

Horizon3 AI
Autonomous penetration-testing platform (NodeZero) that safely hacks production environments to find and fix exploitable attack paths.

Overview: The company that hacks your production network so real attackers can't
Horizon3.ai starts from a blunt question that makes most security teams squirm: you spent millions on tools, so can you actually prove you're secure? Its answer is NodeZero, an autonomous pentester that safely runs real attack techniques against your live production environment, chains the weaknesses together the way a human intruder would, and shows you the exploitable paths that actually matter.
Founded in 2019 and run out of San Francisco, the company was built by a fusion of former U.S. Special Operations cyber operators, national security veterans, and frustrated industry practitioners. CEO Snehal Antani, previously CTO of JSOC and CTO at Splunk, likes to call the approach turning the map around: take the attacker's perspective, because production is where the hackers actually attack. That bet has scaled fast, past a quarter million autonomous tests run in production and thousands of customers including government agencies and Fortune 10 giants.
What They Do: Hack, fix, verify, repeat, on autopilot
NodeZero isn't a vulnerability scanner, and Horizon3 is aggressive about the distinction. A scanner tells you a flaw might exist; NodeZero proves whether it's actually exploitable by safely exploiting it, then shows the blast radius on your business. It runs without agents and without disruption, pivoting through the network, harvesting credentials, and chaining misconfigurations into full attack paths in a real-time view.
The loop is the whole pitch: hack to prove exploitability, fix what genuinely endangers the business, verify the fix worked with a one-click re-test, then repeat continuously as the environment changes. The company frames it as moving from vulnerability management to closing proven attack paths, and it leans hard on evidence over opinion-based risk scores.
Problems: Alert fatigue, checkbox security, and the pentest that's stale by lunch
Security teams drown in noise. Scanners spit out paralyzing to-do lists ranked by theoretical severity, manual pentests are expensive and go stale the moment the environment changes, and nobody can say which of ten thousand findings would actually get them breached. Horizon3 built NodeZero to cut that Gordian knot by testing what's real, not what's hypothetical.
Its founders name the pains directly: ineffective tools, false positives, alert fatigue, blind spots, a checkbox security culture, the cybersecurity skills shortage, and the lead time and cost of hiring outside consultants. The company argues AI has handed attackers unprecedented scale and speed, and that the only credible defense is to fight AI with AI and validate continuously instead of once a quarter.
How it Happens
Who It's For: From small school districts to the NSA and four of the Fortune 10
NodeZero was built for the people who own security posture and are tired of guessing: IT Ops and SecOps teams, in-house and consulting pentesters, and the MSSPs and MSPs who run security for others. Horizon3 sells across a wide size range, from small educational institutions to Global 100 enterprises and government agencies.
The named proof points skew high-stakes. The company says it's trusted by global governments, Fortune 10 giants, and major healthcare providers, and cites the NSA and four of the Fortune 10 among its users, exactly the environments where a test going wrong is not an option.
Ideal Customer Profiles
- Too many findings, no clarity on what to fix first
- Need continuous validation, not quarterly snapshots
- Must prove security posture to the board and auditors
- Executive confidence outrunning real, validated risk
- Need to run scalable, repeatable pentests across many client environments
Products: One platform, four ways to buy the AI hacker
Everything Horizon3 sells is NodeZero, its self-directed penetration testing platform that you can set up and point at your first test in minutes, from a free Docker host or virtual appliance for internal tests, or straight from the Horizon3 cloud for external ones. It covers internal, external, cloud, and Kubernetes attack surfaces, plus Active Directory password auditing and phishing impact testing.
The platform is packaged into tiers that layer on capability: continuous scheduling, precision threat detection with auto-dropped honeytokens, emerging-threat Rapid Response backed by Horizon3's own attack team, and risk-based exposure management with high-value targeting and threat-actor intelligence at the top end. There's also a NodeZero MCP server, a nod to where the product is heading.
