
The open-source AI security agent.
Zero finds & fixes vulnerabilities in your code, dependencies and infrastructure.
curl -fsSL https://raw.githubusercontent.com/0sec-labs/0/main/install.sh | bashToday, fixing things by human hand is no longer fast nor good enough.
Welcome to the post-pentest era.
By prioritizing vulnerabilities based on actual business impact and providing validated, actionable remediation, 0.security enables security teams to focus their resources where they matter most. A compelling AI-powered security solution for enterprise environments.
Partner & Europe West Cybersecurity Competency Leader, Switzerland, at EY
Engineers at these companies deployed our fixes into their software.
3+ billion
devices run software
we have secured.
- 20+
- merged 0-days in the Linux kernel
- 200+ CVEs
- confidential disclosure
- 30+
- software systems
Zero found & fixed 20+
previously unknown
vulnerabilities in Linux and
in government code.
The Linux kernel powers 3+ billion devices, including Android phones and the servers running websites, apps & cloud services.



Looks cute.
Breaks serious software.

Give agents the tools to find and fix vulnerabilities.
Self-improving
Multi-model
Open source
Extensible
The best security dashboard is one you don’t have to use.
Let your agents handle it.

Peace of mind.
Powerful enough to secure governments, find flaws in operating systems and fix software billionsPublic service, literally. rely on.
Continuous scanning & testing for your code, dependencies and infrastructure.
- Pentesting of your full stack (white-box, grey-box and black-box)
- Auto-fixes (verified)
- PR reviews
- Code Scanning
- No dashboard
to watch. - No scans or tests
to start manually. - No false alarms. Only verified findings and fixes.
- Compliance reports.SOC 2 & ISO 27001
Security handled, 24/7.So you can focus on building.
How it works
- He analyzes your repo,
systems and infrastructure - He makes a testing plan
Zero runs this schedule automatically.
Illustrative testing schedule
Security reviews
- Code reviews
- Every PR / push
- Full-codebase scans
- Every release
- Secrets checks
- Every push
- Monitoring
- Threat & CVE alerts
Pentests
- Website & APIs
- Custom
- Dependencies
- Custom
- Cloud & infrastructure
- Custom
- Apps
- Custom
- AI & LLMs
- Custom
- Operating system
- Custom
- He finds problems
- He fixes them
- He tells youor your agent.
- He gets better
Triggers
- Every mergeon push to any branch
- Every releaseon a tag
- On a schedulenightly or weekly
- On demandone API call
Security tests
Depth by rule
- feature branchStandard
- mainDeep
- release tagComplex
Security reviews
Always-on
- PR reviewsCode changes & releases
- Codebase scansYour full codebase
- SecretsForgotten API keys
- MonitoringThreat & CVE alerts
Traditional security tests don’t protect you from today’s cyberattacks.
Test annuallyTest with every change
Traditional approach
With 0.security
Misleading prioritizationPrioritize fixes by business impact
Traditional approach
With 0.security
Only map known vulnerabilitiesFind known vulnerabilities and 0-days
Traditional approach
70% of today’s exploits are 0-days, previously unknown
Test your web app onlyTest your entire stack
Traditional approach
44% of 0-days hit the operating system, not the web app
Work through a PDFShip patches your agents can apply
Traditional approach
With 0.security
Manage another dashboardFindings and patches in your existing tools
Traditional approach
With 0.security
Trust vendor claimsRun an open-source engine
Traditional approach
With 0.security
Use fixed tools and rulesSelf-improvement loop
Traditional approach
With 0.security
Frequently asked questions.
About the managed service, the research, and the little ninja.
You have a little ninja. Do you take security seriously?
Very. We find previously unknown vulnerabilities in software billions of people depend on, including the Linux kernel that powers Android phones and servers around the world. We collaborate with leading AI labs and defence organizations. You can read our public disclosures and inspect the fixes.
That’s Zero, by the way. Who said security had to look boring?
What is 0.security?
We’re an applied AI and cybersecurity research lab. Our managed security service brings that research to your code, dependencies and infrastructure. We handle the testing, verify findings and prepare fixes while your team keeps building.
Why is this needed now?
Attackers are quick to adopt new technology. AI is no exception: it helps them investigate more targets, discover vulnerabilities and develop exploits faster. Security needs to keep pace with both the attackers and the software your team is shipping.
