Four packaging tiers are published by name — NodeZero Flex (“Autonomous Episodic Penetration Testing”), Core (“Continuous Autonomous Penetration Testing”), Pro (“Precision Threat Detection and Emerging Threat Intel”) and Elite (“Risk-Based Exposure Management”). No dollar figure is published against any tier.
- Verified
- 2026-09-14
Read at https://horizon3.ai/pricing/
Every tier, including the entry tier, includes Internal Pentesting, External Pentesting, External Asset Discovery, Cloud Pentesting, Kubernetes Pentesting, Active Directory Audit, Phishing Impact Testing, Fix Actions with verification, reporting, the NodeZero MCP Server, a Vulnerability Management Hub, and Endpoint Security Effectiveness.
- Verified
- 2026-09-14
Read at https://horizon3.ai/pricing/
NodeZero WebApp Pentesting is sold as an add-on rather than as part of any base tier, in two variants — episodic alongside Flex, or continuous alongside Core, Pro and Elite.
- Verified
- 2026-09-14
Read at https://horizon3.ai/pricing/
Internal pentests run from a customer-deployed machine: “Internal tests are run from a free Docker host or open virtualization appliance (OVA) that you can set up in minutes.” The machine is free; the licence is paid.
- Verified
- 2026-09-14
Read at https://horizon3.ai/nodezero/
External tests are executed in the “Horizon3 cloud” using “dedicated, ephemeral resources” in “an isolated virtual private cloud network”. Nothing is placed in a customer network for external testing.
- Verified
- 2026-09-14
Read at https://horizon3.ai/nodezero/
NodeZero Host requirements are published in full: Ubuntu 20.04 LTS or later or RHEL 9+; Docker 20.10 or later, or Podman 4.0 or later; 2 processor cores minimum and 4 recommended; 8 GB memory minimum and 16 GB for heavy workloads; 40 GB free disk, 80 GB solid state preferred; git and bash. The documentation instructs: “Do not install or configure any EDR (Endpoint Detection and Response) services on the NodeZero host.”
- Verified
- 2026-09-14
Read at https://docs.horizon3.ai/quickstart/setup_host/manual_host/host_requirements/
The NodeZero Host needs outbound HTTPS and HTTP (443, 80) to region-specific Horizon3 endpoints, with separate domain sets for the EU and AU portals. Inbound requirements are internal-network only; there is no inbound requirement from Horizon3.
- Verified
- 2026-09-14
Read at https://docs.horizon3.ai/quickstart/network_requirements/
The internal pentesting product page states: “With a SaaS architecture, there’s no hardware or software to maintain and no required agents to install.”
- Verified
- 2026-09-14
Read at https://horizon3.ai/nodezero/internal-pentesting/
Internal pentesting names credential attacks and dumping, man-in-the-middle, password cracking and spraying, credential phishing, OS credential dumping, Log4Shell, Zerologon and RAT implantation, aligned to MITRE ATT&CK. The page states: “Many of the attack paths NodeZero executes don’t involve exploiting any CVEs.”
- Verified
- 2026-09-14
Read at https://horizon3.ai/nodezero/internal-pentesting/
External pentesting covers ransomware exposure assessment, misconfigured third-party applications, weak and default credentials, public-facing asset vulnerabilities, hybrid cloud assets, and third-party or supply chain risk. Asset Discovery is “a passive enumeration capability that leverages DNS and other Open Source Intelligence (OSINT) gathering capabilities”. Tests “can be set up within minutes and executed as often as needed”.
- Verified
- 2026-09-14
Read at https://horizon3.ai/nodezero/external-pentesting/
Kubernetes pentesting is in-cluster: NodeZero “deploys within Kubernetes clusters using Kubernetes Operators and Infrastructure-as-Code (kubectl)” and tests “live, running clusters” for “RBAC misconfigurations, container escapes, and secret exposures”.
- Verified
- 2026-09-14
Read at https://horizon3.ai/nodezero/kubernetes-pentesting/
The cloud pentesting page names AWS, Azure and Kubernetes, and states “NodeZero is deployable both on-prem and in the cloud.”
- Verified
- 2026-09-14
Read at https://horizon3.ai/nodezero/cloud-pentesting/
NodeZero Federal is delivered as “secure SaaS with enforced SSO”. No on-premise, self-hosted or air-gapped deployment option is offered on that page, including for federal customers.
- Verified
- 2026-09-14
Read at https://horizon3.ai/vertical/federal/
NodeZero Federal is FedRAMP High Authorized under the Federal High Impact Virtualized Environment (FedHIVE), Package ID FR1802451335, announced 15 May 2025 following review by a FedRAMP-accredited Third Party Assessment Organization (3PAO).
