Skip to content

Software already builds software.
Now it can secure itself, too.

We take care of security so you can keep building.

Today, fixing things by human hand is no longer fast nor good enough.

Welcome to the post-pentest era.

By prioritizing vulnerabilities based on actual business impact and providing validated, actionable remediation, 0.security enables security teams to focus their resources where they matter most. A compelling AI-powered security solution for enterprise environments.

Roman Haltinner

Partner & Europe West Cybersecurity Competency Leader, Switzerland, at

The best security tool is one you don’t have to use.

Set it up once and forget about it.

Zero.
Zero hovering peacefully in meditation

Peace of mind.

Powerful enough to secure governments, hack operating systems and fix software billionsPublic service, literally. rely on.

Looks cute. Breaks serious software.

We find & fix novel vulnerabilities (0-days) in the software the world runs on.

Engineers at these companies reviewed fixes we submitted.

Zero sitting low and striking a phone between his feet
Your phone.
Zero standing and smashing a laptop on his familiar gray desk
Your laptop.
Zero bracing a foot against a server while pulling his axe free
Your servers.
CriticalRX buffer overflow on zero-length serial framesLinux kernel · mctp
CriticalArbitrary code execution via crafted expressionsjsonata
CriticalCross-tenant agent API-token minting@paperclipai/server
MediumAnonymous /api/systemstatus leaks exception detailSwiss Federal Chancellery · government code
HighSlab use-after-free in AEAD decrypt completionLinux kernel · TIPC
HighUse-after-free in MACsec offload RXLinux kernel · mlx5e

Get started in 2 minutes.

  1. Zero plugging in a connection

    Connect your code.

    CLI
    GitHub
    Coming soon
    GitLab
  2. Zero presenting a completed checklist

    Receive auto-fixes.

    PR
    Agent
    Coming soon
    PR
    Slack
    Ticket
    Jira
    Linear

Security handled, 24/7.So you can focus on building.

How it works

  • No dashboard to watch.
  • No scans to start.
  • You build.
    Zero finds and fixes.
  1. He studies your style
  2. He makes a testing plan

    Zero runs this schedule automatically.

    Always-on coverage
    Code reviews
    Every PR / push
    Full-codebase scans
    Daily
    Secrets checks
    Every push
    Monitoring
    Threat & CVE alerts
    Auto-scheduled tests
    Source code scans
    Daily
    Website & APIs
    Weekly + major releases
    Dependencies
    Weekly
    Cloud & infrastructure
    Every 2 weeks

    Daily scans run overnight when code changes.

  3. He finds problems
  4. He fixes them
  5. He tells youor your agent.
  6. He gets better

Our AI hackers think in exploit chains to1 find, 2 verify and 3 auto-fixthe most complex vulnerabilities.

Working in the background for you. 24/7

Start Zero

Always-on

Find & fix vulnerabilities 24/7.

Security Reviews

Checks your code changes

  • PR reviews

    Checks your code changes & releases

  • Scans

    Checks your Full Code base

  • Secrets

    Removes forgotten API keys

  • Monitoring

    Attack surface, Threat & CVE alerts

Auto-scheduled

Tailor-made to your stack, coding style & speed.

Security Tests

Hacks like a real AI-powered attacker

  • Source Code
  • Website
  • APIs
  • Dependencies
  • Apps
  • Cloud & Infrastructure
  • Operating System
  • AI & LLMs
  • White-boxtesting
  • Black-boxtesting
  • Gray-boxtesting

Start now for free.

Open Source Community

$0Forever free

  • Run locally with your own models (BYOK).
  • Add your tools. Make it yours.
  • No 0.security account required.

Your software evolves.
We keep it secure.

  • Security handled.

    No scans to start.No infrastructure to maintain.

    Security runs in the background while you build. Every agent runs in a new sandbox, isolated at the deepest layer to keep your environment safe.

  • Test more and deeper.

