope pentesting, so cost scales with capability and coverage rather than per-test fees. Pricing itself is quote-based through a demo, but the packaging tells the story: you climb from occasional testing to continuous validation to full exposure management as you move up the tiers.

The published lineup runs Flex (episodic autonomous pentests), Core (continuous testing with scheduling), Pro (Core plus Rapid Response and Tripwires), and Elite (Pro plus high-value targeting, advanced data pilfering, threat-actor intelligence, and vulnerability risk intelligence). A free trial account lets teams run their first internal pentest before talking to sales.

NodeZero is sold as enterprise SaaS with unlimited-scope pentesting, so pricing scales with capability and coverage rather than per-test fees. Published pricing is quote-based through a demo, but the packaging is public: four tiers that climb from episodic testing to continuous validation to full risk-based exposure management. A free trial account lets teams run their first internal pentest before contacting sales.

Plans

NodeZero FlexContact sales

Teams wanting on-demand, episodic testing · Autonomous episodic penetration testing

  • Internal and external pentesting
  • External asset discovery
  • Cloud and Kubernetes pentesting
  • Active Directory password audit
  • Phishing impact testing
  • Fix Actions with 1-click verify
  • Comprehensive reports
  • NodeZero MCP server
NodeZero CoreContact sales

Teams moving to continuous validation · Continuous autonomous penetration testing

  • Everything in Flex
  • Scheduling for continuous testing
  • Threat-informed perspectives
  • Vulnerability Management Hub
  • Endpoint security effectiveness
NodeZero ProContact sales

Teams needing emerging-threat coverage · Precision threat detection and emerging threat intel

  • Everything in Core
  • Tripwires (auto-dropped honeytokens)
  • Rapid Response zero- and N-day alerting
NodeZero EliteContact sales

Enterprises running risk-based exposure management · Risk-based exposure management

  • Everything in Pro
  • NodeZero Insights
  • High-Value Targeting
  • Advanced Data Pilfering
  • Threat Actor Intelligence
  • Vulnerability Risk Intelligence

Good to know

  • Pricing is quote-based; plans are demoed rather than listed with dollar figures
  • Free trial account available to run a first internal pentest
  • Internal tests run from a free Docker host or virtual appliance; external tests run from the Horizon3.ai cloud
  • Higher tiers unlock scheduling, Rapid Response, and advanced targeting/intel capabilities

Competition: Not a scanner, not a BAS tool, and betting the category on that

Horizon3's whole positioning is a wedge against the incumbents: static scanners that test only what you already know, breach-and-attack-simulation tools that model threats rather than prove them, and periodic manual pentests that are stale within days. Its counter is autonomous exploitation that learns and adapts with every test and delivers proof instead of opinion-based risk scores.

The strategic tell is in their recent writing, arguing the category isn't red teaming and that organizations buy answers, not activities. That's a company trying to redraw the map around exploitability-first validation, with a moat built on hundreds of thousands of production tests that, they claim, outpace the collective history of manual pentesting.

Competes with

Traditional vulnerability scannersBreach-and-attack-simulation (BAS) toolsManual / consultant penetration testing

Their edge

Proof, not opinion
NodeZero safely exploits real attack paths to prove business impact instead of producing severity scores or theoretical risk.
Production-safe at scale
Runs agentless against live production with a stated zero-downtime record across all tests, earning trust in high-security government and Fortune 10 environments.
A data moat from real-world testing
Learns from hundreds of thousands of autonomous production tests, which the company argues outpaces the collective history of manual pentesting.

Where they're betting

  • Redefining the category from red teaming to exploitability-first validation
  • Fighting AI-powered attacks with AI (Rapid Response)
  • Global expansion (new Amsterdam EMEA HQ)
  • Agentic and MCP-enabled autonomous testing

Proof: The numbers Horizon3 puts on the table

The headline stat is scale run safely: more than 257,000 autonomous tests executed in production with, the company says, zero downtime across all of them. That production-safe record is the credential it trades on with high-security customers, and it's backed by real accolades rather than self-description.

Horizon3 landed #1 in Security on the Inc. 5000, #3 overall on the Deloitte Technology Fast 500, a spot on Fast Company's Most Innovative Companies, and reported 102% ARR growth heading into 2026. One customer case study says NodeZero cut attack-path impacts from 251 to zero across 18 locations, the kind of before-and-after that's hard to argue with.