Business Model: Tiered SaaS, from episodic tests to always-on exposure management
Horizon3 sells NodeZero as enterprise SaaS with unlimited-scope pentesting, so cost scales with capability and coverage rather than per-test fees. Pricing itself is quote-based through a demo, but the packaging tells the story: you climb from occasional testing to continuous validation to full exposure management as you move up the tiers.
The published lineup runs Flex (episodic autonomous pentests), Core (continuous testing with scheduling), Pro (Core plus Rapid Response and Tripwires), and Elite (Pro plus high-value targeting, advanced data pilfering, threat-actor intelligence, and vulnerability risk intelligence). A free trial account lets teams run their first internal pentest before talking to sales.
NodeZero is sold as enterprise SaaS with unlimited-scope pentesting, so pricing scales with capability and coverage rather than per-test fees. Published pricing is quote-based through a demo, but the packaging is public: four tiers that climb from episodic testing to continuous validation to full risk-based exposure management. A free trial account lets teams run their first internal pentest before contacting sales.
Plans
Teams wanting on-demand, episodic testing · Autonomous episodic penetration testing
- Internal and external pentesting
- External asset discovery
- Cloud and Kubernetes pentesting
- Active Directory password audit
- Phishing impact testing
- Fix Actions with 1-click verify
- Comprehensive reports
- NodeZero MCP server
Teams moving to continuous validation · Continuous autonomous penetration testing
- Everything in Flex
- Scheduling for continuous testing
- Threat-informed perspectives
- Vulnerability Management Hub
- Endpoint security effectiveness
Teams needing emerging-threat coverage · Precision threat detection and emerging threat intel
- Everything in Core
- Tripwires (auto-dropped honeytokens)
- Rapid Response zero- and N-day alerting
Enterprises running risk-based exposure management · Risk-based exposure management
- Everything in Pro
- NodeZero Insights
- High-Value Targeting
- Advanced Data Pilfering
- Threat Actor Intelligence
- Vulnerability Risk Intelligence
Good to know
- Pricing is quote-based; plans are demoed rather than listed with dollar figures
- Free trial account available to run a first internal pentest
- Internal tests run from a free Docker host or virtual appliance; external tests run from the Horizon3.ai cloud
- Higher tiers unlock scheduling, Rapid Response, and advanced targeting/intel capabilities
Competition: Not a scanner, not a BAS tool, and betting the category on that
Horizon3's whole positioning is a wedge against the incumbents: static scanners that test only what you already know, breach-and-attack-simulation tools that model threats rather than prove them, and periodic manual pentests that are stale within days. Its counter is autonomous exploitation that learns and adapts with every test and delivers proof instead of opinion-based risk scores.
The strategic tell is in their recent writing, arguing the category isn't red teaming and that organizations buy answers, not activities. That's a company trying to redraw the map around exploitability-first validation, with a moat built on hundreds of thousands of production tests that, they claim, outpace the collective history of manual pentesting.
Competes with
Their edge
Where they're betting
- Redefining the category from red teaming to exploitability-first validation
- Fighting AI-powered attacks with AI (Rapid Response)
- Global expansion (new Amsterdam EMEA HQ)
- Agentic and MCP-enabled autonomous testing
Proof: The numbers Horizon3 puts on the table
The headline stat is scale run safely: more than 257,000 autonomous tests executed in production with, the company says, zero downtime across all of them. That production-safe record is the credential it trades on with high-security customers, and it's backed by real accolades rather than self-description.
Horizon3 landed #1 in Security on the Inc. 5000, #3 overall on the Deloitte Technology Fast 500, a spot on Fast Company's Most Innovative Companies, and reported 102% ARR growth heading into 2026. One customer case study says NodeZero cut attack-path impacts from 251 to zero across 18 locations, the kind of before-and-after that's hard to argue with.
What People Say: Loved for proving real attacks, dinged on reporting depth
Reviewers consistently praise the thing Horizon3 built the company around: NodeZero behaves like an actual attacker, discovering, pivoting, and chaining issues into clear attack paths tied to business impact. People like that it needs minimal setup and no agents, runs fast across broad scope, and lets non-pentesters get useful results, with one-click verify to confirm a fix without rerunning everything.