    Up to hundreds of agents investigate attack paths in parallel, combining what they find to uncover zero-days before attackers do.

  • Get the engine behind our proven discoveries.

    The research, models and hacking tools we use to find vulnerabilities in software billions of devices and governments rely on. See the findings ↗

  • Stop wasting time on false alarms.

    We reproduce findings to confirm they’re real, prioritise them by business impact and then open a PR with the fix for you or your agent to approve or review.

We are building the world’s first self-evolving, multi-model cybersecurity harness.

Continuous

Self-improving

Multi-model

Open source

Extensible

Traditional security tests don’t protect you from today’s cyberattacks.

Test annuallyTest with every change

Traditional approach

With 0.security

Misleading prioritizationPrioritize fixes by business impact

Traditional approach

With 0.security

Only map known vulnerabilitiesFind known vulnerabilities and 0-days

Traditional approach

70% of today’s exploits are 0-days, previously unknown

With 0.security

Test your web app onlyTest your entire stack

Traditional approach

44% of 0-days hit the operating system, not the web app

With 0.security

Work through a PDFShip patches your agents can apply

Traditional approach

With 0.security

Cursor, Claude Code, Codex, Gemini CLI, GitHub Copilot, OpenCode
Manage another dashboardFindings and patches in your existing tools

Traditional approach

With 0.security

GitHub, GitLab, Slack
Trust vendor claimsRun an open-source engine

Traditional approach

With 0.security

GitHub
Use fixed tools and rulesSelf-improvement loop

Traditional approach

With 0.security

Don’t believe me?

Frequently asked questions.

About the research, the product, and the little ninja.

You have a little ninja. Do you take security seriously?

Very. We find previously unknown vulnerabilities in software billions of people depend on, including the Linux kernel that powers Android phones and servers around the world. We collaborate with leading AI labs and defence organizations. You can read our public disclosures and inspect the fixes.

That’s Zero, by the way. Who said security had to look boring?Bored Zero sitting with his head resting on one hand

What is 0.security?

We’re an applied AI and cybersecurity research lab. We find previously unknown vulnerabilities and turn that research into security people can use. Our first product brings that work into your development workflow, finding and fixing weaknesses while you build.

Why is this needed now?

Attackers are quick to adopt new technology. AI is no exception: it helps them investigate more targets, discover vulnerabilities and develop exploits faster. Security needs to keep pace with both the attackers and the software your team is shipping.

We put agents to work continuously, investigating attack paths and preparing fixes as your software changes. Recent incidents involving agents taking unauthorized actions also show why that power needs carefully designed infrastructure around it.

I already use an AI security tool like Aikido or Strix. Why would I need this?

Good. Keep what works for you. Tools like these focus heavily on application security, especially web apps and APIs. Our research goes deeper into the software underneath: operating systems, kernels and the components your applications depend on. Our Linux kernel discoveries show that work in practice.

Our specialty is novel vulnerability research: finding weaknesses nobody has reported before. In one published analysis, 70% of exploited vulnerabilities were zero-days. Matching your software against known CVEs alone won’t uncover those.

We combine that research with ongoing investigations and fix PRs in your existing workflow. Set it up once, then let the work run in the background. The value is deeper investigation with less work for your team.

And yes, you get Zero.

What does 0.security actually do?

Codebase scans, PR reviews, secret detection, vulnerability monitoring and pentesting. Our agents investigate different attack paths in parallel and combine what they find to uncover problems across your software. We learn how you build, recommend what to test and how often, and turn confirmed findings into fix PRs.

Which parts of my software can you check?

Your source code, dependencies, websites, APIs, apps, cloud infrastructure, operating systems and AI systems. We investigate how these parts connect, because an attack can start in one place and reach something much more valuable elsewhere.

Your web app is only part of the picture. Operating systems accounted for 44% of exploited zero-days (2025), making them the largest category. Your security needs to reach the software underneath your application, too.

