Three comparisons, written concession first
Each of them opens by saying what the other product does better, by name, before it argues anything at all. Every statement about a competitor on those pages carries the page it was read on and the date it was read, in a table the page cannot be built without.
The oldest verification anywhere in this directory is 14 September 2026. That is the weakest row rather than the freshest one, and it is the date to judge every page here by.
Conceded first
What each of them does better
This band is at the top of the page because the reader who came to compare is exactly the reader who will check. A comparison that concedes nothing is a brochure, and one overstated line about a product somebody has already trialled costs every other line on the page its credibility.
| Comparison | What they do better than B-52 | Last re-read |
|---|---|---|
| B-52 and Pentera | Pentera is better than B-52 inside a network. Internal network and Active Directory testing is their home ground, run repeatedly against production rather than scoped and staffed each time, and B-52 makes no depth claim against Pentera Core. | 14 September 2026 |
| Conceded in full on the Pentera page, where every statement about Pentera carries the page it was read on and the date it was read. | ||
| B-52 and XBOW | XBOW proves exploitability by chaining defects into a working attack, and their API starts, pauses and cancels an assessment from your own release process. Their public record sits on scoreboards they do not run. | 14 September 2026 |
| Conceded in full on the XBOW page, where every statement about XBOW carries the page it was read on and the date it was read. | ||
| B-52 and Horizon3 | Horizon3 runs an internal pentest from a host you stand up yourself, with the requirements published in full and a trial you can start without speaking to anybody. NodeZero also tests live Kubernetes clusters, which is not one of the eleven classes B-52 covers. | 14 September 2026 |
| Conceded in full on the Horizon3 page, where every statement about Horizon3 carries the page it was read on and the date it was read. | ||
- What they do better than B-52
- Pentera is better than B-52 inside a network. Internal network and Active Directory testing is their home ground, run repeatedly against production rather than scoped and staffed each time, and B-52 makes no depth claim against Pentera Core.
- Last re-read
- 14 September 2026
Conceded in full on the Pentera page, where every statement about Pentera carries the page it was read on and the date it was read.
- What they do better than B-52
- XBOW proves exploitability by chaining defects into a working attack, and their API starts, pauses and cancels an assessment from your own release process. Their public record sits on scoreboards they do not run.
- Last re-read
- 14 September 2026
Conceded in full on the XBOW page, where every statement about XBOW carries the page it was read on and the date it was read.
- What they do better than B-52
- Horizon3 runs an internal pentest from a host you stand up yourself, with the requirements published in full and a trial you can start without speaking to anybody. NodeZero also tests live Kubernetes clusters, which is not one of the eleven classes B-52 covers.
- Last re-read
- 14 September 2026
Conceded in full on the Horizon3 page, where every statement about Horizon3 carries the page it was read on and the date it was read.
None of those is hedged with something of ours in the same breath. Each is conceded in full on its own page, in the first block, and the arguments B-52 does make sit after it where they can be read against it.
The short list
Three pages, and why there are not more
Demand is checked at both of the locations we measure before a comparison page is written. Three competitors return it. For the others, the term somebody would type when they are looking for an alternative returns no data at either — so there is no page for them here, and that absence is a measurement rather than an opinion about their product.
| Competitor | What the demand check returned | What we publish |
|---|---|---|
| Pentera | Measured demand from people looking for a way out of a product they already run. It is the strongest alternative-seeking signal on this project. | B-52 and Pentera |
| XBOW | Measured demand, and it is mostly people trying to find out what it costs. | B-52 and XBOW |
| Horizon3 | Measured demand, again mostly on price — for the company and for NodeZero separately. | B-52 and Horizon3 |
| Four others | Astra, Cobalt, Ridge Security and Vonahi. The alternative-seeking term for each returns no data at either location we measure. | No page here, and none until that changes |
- A comparison page exists, and it carries dates
- No measured alternative-seeking demand, so no page
A comparison page for a competitor nobody is searching for is a claim surface with no traffic behind it. It still has to be re-read against their own pages every quarter, and every row on it is a statement about somebody else’s product that can quietly go wrong in the meantime. Writing the other four would make this directory longer and less accurate at the same time.
If the product you are evaluating is not on that list, a scoping call is the faster answer than a page we would have to write first — tell us what you are comparing against and the coverage question can be answered directly.
