Skip to content

The open-source AI security agent.

Zero finds & fixes vulnerabilities in your code, dependencies and infrastructure.

curl -fsSL https://raw.githubusercontent.com/0sec-labs/0/main/install.sh | bash

Today, fixing things by human hand is no longer fast nor good enough.

Welcome to the post-pentest era.

By prioritizing vulnerabilities based on actual business impact and providing validated, actionable remediation, 0.security enables security teams to focus their resources where they matter most. A compelling AI-powered security solution for enterprise environments.

Roman Haltinner

Partner & Europe West Cybersecurity Competency Leader, Switzerland, at EY

Engineers at these companies deployed our fixes into their software.

3+ billion

devices run software
we have secured.

20+
merged 0-days in the Linux kernel
200+ CVEs
confidential disclosure
30+
software systems

Zero found & fixed 20+
previously unknown
vulnerabilities in Linux and
in government code.

The Linux kernel powers 3+ billion devices, including Android phones and the servers running websites, apps & cloud services.

Zero sitting low and striking a phone between his feet
Your phone.
Zero standing and smashing a laptop on his familiar gray desk
Your laptop.
Zero bracing a foot against a server while pulling his axe free
Your servers.

Looks cute.
Breaks serious software.

Zero blinking while holding an axe behind his back
CriticalRX buffer overflow on zero-length serial framesLinux kernel · mctp
CriticalArbitrary code execution via crafted expressionsjsonata
CriticalCross-tenant agent API-token minting@paperclipai/server
MediumAnonymous /api/systemstatus leaks exception detailSwiss Federal Chancellery · government code
HighSlab use-after-free in AEAD decrypt completionLinux kernel · TIPC
HighUse-after-free in MACsec offload RXLinux kernel · mlx5e

Give agents the tools to find and fix vulnerabilities.

Continuous

Self-improving

Multi-model

Open source

Extensible

The best security dashboard is one you don’t have to use.

Let your agents handle it.

Zero.
Zero hovering peacefully in meditation

Peace of mind.

Powerful enough to secure governments, find flaws in operating systems and fix software billionsPublic service, literally. rely on.

Continuous scanning & testing for your code, dependencies and infrastructure.

  • Pentesting of your full stack (white-box, grey-box and black-box)
  • Auto-fixes (verified)
  • PR reviews
  • Code Scanning
Enterprise features
  • No dashboard
    to watch.
  • No scans or tests
    to start manually.
  • No false alarms. Only verified findings and fixes.
  • Compliance reports.SOC 2 & ISO 27001

Security handled, 24/7.So you can focus on building.

How it works

  1. He analyzes your repo,
    systems and infrastructure
  2. He makes a testing plan

    Zero runs this schedule automatically.

    Security reviews
    Code reviews
    Every PR / push
    Full-codebase scans
    Every release
    Secrets checks
    Every push
    Monitoring
    Threat & CVE alerts
    Pentests
    Website & APIs
    Custom
    Dependencies
    Custom
    Cloud & infrastructure
    Custom
    Apps
    Custom
    AI & LLMs
    Custom
    Operating system
    Custom
  3. He finds problems
  4. He fixes them
  5. He tells youor your agent.
  6. He gets better
CI/CD integration: From code change to auto-fix

Triggers

  • Every mergeon push to any branch
  • Every releaseon a tag
  • On a schedulenightly or weekly
  • On demandone API call

Security tests

Depth by rule

  • feature branchStandard
  • mainDeep
  • release tagComplex

Security reviews

Always-on

  • PR reviewsCode changes & releases
  • Codebase scansYour full codebase
  • SecretsForgotten API keys
  • MonitoringThreat & CVE alerts
Talk to us

He analyzes your repo, systems and infrastructure.

Your codebase sets the starting point.

Your stack

Languages & frameworks

Your conventions

Code style & project guidance

Your tests

How your team checks changes

Recent changes

Where your team is building

Your project context

Ready for a testing plan
that fits your code.

Always-on

Find & fix vulnerabilities 24/7.

Security Reviews

Checks your code changes

  • PR reviews

    Checks your code changes & releases

  • Scans

    Checks your Full Code base

  • Secrets

    Removes forgotten API keys

  • Monitoring

    Attack surface, Threat & CVE alerts

Auto-scheduled

Tailor-made to your stack, coding style & speed.

Pentests

Tests real-world attack paths

  • Source Code
  • Website
  • APIs
  • Dependencies
  • Apps
  • Cloud & Infrastructure
  • Operating System
  • AI & LLMs
  • White-boxtesting
  • Black-boxtesting
  • Gray-boxtesting

Zero coordinates the agents behind his investigation.

0agents active
0findings

Our security agents think in exploit chains to1 find, 2 verify and 3 auto-fixthe most complex vulnerabilities.

Delivered where you already work.

f-0416 · evidence packrequest · response · proof
Accepted by your operator

Comprehensive report

Findings, fixes and PoC · full technical detail

Pull request

The fix, opened against your repo

Webhook

Fired into your SIEM or SOAR

Findings API

Behind the dashboard your team already uses

Board report

Optional

AML.T0051 · LLM Prompt Injection · f-0416

A CV upload could talk the assistant into opening another customer's account. We proved it twice, and wrote the fix.

Every investigation
builds on the last.

Context about your code, architecture and past findings carries into the next investigation. As your software changes, that context helps guide what to test next.