The criticism is just as consistent. Reporting can read too generic or high-level instead of clean per-asset detail, Docker installation gets tricky inside locked-down enterprise networks, and results lean on how well the environment is scoped, so conservative IP ranges can hide paths. Some reviewers note occasional false positives or missed nuanced vulnerabilities, a fair reminder that autonomous still isn't infallible.
Reviewers praise NodeZero for proving real, exploitable attack paths with little setup, while wanting deeper reporting and smoother enterprise deployment.
…without taking an attacker's perspective by considering actual attack vectors that they can use to get in, you really can't be ready.
- Behaves like a real attacker: discovers, pivots, and chains issues into clear attack paths tied to business impact
- Minimal setup, no agents, fast across broad scope
- Usable by non-pentesters; results say what to fix and how
- One-click verify to confirm a fix without rerunning the whole assessment
- Reporting can be too generic or high-level rather than clean per-asset detail
- Docker installation is tricky inside locked-down enterprise networks
- Results depend heavily on how well the environment is scoped
- Occasional false positives or missed nuanced vulnerabilities
Funding: $100M from NEA, then Aramco's fund came knocking
Horizon3 raised a $100M Series D led by New Enterprise Associates in June 2025, with SignalFire, Craft Ventures, 9Yards Capital, and Qualcomm Ventures joining, reportedly at a valuation north of $750M. Total funding sits around $178M to $183M depending on the source, from a backer list that also includes NightDragon, NewView Capital, and Bridgespan.
Then in January 2026 came a strategic investment from Prosperity7 Ventures, the diversified venturing fund of Aramco Ventures, a signal that Horizon3's global-security story is drawing sovereign-scale capital, not just Silicon Valley venture money.
Total raised
Valuation
Latest round
Backers
Outlook: Betting that machine-speed defense becomes the default
Horizon3's thesis is that cyber warfare is heading toward algorithm-versus-algorithm at machine speed, with humans by exception, and it's building NodeZero to be the defender's side of that fight. The recent moves, Rapid Response, an MCP server, a European HQ, and Aramco-linked capital, all point the same direction: continuous, autonomous, exploitability-first validation as the new baseline.
The open question is whether autonomous testing fully wins the trust of the most cautious buyers, given the reporting-depth and false-positive gripes reviewers still raise. But with triple-digit ARR growth, a category it's actively trying to define, and marquee government and Fortune 10 logos, Horizon3 is arguing from a position of strength.
Team & Culture: Learn-it-alls with a special-ops streak
Horizon3 describes its people as learn-it-alls, a deliberate anti-know-it-all posture, drawn from technology startups, Fortune 500s, and the U.S. military. The founding DNA is unusual: special operations cyber operators and national security veterans sitting alongside startup engineers, which shows up in a mission-first, attacker-minded culture that prizes grit and ownership.
On the engineering side, the work is genuinely hard and they say so plainly, building an LLM-driven autonomous pentester under a strict no-false-positives, production-safe mandate where the hard problems are reliability engineering, not chasing benchmarks. It's remote-first with offices in San Francisco, Chicago, and a new Amsterdam EMEA headquarters, and the company took a rare public moment to mourn its late CFO, Holly Grey, on its own leadership page.
- Values
- Learn-it-alls, not know-it-alls, Attacker-minded, mission-first, Respect, collaboration, ownership, and results, Grit and tenacity on hard, mission-critical problems, Diverse backgrounds from startups, Fortune 500s, and the U.S. military
- Work policy
- Remote-first with hybrid options; offices in San Francisco, Chicago, and Amsterdam. Some roles require regular in-office presence (e.g., Chicago); light travel (roughly 5-15%) for some positions.
- Hiring
- Hiring across engineering, sales, marketing, and IT/operations, with roles in the U.S. (San Francisco and Chicago), plus EMEA hubs in Amsterdam, Germany, and France; remote-first with hybrid options.
- Backend
- Python, Go, Rust, Java, TypeScript, GraphQL, SQL
- AI/ML
- LLM agents / tool use, AWS Bedrock, Model Context Protocol (MCP), LangChain, LangFlow, structured-output validation
