Horizon3.ai is a cybersecurity company focused on proactive security validation through autonomous pentesting. Its NodeZero Platform helps organizations continuously find, fix, and verify exploitable attack paths across production environments by emulating how attackers move through internal networks, internet-facing assets, cloud infrastructure, identity systems, and Kubernetes environments.
Founded in 2019 and headquartered in San Francisco, Horizon3.ai positions its approach around proof-based security rather than theoretical exposure. The company emphasizes safe testing in production, rapid retesting after remediation, and attacker-perspective evidence that helps security teams understand which weaknesses create real business risk and which fixes measurably reduce it.
Offerings, Capabilities, and Integrations
Horizon3.ai delivers autonomous security validation that combines attacker-style discovery, exploitation, lateral movement, impact analysis, and fix verification in a single workflow. Its capabilities span internal, external, cloud, and Kubernetes testing, along with credential-focused assessments, phishing-driven validation, emerging-threat response, and deception-based detection. The platform is designed to help teams move from vulnerability backlogs to validated risk reduction.
Beyond testing, Horizon3.ai supports operationalization through trend reporting, exposure analysis, remediation workflows, and repeatable security programs. Horizon3.ai also offers integrations and connected workflows for enterprise operations, including Jira and ServiceNow for remediation processes, Splunk and Microsoft Sentinel for alerting and monitoring use cases, and MCP-based connectivity that exposes exploitability data to AI-driven and automation workflows.
Products and Services
- NodeZero Platform: Horizon3.ai’s flagship autonomous pentesting platform for continuously finding, prioritizing, and verifying exploitable attack paths across production environments.
- Internal Pentesting: Autonomous internal network pentesting that simulates an attacker or malicious insider already inside the environment to uncover lateral movement, credential abuse, and downstream impact.
- External Pentesting: Internet-facing pentesting that discovers exposed assets, tests perimeter weaknesses, and maps external-to-internal attack paths.
- Kubernetes Pentesting: Autonomous testing for Kubernetes clusters that identifies exploitable vulnerabilities, RBAC issues, secret exposures, and other misconfigurations.
- Cloud Pentesting: Cloud security testing for environments such as AWS and Azure that evaluates exploitable vulnerabilities, IAM weaknesses, and cloud misconfigurations.
- NodeZero Tripwires: Decoy and monitoring capabilities that deploy during pentests to create early warning signals when attackers interact with high-risk exposures.
- Rapid Response: A service and testing capability that helps customers assess newly emerging threats quickly with targeted validation and early actionable intelligence.
- AD Password Audit: Active Directory password auditing that identifies weak, reused, and exposed credentials to support credential hardening.
- Phishing Impact Testing: Testing that uses simulated phished credentials to measure blast radius and show what an attacker could do with compromised user accounts.
- NodeZero MCP Server: An MCP-based service that makes NodeZero exploitability data and test execution accessible to AI assistants, IDEs, and automation workflows.
- NodeZero Insights: Analytics and dashboarding capabilities that aggregate test data over time to show trends, remediation progress, and security posture metrics.
- Threat Informed Perspectives: Attacker-aligned scenario views that help organizations measure blast radius, control effectiveness, and exposure from specific footholds.
- Pentesting Campaigns: Program management capabilities that structure repeatable testing around initiatives such as identity, cloud posture, and compliance.
- Vulnerability Management Hub: A centralized workspace for managing proven weaknesses, assigning remediation, syncing workflows, and verifying fixes through retesting.
Target Customers
Horizon3.ai targets security teams that need continuous validation rather than occasional point-in-time assessments. Its platform is suited to enterprise security, security operations, IT infrastructure, and risk teams that want proof of exploitability, faster remediation prioritization, and measurable verification of fixes across hybrid environments.
Horizon3.ai serves both commercial and public sector organizations, with particular relevance for regulated and high-consequence environments such as healthcare, financial services, manufacturing, critical infrastructure, and government. Its offerings also align with managed security service providers, managed service providers, resellers, and advisory partners that want to deliver repeatable offensive security and validation services to their own customers.
Cloud Integrations and Marketplace
- AWS Marketplace: Horizon3.ai offers verified AWS Marketplace availability for the NodeZero Platform, and it also lists the NodeZero MCP Server through AWS Marketplace for agentic AI and automation use cases.
Key People
- Snehal Antani: Co-Founder, CEO
- Matthew Hartley: Chief Revenue Officer
- Holly Grey: Chief Financial Officer
- Andres Botero: Chief Marketing Officer
- Jill Passalacqua: Chief Legal Officer
- Torie Runzel: Chief People Officer
- Chris Corbett: Vice President of Engineering
- Erick Dean: Vice President of Product
- Ellen Sundra: Vice President of Customers
- Tim Mackie: Global Vice President of Worldwide Channels
Key Facts
- Headquarters: San Francisco, California, United States
- Employees: Approximately 250-275
- Annual Revenue: $30M-$51M
- Parent Company: None
- Subsidiaries: Horizon3.ai Europe GmbH
- Publicly Listed: Privately held
Analyst Recognitions
- Gartner: 2025 Gartner Market Guide for Adversarial Exposure Validation — Representative Vendor. 2025 Gartner Hype Cycle for Security Operations — Sample Vendor in Adversarial Exposure Validation. 2025 Gartner Peer Insights “Voice of the Customer”: Adversarial Exposure Validation — Customers’ Choice.