257,000+
autonomous tests run safely in production
Thousands of customers across government, Fortune 10, and healthcare
102%
ARR growth reported heading into 2026
#1 in Security on the Inc. 5000
#3 overall on the Deloitte Technology Fast 500
Fast Company Most Innovative Companies (2026)

What People Say: Loved for proving real attacks, dinged on reporting depth

Reviewers consistently praise the thing Horizon3 built the company around: NodeZero behaves like an actual attacker, discovering, pivoting, and chaining issues into clear attack paths tied to business impact. People like that it needs minimal setup and no agents, runs fast across broad scope, and lets non-pentesters get useful results, with one-click verify to confirm a fix without rerunning everything.

The criticism is just as consistent. Reporting can read too generic or high-level instead of clean per-asset detail, Docker installation gets tricky inside locked-down enterprise networks, and results lean on how well the environment is scoped, so conservative IP ranges can hide paths. Some reviewers note occasional false positives or missed nuanced vulnerabilities, a fair reminder that autonomous still isn't infallible.

Reviewers praise NodeZero for proving real, exploitable attack paths with little setup, while wanting deeper reporting and smoother enterprise deployment.

…without taking an attacker's perspective by considering actual attack vectors that they can use to get in, you really can't be ready.

Jon Isaacson, Principal Consultant, horizon3.ai
Loved
  • Behaves like a real attacker: discovers, pivots, and chains issues into clear attack paths tied to business impact
  • Minimal setup, no agents, fast across broad scope
  • Usable by non-pentesters; results say what to fix and how
  • One-click verify to confirm a fix without rerunning the whole assessment
Gripes
  • Reporting can be too generic or high-level rather than clean per-asset detail
  • Docker installation is tricky inside locked-down enterprise networks
  • Results depend heavily on how well the environment is scoped
  • Occasional false positives or missed nuanced vulnerabilities

Funding: $100M from NEA, then Aramco's fund came knocking

Horizon3 raised a $100M Series D led by New Enterprise Associates in June 2025, with SignalFire, Craft Ventures, 9Yards Capital, and Qualcomm Ventures joining, reportedly at a valuation north of $750M. Total funding sits around $178M to $183M depending on the source, from a backer list that also includes NightDragon, NewView Capital, and Bridgespan.

Then in January 2026 came a strategic investment from Prosperity7 Ventures, the diversified venturing fund of Aramco Ventures, a signal that Horizon3's global-security story is drawing sovereign-scale capital, not just Silicon Valley venture money.

Total raised

$178.5M

Valuation

$750M+

Latest round

Series D · $100M · 2025 (led by NEA)

Backers

New Enterprise Associates (NEA)SignalFireCraft Ventures9Yards CapitalQualcomm VenturesProsperity7 VenturesNightDragonNewView CapitalBridgespan

Outlook: Betting that machine-speed defense becomes the default

Horizon3's thesis is that cyber warfare is heading toward algorithm-versus-algorithm at machine speed, with humans by exception, and it's building NodeZero to be the defender's side of that fight. The recent moves, Rapid Response, an MCP server, a European HQ, and Aramco-linked capital, all point the same direction: continuous, autonomous, exploitability-first validation as the new baseline.

The open question is whether autonomous testing fully wins the trust of the most cautious buyers, given the reporting-depth and false-positive gripes reviewers still raise. But with triple-digit ARR growth, a category it's actively trying to define, and marquee government and Fortune 10 logos, Horizon3 is arguing from a position of strength.

Team & Culture: Learn-it-alls with a special-ops streak

Horizon3 describes its people as learn-it-alls, a deliberate anti-know-it-all posture, drawn from technology startups, Fortune 500s, and the U.S. military. The founding DNA is unusual: special operations cyber operators and national security veterans sitting alongside startup engineers, which shows up in a mission-first, attacker-minded culture that prizes grit and ownership.

On the engineering side, the work is genuinely hard and they say so plainly, building an LLM-driven autonomous pentester under a strict no-false-positives, production-safe mandate where the hard problems are reliability engineering, not chasing benchmarks. It's remote-first with offices in San Francisco, Chicago, and a new Amsterdam EMEA headquarters, and the company took a rare public moment to mourn its late CFO, Holly Grey, on its own leadership page.