- Browser Automation
- Playwright, Puppeteer, Selenium, Stagehand, Chrome DevTools Protocol, Node.js, TypeScript
- Data
- PostgreSQL, Neo4j, MongoDB, ETL/ELT pipelines, Airflow, Temporal
- Infrastructure
- AWS, Azure, GCP, Kubernetes, Docker, Terraform, Crossplane, ArgoCD, GitLab CI/CD, GitOps
- Observability
- Datadog, Prometheus, Grafana
- Security
- Burp Suite, Nuclei, sqlmap, SonarQube, Trivy, Trufflehog, ZAProxy, MITRE ATT&CK, Okta, SAML/OAuth
Engineering culture at Horizon3 AI
- Deterministic-first, LLM-as-scalpel philosophy: models used surgically, not as a default
- Strict no-false-positives, production-safe mandate; reliability engineering over benchmark chasing
- Small, fast-growing teams with heavy individual ownership of critical subsystems
- Design-before-build discipline with ADRs, RFCs, design and code reviews, and blameless retrospectives
Sales culture at Horizon3 AI
- Challenger / question-based selling into enterprise cybersecurity buyers
- Heavy tooling: Salesforce, Outreach.io, ZoomInfo, LinkedIn Sales Navigator, Gainsight
- Channel- and partner-led motion with dedicated field and channel roles across the Americas and EMEA
Benefits & perks
- Medical, vision, and dental insurance for you and your family
- Equity package in the form of stock options
- Flexible vacation policy plus generous holidays (4 weeks + globally per careers page)
- Generous parental leave
- Competitive salary
- Job training, conferences, and career development opportunities
Open roles · 81
View all roles →Horizon3 AI is hiring 81 roles across marketers, software engineers, sales, operations, and more.
Compensation: Published U.S. bands, equity on every full-time role
Horizon3 leans into pay transparency, publishing base ranges in its job posts to comply with state disclosure laws. Disclosed U.S. engineering bases run from roughly $102K for support engineering up to about $315K for senior leadership roles, with product and design landing in the $175K to $260K range and sales stretching wide from $80K to $450K once on-target commission is folded in.
Every full-time role is eligible for an equity package in the form of stock options, and the company states its comp philosophy is to pay fairly and consistently across roles, levels, and locations. Bands are also posted in EUR for its growing European roles.
All full-time roles are eligible for an equity package in the form of stock options; sales roles carry on-target commission that widens the effective total range well above base.
Security & Legal: The registered entity behind the AI hacker
The legal entity behind the product is Horizon3 AI, Inc., which discloses in its privacy policy that it does not directly collect or store payment card data and keeps customer data governed by contract terms separate from its general privacy policy. As a security company selling into government and regulated buyers, Horizon3 builds against the frameworks its customers live by.
Across its security-engineering roles the company names SOC 2, ISO 27001, GDPR, FedRAMP, NIST, CIS, and MITRE ATT&CK as the compliance and control frameworks its own program is held to, which doubles as a signal of the assurance posture enterprise buyers should expect.
Legal entity
Registered address
Certifications
Data practices
In the News: A raise, a European HQ, and a steady drip of attack research
The past year reads like a company pressing its advantage: a $100M Series D, a new Amsterdam headquarters to anchor EMEA, the launch of Rapid Response for AI-powered attacks, and NodeZero clearing awardable status for U.S. Department of War work in the Tradewinds marketplace. Fast Company named it to its 2026 Most Innovative Companies list.
Underneath the announcements is a prolific attack-research operation, publishing CVE disclosures, exploit analysis, and threat guidance, that keeps Horizon3's name in front of practitioners between funding headlines.
Horizon3.ai Raises $100M to Cement Leadership in Autonomous Security
Security startup Horizon3.ai is raising $100M in new round
Horizon3.ai, The Fastest Growing Cyber Company in North America, Strategically Commits to Europe with New Amsterdam Headquarters
Horizon3.ai Launches Rapid Response to Secure the Era of AI-Powered Attacks
Horizon3.ai NodeZero Assessed 'Awardable' for Department of War Work in the Tradewinds Solutions Marketplace
Horizon3.ai Named to Fast Company's Annual List of the World's Most Innovative Companies of 2026
Horizon3.ai's NodeZero Drives 102% ARR Growth
Horizon3.ai and Brinqa Partner to Help Enterprises Prioritize Real-World Cyber Exposure
More in Security
Other companies hiring in the same space.

