SwissApplied AI Cybersecurity Research Lab

We hack your company
before attackers do.

AI lets attackers discover new vulnerabilities every day. 0sec does it first across everything your company runs and depends on.

Traditional security tests don’t protect you from today’s cyberattacks.

The “pentesting” concept was designed for a slower, human-led attacker, and for a team that fixes things by hand.

Test once a year

Test continuously

70%

of today’s exploits are 0-days, previously unknown

Only find known vulnerabilities

Find and fix the known and the unknown

44%

of 0-days hit the operating system, not the web app

Only test your web app

Test everything your company runs on

A long list to triage, full of false alarms

Provide fixes for verified vulnerabilities, ranked by business impact

Hand over a PDF for a human to read

Ship fixes your own agents can apply

One more SaaS dashboard to learn and log into

Arrive in the tools your team already uses

Trust vendor benchmarks and take their word for it

Run an open-source engine you can audit

0-day vulnerabilities we found.

Benchmarks test yesterday's vulnerabiltiies. The frontier is novel vulnerability discovery.

RX buffer overflow on zero-length serial frames
CVE-2026-68124 · CNA 9.6 Critical
Arbitrary code execution via crafted expressions
CVE-2026-77413 · GHSA-8gq3-vp5j-2grp
Cross-tenant agent API-token minting
GHSA-47wq-cj9q-wpmp
Anonymous /api/systemstatus leaks exception detail
GHSA-32p4-g4fj-cg95
Slab use-after-free in AEAD decrypt completion
CVE-2026-63801
Use-after-free in MACsec offload RX
CVE-2026-72072
Read our research

Engineers reviewed vulnerabilities found and fixed by 0sec. Affecting over 3 billion computers, smartphones & servers worldwide.

Frequently asked questions.

What do you test?+

We begin with an agreed scope: selected codebases, packages, web applications, or AI systems. The target and test plan are set before work begins.

Is it autonomous?+

The harness automates investigation and evidence collection. Humans set authorization and scope, then review findings before delivery.

How is this different from a scanner?+

Scanners flag potential issues. We investigate approved leads and return reproducible evidence when a finding survives verification.

Can you run this against production?+

Only with explicit written authorization and an agreed test plan. When production is not appropriate, we can use a staging environment.

What happens to our data?+

Data handling is agreed for each engagement. Targets and findings stay within the approved engagement boundary.

Can we use this for SOC 2 or ISO 27001?+

We do not sell certifications. Evidence from an engagement may support your own assurance work, subject to your review.

Is the harness open source?+

The 0sec source and CLI are published under MIT OR Apache-2.0. 0cloud operations, customer data, target scopes, and internal records are not part of that release.

What does it cost?+

You choose the target, number of agents, and hours per agent. We agree the scope and price before work starts, then stop at the approved ceiling.

Start with the tools.

We've open sourced 2 of our research tools already so you can test them out for free!

Foxguard

First-pass scanner. Local, no account.

0sec

The full engine and CLI. Findings stay on your machine.

Want us to make your company more secure with the latest research?

Let's work together to see how the latest AI research can hack your company within 24 hours.