Your environment informs every investigationCode, architecture and past findings feed a shared context. That context guides the next investigation, whose findings carry forward into future work.Your codeArchitecturePast findingsYour project contextUpdated as your software changes.Next investigationNew findings inform the next run.

Traditional security tests don’t protect you from today’s cyberattacks.

Test annuallyTest with every change

Traditional approach

With 0.security

Misleading prioritizationPrioritize fixes by business impact

Traditional approach

With 0.security

Only map known vulnerabilitiesFind known vulnerabilities and 0-days

Traditional approach

70% of today’s exploits are 0-days, previously unknown

With 0.security

Test your web app onlyTest your entire stack

Traditional approach

44% of 0-days hit the operating system, not the web app

With 0.security

Work through a PDFShip patches your agents can apply

Traditional approach

With 0.security

Cursor, Claude Code, Codex, Gemini CLI, GitHub Copilot, OpenCode
Manage another dashboardFindings and patches in your existing tools

Traditional approach

With 0.security

GitHub, GitLab, Slack
Trust vendor claimsRun an open-source engine

Traditional approach

With 0.security

GitHub
Use fixed tools and rulesSelf-improvement loop

Traditional approach

With 0.security

Don’t believe me?

Frequently asked questions.

About the managed service, the research, and the little ninja.

You have a little ninja. Do you take security seriously?

Very. We find previously unknown vulnerabilities in software billions of people depend on, including the Linux kernel that powers Android phones and servers around the world. We collaborate with leading AI labs and defence organizations. You can read our public disclosures and inspect the fixes.

That’s Zero, by the way. Who said security had to look boring?Bored Zero sitting with his head resting on one hand

What is 0.security?

We’re an applied AI and cybersecurity research lab. Our managed security service brings that research to your code, dependencies and infrastructure. We handle the testing, verify findings and prepare fixes while your team keeps building.

Why is this needed now?

Attackers are quick to adopt new technology. AI is no exception: it helps them investigate more targets, discover vulnerabilities and develop exploits faster. Security needs to keep pace with both the attackers and the software your team is shipping.

We put agents to work continuously, investigating attack paths and preparing fixes as your software changes. Recent incidents involving agents taking unauthorized actions also show why that power needs carefully designed infrastructure around it.

Which parts of my software can you check?

Your source code, dependencies, websites, APIs, apps, cloud infrastructure, operating systems and AI systems. We investigate how these parts connect, because an attack can start in one place and reach something much more valuable elsewhere.

Your web app is only part of the picture. Operating systems accounted for 44% of exploited zero-days (2025), making them the largest category. Your security needs to reach the software underneath your application, too.

Do you do pentesting, too?

Yes. Our managed service includes white-box, grey-box and black-box pentesting across your full stack. We agree the targets, access and testing depth with you, then handle the investigations, verified findings and fixes.

We already have more findings than we can fix. Why would we want more?

We know your engineers already have plenty on their plate. We prioritise findings by business impact and prepare verified fixes as pull requests, ready for your team to review and merge.

That saves your developers time investigating issues and writing fixes, so they can spend more of it building.

Another dashboard to check. More work to manage?

We handle testing in the background and bring verified findings and fix PRs into the tools you already use. You don’t need to watch a dashboard or start scans manually.

We agree the scope, schedule and approvals with you. Your team stays in control of access and which changes are merged.

What makes this AI-native?

Agents do the security work: planning investigations, exploring attack paths, writing tools when they need them and preparing fixes. We select models for different tasks, and agents combine their findings.

The entire workflow is built around delegating that work, from investigation to repair. You shouldn’t have to supervise every step to get a useful result.

What does your research have to do with my code?

You get the research, models and security testing tools behind our discoveries in software billions of devices and governments rely on. Real attack paths and verified findings guide new investigations. Our public disclosures and upstream fixes let you inspect the work behind the service.

Can I integrate this into CI/CD and my existing workflow?

Yes. We connect the managed service to your repositories, CI/CD pipeline and delivery workflow. PR reviews, releases, pushes and custom schedules can trigger the agreed work. Verified findings and fix PRs arrive where your engineers and coding agents already work.

How do you keep powerful agents from becoming another security risk?

Tests run in fresh, disposable virtual-machine sandboxes, isolated at the virtualization layer. Runs have time limits, and the sandboxes are torn down afterwards.

We agree testing scope, access and approval controls before work starts. Your team keeps control over what gets tested and which changes are applied.

Can our enterprise team stay in control without supervising every agent?

Yes. You set the scope, budget and where approvals are required. Agents carry out the work without needing someone to direct every step.

Your team can review the evidence and fix PRs, require approval before changes are merged, and track what was tested and changed. We work with you on deployment requirements and how the service fits your existing processes.

If the engine is open source, what am I paying for?

The open-source harness is free to inspect, run and extend with your own models and tools. We’re setting a new standard for transparency in the security industry: you can inspect the engine behind the service and the public research behind our findings.

The managed service turns that foundation into continuous security testing tailored to your business. We handle setup, infrastructure, frontier cyber models and ongoing testing. We verify findings and fixes in isolated sandboxes and deliver the results through your workflow. Your team gets the benefit of our research without having to build and operate the system themselves.

Can you support our compliance reporting?

Yes. We provide testing evidence and reports for your SOC 2 and ISO 27001 work, alongside board reporting. We agree the reporting requirements with you when scoping the service.

Tell us what your team needs.

We’re building the next generation of security products around real needs. Tell us what’s difficult today, what takes too much time, and what you wish worked better.

Talk to us