- Verified
- 2026-09-14
Read at https://horizon3.ai/vertical/federal/
NodeZero WebApp requires customer infrastructure for authenticated or private testing: “Applications behind a VPN or private network are tested through a NodeZero Runner with network connectivity to the target,” and “A NodeZero Runner with network connectivity to the target is required in order to use the credentials.” Unauthenticated, internet-reachable applications need no such machine.
- Verified
- 2026-09-14
Read at https://docs.horizon3.ai/portal/test_types/webapp/
NodeZero WebApp covers route discovery and crawling via headless browser automation, authenticated testing with multi-role support, parameter testing across query strings, headers, cookies and request bodies, exploitation, and attack chaining across networks. REST, SOAP and GraphQL endpoint discovery and single-page application testing are named on the product page.
- Verified
- 2026-09-14
Read at https://horizon3.ai/nodezero/webapp/
The NodeZero WebApp launch release is dated 29 July 2026 and claims “Coverage of the OWASP Top 10”, detection of “complex access-control failures that traditional scanners routinely miss”, continuous autonomous testing of pre-production and production applications, and “Full attack-path chaining”. The OWASP Top 10 wording appears in the release rather than on the product page.
- Verified
- 2026-09-14
Read at https://horizon3.ai/news/press-release/nodezero-webapp-launch/
NodeZero WebApp early access ran with “95 customers globally, including Fortune 10 enterprises”, and the release states that during beta “a major social media company discovered a broken access control flaw in a critical component that was missed by human reviewers”.
- Verified
- 2026-09-14
Read at https://horizon3.ai/news/press-release/nodezero-webapp-launch/
Pentera announced web application penetration testing on 29 July 2026 — the same day as the NodeZero WebApp release — in beta, with general availability published as rolling out in Q4 2026.
- Verified
- 2026-09-14
Read at https://pentera.io/press-release/pentera-ai-web-app-pentesting/
Homepage and platform autonomy claims: “Safely and autonomously hack your production environment”, “NodeZero® autonomously executes real attack techniques, without agents or disruption”, “NodeZero navigates through your network without scripts”, and that it “exploits weaknesses based on its discoveries just as attackers do, chaining weaknesses”.
- Verified
- 2026-09-14
Read at https://horizon3.ai/
Social proof: the homepage reads “Trusted by NSA and 4 of the Fortune 10” with a customer counter showing 7,012 on 2026-09-14, while the dated 29 July 2026 release states “More than 6,500 organizations, including the NSA, CISA, major healthcare providers and four of the Fortune 10.” The homepage figure appears to be a live counter and moves.
- Verified
- 2026-09-14
Read at https://horizon3.ai/
A documented GraphQL API is published at a single /graphql endpoint, supporting scheduling pentests, retrieving weaknesses, hosts, credentials and attack paths, deploying runners and creating templates. An h3-cli command-line tool is published with guides for scheduling, automating deployment, injecting credentials and monitoring pentests.
- Verified
- 2026-09-14
Read at https://docs.horizon3.ai/api/graphql/
Third-party integrations with published setup guides: Jira, ServiceNow VR, Splunk Cloud and Microsoft Sentinel.
- Verified
- 2026-09-14
Read at https://docs.horizon3.ai/
The NodeZero MCP Server is positioned as “The Exploitability Data Engine for Agentic Security Workflows”, claiming it “operationalizes FixOps by connecting your AI ecosystem to the exploitability intelligence it needs”. Named uses include prioritisation by proven attack path, ticket enrichment, continuous retesting, and “security validation in CI/CD pipelines before deployment”. This page is the only place CI/CD appears on their site or documentation.
- Verified
- 2026-09-14
Read at https://horizon3.ai/nodezero/mcp-server/
A 30-day free trial is published and self-service: “Once your 30 day free trial is over, you will be placed back into read-only mode.” It requires a company information form and a valid company email verified by token, and “You can only verify a company email for a free trial once.”
- Verified
- 2026-09-14
Read at https://docs.horizon3.ai/quickstart/register/upgrade/
The compliance page positions NodeZero against PCI DSS v4.0, SOC, DORA, GDPR, CIS, NIST and CMMC, and offers “Expert human analysis by Offensive Security Certified Professional (OSCP) pentesters” alongside the platform.
- Verified
- 2026-09-14
Read at https://horizon3.ai/compliance/
Press releases published since 1 June 2026 include: a $250 million Series E at a stated $2B+ valuation (3 August 2026); a $20 million investment in partner-led growth (5 August 2026); a World Wide Technology partnership (27 July 2026); an EMEA headquarters in Amsterdam (29 June 2026); a Brinqa partnership (3 June 2026); and a “Rapid Response” launch (1 June 2026).
- Verified
- 2026-09-14
Read at https://horizon3.ai/category/news/press-release/