Do you do pentesting, too?

Yes. The product currently offers white-box pentesting: agents use access to your code to investigate how your software could be exploited. We also use black-box and grey-box testing in our research, approaching systems from the outside or with limited access. We’re bringing those capabilities into the product next.

We already have more findings than we can fix. Why would we want more?

You want problems fixed, not a longer backlog. That’s why we reproduce findings to confirm they’re real, prioritise them by business impact and open PRs with fixes for you or your agent to review. Enterprise adds independent verification that the fixes actually resolve the vulnerabilities.

Your team spends less time investigating alerts and working out what to change, and more time getting repairs shipped.

Another dashboard to check. More work to manage?

No. Your workflow is the interface. We handle the testing in the background and bring findings and fix PRs into the tools you already use. No dashboard to babysit, no scans you have to remember to start. Want to run an investigation yourself? You can, through the CLI.

Coding agents put more engineering power in your hands. We’re doing the same for security: agents that investigate, test and prepare fixes while you build. The point is to give you time back, not another tool to operate.

What makes this AI-native?

Agents do the security work: planning investigations, exploring attack paths, writing tools when they need them and preparing fixes. We select models for different tasks, and agents combine their findings.

The entire workflow is built around delegating that work, from investigation to repair. You shouldn’t have to supervise every step to get a useful result.

What does your research have to do with my code?

You get the research, models and hacking tools behind our discoveries in software billions of devices and governments rely on. Real attack paths and verified findings help guide new investigations. Our public disclosures and upstream fixes let you inspect the work behind the product.

Can I integrate this into CI/CD and my existing workflow?

Yes. You can run the open-source harness through the CLI in your CI/CD pipeline and make security testing part of how you build and release.

With the managed service, we handle the infrastructure and ongoing testing, with findings and fix PRs arriving in your development workflow. Your engineers or coding agents can review the work where they already build.

How do you keep powerful agents from becoming another security risk?

Tests run in fresh, disposable virtual-machine sandboxes, with isolation below the guest operating system, at the virtualization layer. This separates agent execution from your environment. Runs have time limits, and their sandboxes are torn down afterwards.

Incidents involving Mythos demonstrated what can happen when agents gain unintended access to real systems. That’s why the infrastructure around the model matters. We combine isolated execution with defined testing scope and enterprise approval controls, so your team can delegate work while retaining control over what gets tested and what changes are applied.

Can our enterprise team stay in control without supervising every agent?

Yes. You set the scope, budget and where approvals are required. Agents carry out the work without needing someone to direct every step.

Your team can review the evidence and fix PRs, require approval before changes are merged, and track what was tested and changed. We work with you on deployment requirements and how the service fits your existing processes.

If the engine is open source, what am I paying for?

The engine is free to inspect, run and extend with your own models and tools. No 0.security account required.

With the managed service, we run the infrastructure, select the models and put our research to work on your software. You’re paying for the security work being handled.

What do you mean by “self-evolving”?

Agents write and run their own tools on the fly, then reuse them. We’re building on this with evaluated improvements to their tools and workflows.

Put simply: if an agent needs a tool it doesn’t have, it can build one. To improve over time, it tries changes, checks whether they help and keeps the better version.

What are you building toward?

Software is already writing itself. This closes the loop: software that builds, secures and improves itself.

Our first product is a step toward that future, making security part of how software evolves. We want the developer shipping alone, the startup moving quickly and the enterprise running critical systems to benefit from the same research.

How do I start, and what will it cost?

Connect GitHub and choose your project. Your first security test is on us, with results arriving as checks finish.

We learn how you build, then recommend ongoing testing and a usage-based price. You approve the plan and budget before paid work starts. Set up the ongoing work once; you don’t need to configure every run yourself.

Tell us what your team needs.

We’re building the next generation of security products around real needs. Tell us what’s difficult today, what takes too much time, and what you wish worked better.

Talk to our team