Home / Security / NodeZero / Subscriptions

NodeZero subscription

Horizon3.ai

No offers yet

Nobody has listed this product yet. We do not invent prices: a displayed price is a public offer, and it only ever comes from a live seller.

Log in to get the notification: without an account there is nowhere to send it.

Plans

NodeZero Flex

  • Autonomous penetration tests on demand, whenever you need them
  • Internal and external testing plus external asset discovery
  • Cloud and Kubernetes cluster testing
  • Active Directory audit and phishing impact testing
  • Suggested fix actions with one-click verification and comprehensive reports
  • MCP server and vulnerability management hub

NodeZero Core

  • Everything in Flex, but testing runs continuously rather than as separate campaigns
  • Scheduled runs without manual launches
  • Testing from the perspective of current threat scenarios
  • Assessment of whether your endpoint protection actually fires
  • Fits environments that change faster than once a year

NodeZero Pro

  • Everything in Core plus precision intrusion detection
  • Honeytokens dropped automatically where an attacker would actually find them
  • Rapid alerting on emerging vulnerabilities, including ones with no patch yet
  • A check on whether the latest headline vulnerability affects you specifically, not a network in the abstract
  • The vendor's own attack research team as the intelligence source

NodeZero Elite

  • Everything in Pro plus risk management driven by test data
  • High-value target discovery — what the business actually loses if an attack lands
  • Verification of which data can genuinely be exfiltrated from the network
  • Threat actor intelligence and vulnerability prioritization by real risk
  • Executive reporting on how the organization's posture changes over time

Plan contents as published by the vendor; seller prices arrive at launch.

What you get

A NodeZero subscription is an enterprise product: the vendor does not publish its terms and arranges access through its own people or partners, usually annually and for an agreed volume of assets under test. Get the essentials from the seller: which package tier is paid for and what asset volume it is sized for, because that drives both test coverage and which capabilities switch on at all. Ask whose email and whose organization the access is registered to and whether admin rights transfer to you — without them you cannot launch a run or add a new network segment. Check the formal side separately: running tests against infrastructure requires proof that you own the assets, and that proof is given on behalf of the organization.

About the service

An autonomous penetration test that runs against your own infrastructure without hiring a team of pentesters: the agent finds reachable hosts itself, picks and chains vulnerabilities together and drives the chain to a real outcome — a stolen credential, access to data that is not yours, a domain takeover. It covers the internal network, the external perimeter, cloud and Kubernetes clusters, with a separate directory service audit and phishing impact assessment. Every finding arrives not as "possibly vulnerable" but with the attack path shown, which makes it hard to argue with, and the fix is verified by a one-click re-run. Higher tiers add continuous scheduled runs, honeytokens for early detection of an attacker, rapid alerting on freshly exploited vulnerabilities and risk reporting for leadership. An MCP server is included, so the results can be worked through with your own AI assistant.

The same from another vendor