Values
Learn-it-alls, not know-it-alls, Attacker-minded, mission-first, Respect, collaboration, ownership, and results, Grit and tenacity on hard, mission-critical problems, Diverse backgrounds from startups, Fortune 500s, and the U.S. military
Work policy
Remote-first with hybrid options; offices in San Francisco, Chicago, and Amsterdam. Some roles require regular in-office presence (e.g., Chicago); light travel (roughly 5-15%) for some positions.
Hiring
Hiring across engineering, sales, marketing, and IT/operations, with roles in the U.S. (San Francisco and Chicago), plus EMEA hubs in Amsterdam, Germany, and France; remote-first with hybrid options.
Backend
Python, Go, Rust, Java, TypeScript, GraphQL, SQL
AI/ML
LLM agents / tool use, AWS Bedrock, Model Context Protocol (MCP), LangChain, LangFlow, structured-output validation
Browser Automation
Playwright, Puppeteer, Selenium, Stagehand, Chrome DevTools Protocol, Node.js, TypeScript
Data
PostgreSQL, Neo4j, MongoDB, ETL/ELT pipelines, Airflow, Temporal
Infrastructure
AWS, Azure, GCP, Kubernetes, Docker, Terraform, Crossplane, ArgoCD, GitLab CI/CD, GitOps
Observability
Datadog, Prometheus, Grafana
Security
Burp Suite, Nuclei, sqlmap, SonarQube, Trivy, Trufflehog, ZAProxy, MITRE ATT&CK, Okta, SAML/OAuth

Engineering culture at Horizon3 AI

  • Deterministic-first, LLM-as-scalpel philosophy: models used surgically, not as a default
  • Strict no-false-positives, production-safe mandate; reliability engineering over benchmark chasing
  • Small, fast-growing teams with heavy individual ownership of critical subsystems
  • Design-before-build discipline with ADRs, RFCs, design and code reviews, and blameless retrospectives

Sales culture at Horizon3 AI

  • Challenger / question-based selling into enterprise cybersecurity buyers
  • Heavy tooling: Salesforce, Outreach.io, ZoomInfo, LinkedIn Sales Navigator, Gainsight
  • Channel- and partner-led motion with dedicated field and channel roles across the Americas and EMEA

Benefits & perks

All full-time roles
  • Medical, vision, and dental insurance for you and your family
  • Equity package in the form of stock options
  • Flexible vacation policy plus generous holidays (4 weeks + globally per careers page)
  • Generous parental leave
  • Competitive salary
  • Job training, conferences, and career development opportunities

Compensation: Published U.S. bands, equity on every full-time role

Horizon3 leans into pay transparency, publishing base ranges in its job posts to comply with state disclosure laws. Disclosed U.S. engineering bases run from roughly $102K for support engineering up to about $315K for senior leadership roles, with product and design landing in the $175K to $260K range and sales stretching wide from $80K to $450K once on-target commission is folded in.

Every full-time role is eligible for an equity package in the form of stock options, and the company states its comp philosophy is to pay fairly and consistently across roles, levels, and locations. Bands are also posted in EUR for its growing European roles.

Engineering
$102,465$315,000 · yearly
based on many disclosed roles
Sales
$80,000$450,000 · yearly
based on many disclosed roles
Operations
$85,000$297,000 · yearly
based on several disclosed roles
Marketing
$110,000$185,000 · yearly
based on a few disclosed roles
Product
$175,000$260,000 · yearly
based on a few disclosed roles
Design
$200,000$220,000 · yearly
based on a few disclosed roles
Sales (EUR)
€70,000€190,000 · yearly
based on a few disclosed roles

All full-time roles are eligible for an equity package in the form of stock options; sales roles carry on-target commission that widens the effective total range well above base.

In the News: A raise, a European HQ, and a steady drip of attack research

The past year reads like a company pressing its advantage: a $100M Series D, a new Amsterdam headquarters to anchor EMEA, the launch of Rapid Response for AI-powered attacks, and NodeZero clearing awardable status for U.S. Department of War work in the Tradewinds marketplace. Fast Company named it to its 2026 Most Innovative Companies list.

Underneath the announcements is a prolific attack-research operation, publishing CVE disclosures, exploit analysis, and threat guidance, that keeps Horizon3's name in front of practitioners between funding headlines.

More in Security

Other companies hiring in the same space.

Backed by Craft Ventures

Companies that share an investor.

Also serving Large enterprises (Global 100 / Fortune 10)

Companies selling to a similar audience.