What is ZeroThreat.ai?

As an AI-powered penetration testing solution, ZeroThreat.ai detects and confirms actionable, exploitable vulnerabilities in modern APIs and web applications. Its Agentic AI engine deploys dynamic attacker workflows to simulate realistic attack paths, proving actual exploitability and filtering out false alarms.

Equipped with real-time CVE coverage and proof-based validation, the platform utilizes Playwright-driven Application Journeys to test deep business logic, authenticated sessions, and APIs that standard web crawlers miss. It also supports custom and community-sourced attack templates to enhance testing scope with current attack tactics.

By centering on confirmed findings instead of high-volume vulnerability counts, ZeroThreat.ai cuts manual triage time by over 90%, giving security teams the clarity needed to fix critical risks efficiently while running continuous, production-safe assessments.

Pricing

Price Starts At:
$100/Target
Free Version:
Free Version available.
Free Trial Offered?:
Yes

Screenshots and Video

Company Facts

Company Name:
ZeroThreat Inc.
Date Founded:
2023
Company Location:
United States
Company Website:
zerothreat.ai/
Edit This Page

Product Details

Deployment
SaaS
Training Options
Documentation Hub
Video Library
Support
Web-Based Support

Product Details

Target Company Sizes
Individual
1-10
11-50
51-200
201-500
501-1000
1001-5000
5001-10000
10001+
Target Organization Types
Mid Size Business
Small Business
Enterprise
Freelance
Nonprofit
Government
Startup
Supported Languages
English

ZeroThreat.ai Categories and Features

More ZeroThreat.ai Categories

ZeroThreat.ai Customer Reviews

Write a Review
  • Reviewer Name: David R.
    Position: Security Architect
    Has used product for: Less than 6 months
    Uses the product: Weekly
    Org Size (# of Employees): 26 - 99
    Feature Set
    Layout
    Ease Of Use
    Cost
    Customer Service
    Would you Recommend to Others?
    1 2 3 4 5 6 7 8 9 10

    Found a bunch of APIs we forgot about

    Updated: May 01 2026
    Summary

    After moving to microservices, we lost visibility into some endpoints and were concerned about shadow APIs. ZeroThreat.ai helped map our API ecosystem quickly, including endpoints we thought were inactive. What stood out was its ability to test business logic issues like BOLA, which usually requires manual pentesting. The reports were simple and included actionable code fixes.

    Positive

    - Strong API discovery, including hidden endpoints
    - Tests for complex logic vulnerabilities like BOLA
    - Clear, developer-friendly reports
    - Provides actionable remediation guidance

    Negative

    - Initial mapping may require fine-tuning for large systems
    - Some advanced configurations need security expertise

    Read More...
  • Reviewer Name: Kai B.
    Position: Principal Security Engineer
    Has used product for: 6-12 Months
    Uses the product: Weekly
    Org Size (# of Employees): 26 - 99
    Feature Set
    Layout
    Ease Of Use
    Cost
    Customer Service
    Would you Recommend to Others?
    1 2 3 4 5 6 7 8 9 10

    Tested it against a known-vulnerable environment before trusting it in production

    Date: May 25 2026
    Summary

    I don't deploy tools into our pipeline without validating them first. I set up a deliberately vulnerable API environment — OWASP API Security Top 10 style — and ran ZeroThreat.ai against it before touching anything real. It caught 8 of the 10 categories. Missed a rate limiting issue and a mass assignment vulnerability that needed more application context to detect. That's a reasonable hit rate for an automated tool and honestly better than I expected.

    In production it's been running for four months. It's found two genuine access control issues that our quarterly manual assessment hadn't caught. The BOLA detection in particular is better than anything I've seen from an automated scanner.

    Positive

    BOLA and broken function-level authorization testing is genuinely strong — better than competitors I've evaluated.
    Transparent about what it can and can't detect, which I appreciate more than overpromising.
    API discovery found three endpoints in our staging environment that weren't in our internal docs.

    Negative

    Mass assignment vulnerabilities and some rate limiting issues need more manual follow-up — the tool doesn't catch everything.
    Would like to see more granular control over which test modules run. Right now it's a bit all-or-nothing.
    Documentation for edge-case authentication setups is thin. Had to contact support for our custom JWT flow.

    Read More...
  • Previous
  • You're on page 1
  • Next