We put agents to work continuously, investigating attack paths and preparing fixes as your software changes. Recent incidents involving agents taking unauthorized actions also show why that power needs carefully designed infrastructure around it.
Which parts of my software can you check?
Your source code, dependencies, websites, APIs, apps, cloud infrastructure, operating systems and AI systems. We investigate how these parts connect, because an attack can start in one place and reach something much more valuable elsewhere.
Your web app is only part of the picture. Operating systems accounted for 44% of exploited zero-days (2025), making them the largest category. Your security needs to reach the software underneath your application, too.
Do you do pentesting, too?
Yes. Our managed service includes white-box, grey-box and black-box pentesting across your full stack. We agree the targets, access and testing depth with you, then handle the investigations, verified findings and fixes.
We already have more findings than we can fix. Why would we want more?
We know your engineers already have plenty on their plate. We prioritise findings by business impact and prepare verified fixes as pull requests, ready for your team to review and merge.
That saves your developers time investigating issues and writing fixes, so they can spend more of it building.
Another dashboard to check. More work to manage?
We handle testing in the background and bring verified findings and fix PRs into the tools you already use. You don’t need to watch a dashboard or start scans manually.
We agree the scope, schedule and approvals with you. Your team stays in control of access and which changes are merged.
What makes this AI-native?
Agents do the security work: planning investigations, exploring attack paths, writing tools when they need them and preparing fixes. We select models for different tasks, and agents combine their findings.
The entire workflow is built around delegating that work, from investigation to repair. You shouldn’t have to supervise every step to get a useful result.
What does your research have to do with my code?
You get the research, models and security testing tools behind our discoveries in software billions of devices and governments rely on. Real attack paths and verified findings guide new investigations. Our public disclosures and upstream fixes let you inspect the work behind the service.
Can I integrate this into CI/CD and my existing workflow?
Yes. We connect the managed service to your repositories, CI/CD pipeline and delivery workflow. PR reviews, releases, pushes and custom schedules can trigger the agreed work. Verified findings and fix PRs arrive where your engineers and coding agents already work.
How do you keep powerful agents from becoming another security risk?
Tests run in fresh, disposable virtual-machine sandboxes, isolated at the virtualization layer. Runs have time limits, and the sandboxes are torn down afterwards.
We agree testing scope, access and approval controls before work starts. Your team keeps control over what gets tested and which changes are applied.
Can our enterprise team stay in control without supervising every agent?
Yes. You set the scope, budget and where approvals are required. Agents carry out the work without needing someone to direct every step.
Your team can review the evidence and fix PRs, require approval before changes are merged, and track what was tested and changed. We work with you on deployment requirements and how the service fits your existing processes.
If the engine is open source, what am I paying for?
The open-source harness is free to inspect, run and extend with your own models and tools. We’re setting a new standard for transparency in the security industry: you can inspect the engine behind the service and the public research behind our findings.
The managed service turns that foundation into continuous security testing tailored to your business. We handle setup, infrastructure, frontier cyber models and ongoing testing. We verify findings and fixes in isolated sandboxes and deliver the results through your workflow. Your team gets the benefit of our research without having to build and operate the system themselves.
Can you support our compliance reporting?
Yes. We provide testing evidence and reports for your SOC 2 and ISO 27001 work, alongside board reporting. We agree the reporting requirements with you when scoping the service.
Roman Haltinner
Ilya Lyamkin
Marijus Gudiškis
Roman Peneder