Our side of it
What B-52 publishes, in one table
Facts about B-52 only. There is no competitor column here on purpose: a claim about somebody else’s product is worth reading only beside the page it was read on and the date it was read, and those live on the comparison pages above, where the format forces both.
| What an evaluation asks | What B-52 publishes |
|---|---|
| Coverage | Eleven classes on one platform: Web applications, Mobile apps, APIs, Thick client, External network, Internal network, Cloud, Active Directory, Social engineering, Secure code review, LLM applications. Physical, hardware and wireless are out of scope for the platform entirely, and that exclusion is stated in the same words on every class page. |
| Delivery | Three models: fully autonomous, where a person signs off scope and nothing after it; autonomous with expert verification, where a senior auditor verifies every finding; and human led. All three cover all of the classes above. What differs is whose signature the report carries, never what is tested. |
| Evidence per finding | A reproducible exploit artefact on every finding: the request, the response, the steps that reproduce it, a CVSS v4.0 vector and a CWE. |
| Published price | $500 for one scan of one application or target, and a paid trial at $299. Anything larger than one target is a scoping call; the rest of the ladder is not published. |
| What you can buy on a card | The self-serve flow reaches the five application classes — web applications, mobile apps, APIs, thick client and secure code review. The other six start with a scoping call. |
| Pipelines | A step in GitHub Actions, GitLab CI, Jenkins or Azure DevOps, each in production with customers. A result can fail a build on a severity threshold you set, at the point in the pipeline where you place the step. |
| Deployment | Nothing is required inside your network for external and application testing. Internal testing needs a deployed position. On-premise and your own cloud tenancy are both available today. |
| Residency | India, the European Union, the United States, and Singapore for Asia-Pacific. |
| Turnaround | An observed median of one to three business days, for the fully autonomous model only. It is a median rather than a service level, and no figure exists for the other two models, so none is given. |
| Benchmark | Run in parallel with Security Brigade’s expert assessment team against the same targets, with both sets of findings pooled and each item counted once, B-52 reached 90–95% of that pooled set. |
| Instruments | Security Brigade started in 2006, has been CERT-In empanelled since 2008, and is ISO 27001 certified. Those are the firm’s. The B-52 platform holds no certification of its own. |
- What B-52 publishes
- Eleven classes on one platform: Web applications, Mobile apps, APIs, Thick client, External network, Internal network, Cloud, Active Directory, Social engineering, Secure code review, LLM applications. Physical, hardware and wireless are out of scope for the platform entirely, and that exclusion is stated in the same words on every class page.
- What B-52 publishes
- Three models: fully autonomous, where a person signs off scope and nothing after it; autonomous with expert verification, where a senior auditor verifies every finding; and human led. All three cover all of the classes above. What differs is whose signature the report carries, never what is tested.
- What B-52 publishes
- A reproducible exploit artefact on every finding: the request, the response, the steps that reproduce it, a CVSS v4.0 vector and a CWE.
- What B-52 publishes
- $500 for one scan of one application or target, and a paid trial at $299. Anything larger than one target is a scoping call; the rest of the ladder is not published.
- What B-52 publishes
- The self-serve flow reaches the five application classes — web applications, mobile apps, APIs, thick client and secure code review. The other six start with a scoping call.
- What B-52 publishes
- A step in GitHub Actions, GitLab CI, Jenkins or Azure DevOps, each in production with customers. A result can fail a build on a severity threshold you set, at the point in the pipeline where you place the step.
- What B-52 publishes
- Nothing is required inside your network for external and application testing. Internal testing needs a deployed position. On-premise and your own cloud tenancy are both available today.
- What B-52 publishes
- India, the European Union, the United States, and Singapore for Asia-Pacific.
- What B-52 publishes
- An observed median of one to three business days, for the fully autonomous model only. It is a median rather than a service level, and no figure exists for the other two models, so none is given.
- What B-52 publishes
- Run in parallel with Security Brigade’s expert assessment team against the same targets, with both sets of findings pooled and each item counted once, B-52 reached 90–95% of that pooled set.
- What B-52 publishes
- Security Brigade started in 2006, has been CERT-In empanelled since 2008, and is ISO 27001 certified. Those are the firm’s. The B-52 platform holds no certification of its own.
Every engagement since Security Brigade started in 2006 was worked inside Lemon, the firm’s own assessment platform, and that record is what trained the models behind B-52. It is also the argument for the first row of the table: the classes are not a roadmap written outwards from one of them, they are the work the firm was already doing.
Freshness
Competitive claims go stale, so every one of them is dated
Every product named here is being actively developed, and a capability can arrive between one reading and the next. So each page is written so that a reader can tell exactly how far a row has aged, and check it in the same place we did.
How this directory is kept As of 14 September 2026
- Every page here was re-read in one sitting, against each competitor’s own pages rather than against anybody’s summary of them.
- Each statement about a competitor sits in a table on its own page with the page it was read on and the date it was read. The template will not build a comparison that has none.
- The date above is the oldest verification in the whole directory, not the newest. A banner quoting its freshest row is telling you about its best page.
- The next re-read of the whole directory is diarised for January 2027. Anything older than a quarter is worth checking against the vendor’s own pages before you rely on it.
Deliberately excluded
- No competitor price appears on this page. Where a vendor publishes one it sits on that vendor’s own comparison page with its source and date, because a published price changes without notice.
- No ratio, multiple or percentage comparing the two products appears anywhere in this directory. The two figures we publish are $500 and $299, and the arithmetic is yours to do.
- No named customer reference, here or on any page of this site. Where an engagement is described it is an anonymised composite.
The quickest comparison is a scan of your own application
One scan is one application or target, from $500, and card payment works without a sales conversation. Where the estate is larger than one target, or the report has to carry a signature, a scoping call settles it faster than a form.