Nord Security (164 jobs)
Nord Security is a global provider of digital security and privacy solutions for individuals and businesses, best known for its flagship product NordVPN.

TRM Labs (118 jobs)
Blockchain intelligence platform that helps governments and financial institutions trace, investigate, and freeze crypto-facilitated crime.

Vanta (114 jobs)
The leading Agentic Trust Platform, automating compliance, risk, and security proof for 16,000+ companies.

Gen Digital Inc. (112 jobs)
Consumer Cyber Safety and financial-wellness company behind Norton, Avast, LifeLock, and MoneyLion.

Socure (94 jobs)
AI-powered platform for digital identity verification, fraud prevention, and risk decisioning, used by enterprises and government agencies to verify consumers, businesses, and employees.

Delinea (69 jobs)
Cloud-native identity security control plane that extends privileged access management into continuous, real-time authorization for human, machine, and AI identities.

Illumio (65 jobs)
Breach containment platform that stops attackers moving laterally across hybrid and multi-cloud environments.
Backed by Craft Ventures
Companies that share an investor.

Neura Robotics (344 jobs)
German cognitive-robotics company building humanoid and collaborative robots that see, hear, feel, and learn to work alongside people.

Halter (227 jobs)
Halter develops solar-powered smart cattle collars and farm-management software that let farmers virtually fence, remotely move, and monitor cattle with sound and vibration cues.

Replit (90 jobs)
Agentic software creation platform that turns plain-English ideas into working, deployed apps.

Synthesia (74 jobs)
All-in-one AI video platform that lets businesses create, localize, manage and publish professional videos with AI avatars and voiceovers, no cameras or editing skills required.

Allen Control Systems (67 jobs)
Defense-tech startup building Bullfrog, an autonomous robotic weapon station that uses AI and computer vision to shoot down drones at a fraction of the cost of missiles.

ClickUp (64 jobs)
ClickUp is an all-in-one productivity platform: tasks, docs, collaboration, and AI agents in one app.
Also serving Large enterprises (Global 100 / Fortune 10)
Companies selling to a similar audience.

Cohere (128 jobs)
Enterprise AI company building secure, privately deployable foundation models and an agentic workspace (North) for regulated businesses.

Sierra (175 jobs)
Enterprise AI platform for building branded customer-service agents that resolve conversations across chat, voice, and messaging.

UiPath (126 jobs)
Enterprise platform for agentic automation, where AI agents, robots, and people work together across governed business processes.

Redis (27 jobs)
Redis is the in-memory data platform behind much of the internet's fast path, now betting its future on being the memory layer for AI agents.

MaintainX (173 jobs)
AI-powered maintenance and asset management platform for frontline industrial teams.

Mistral (151 jobs)
A French AI lab building open and frontier-grade large language models, with the full developer and enterprise stack around them.
Zip (132 jobs)
The AI platform for enterprise procurement, orchestrating every purchase from intake to pay.

Ramp (119 jobs)
All-in-one AI finance platform: corporate cards, expense management, bill pay, procurement, travel, treasury, and accounting automation.