Hack any software
before attackers do.

The Swiss Applied AI & Cybersecurity Research Lab

Your Phone, Your Laptop, Your Servers.

We find 0-days in software used by billions, and fix them to make the world a safer place.

CriticalRX buffer overflow on zero-length serial framesLinux kernel · mctp
CVE-2026-68124 · CNA 9.6 Critical
CriticalArbitrary code execution via crafted expressionsjsonata
CVE-2026-77413 · GHSA-8gq3-vp5j-2grp
CriticalCross-tenant agent API-token minting@paperclipai/server
GHSA-47wq-cj9q-wpmp
MediumAnonymous /api/systemstatus leaks exception detailSwiss Federal Chancellery · government code
GHSA-32p4-g4fj-cg95
HighSlab use-after-free in AEAD decrypt completionLinux kernel · TIPC
CVE-2026-63801
HighUse-after-free in MACsec offload RXLinux kernel · mlx5e
CVE-2026-72072
Read our research

Every company I work with faces the same challenge: more security vulnerabilities than teams can realistically address.

What sets 0sec apart is that it helps reduce that list rather than add to it. By prioritizing vulnerabilities based on actual business impact and providing validated, actionable remediation, 0sec enables security teams to focus their resources where they matter most.

That is what makes 0sec a compelling AI-powered security solution for enterprise environments.

Partner & Europe West Cybersecurity Competency Leader, Switzerland, EY

Traditional security tests don’t protect you from today’s cyberattacks.

Pentesting was designed for a slower, human-led attacker.
The times are changing, and fixing things by hand is no longer fast enough.

Legacy approach

Severity-ranked findings.

0sec

Prioritize fixes by business impact.

Legacy approach

Annual pentests.

0sec

Test with every change.

Legacy approach

Known patterns only.

70%of today’s exploits are 0-days, previously unknown

0sec

Find the known and unknown.

Legacy approach

Web apps only.

44%of 0-days hit the operating system, not the web app

0sec

Test your entire stack.

Legacy approach

A PDF to work through.

0sec

Ship patches your agents can apply.

Cursor, Claude Code, Codex, Gemini CLI, GitHub Copilot, OpenCode

Legacy approach

Another dashboard.

0sec

Findings in your existing tools.

GitHub, GitLab

Legacy approach

Vendor claims.

0sec

Run an open-source engine.

GitHub

Legacy approach

Fixed harness and rules.

0sec

Self-improvement loop.

Research Preview. Evaluate CLI changes and select versions for later runs.

Questions answered.

What can I use 0sec for?

We investigate codebases, open-source packages, web applications and AI systems for security flaws.

Can I try it myself?

Yes. The open-source 0sec CLI runs on your machine and works with your coding agent. You bring your own AI model or API key. It's a research preview, so expect rough edges.

Can it find bugs nobody has reported?

Yes. Our public research includes previously unknown vulnerabilities in Linux and other open-source projects. A new vulnerability isn't guaranteed on every run.

How do you know a finding is real?

A separate agent tries to reproduce the issue from the reproduction steps alone. If it can't, we don't treat the finding as verified. For managed work, people review the findings before delivery.

Do you help fix what you find?

Yes. We develop patches and provide reproduction steps so engineers can review the fix. Our public research links to fixes accepted by the projects' maintainers.

Can you run it for our team?

With 0cloud, we run the engine for you and review the findings before delivery. We agree which systems to test and how the test will run before starting.

We love open source.

We've open sourced 2 of our research tools so you can try them for free.

Become a design partner.

Work directly with our team. Put 0sec to work in your environment and help shape what we build next.