ZeroThreat

Application SecurityDeveloper Tools also known as ZeroThreat.ai, ZeroThreat, Inc.

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software.
Founded 2023
Last updated 2026-08-18

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

ZeroThreat sells a cloud service that scans web applications and APIs and tries to exploit what it finds. An outside review places the fit with small and mid-sized teams buying below enterprise prices. It costs nothing for one scan a month and $100 a month for one application. Its own engine picks the payloads, and the company says large language models such as GPT-4 Turbo and Gemini Ultra drive the platform at its core. The site claims 99.9 percent accuracy while that review records the company marketing 98.9 percent. Its pricing page counts 130,000 vulnerabilities of coverage where that review counts over 40,000. It fits a small team that wants a scanner in its pipeline at that price, and not a buyer who needs numbers a third party has checked.

Sourced Details

Description ZeroThreat sells a cloud service that scans web applications and APIs for vulnerabilities and then tries to exploit what it finds, with no agent to install and nothing to configure before a scan runs. [f1]
Founded 2023 [f2]
HQ Carol Stream, Illinois, United States [f2]

Products

Product What it does
ZeroThreat Cloud scanner and automated pentesting service for web applications and APIs, sold on a free tier, a per-target monthly plan, and pay-per-scan credits.

Matrix Coverage

Cyber Defense Matrix

IdentifyProtectDetectRespondRecover
Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware.
Applications Software, interactions, and application flows on the devices.
Networks Connections and traffic flowing among devices and apps, plus communication paths.
Data Content at rest, in transit, or in use across devices, apps, and networks.
Users The people using the devices, apps, networks, and data.

ZeroThreat crawls a customer's web applications and APIs, discovers endpoints it was not told about, and reports which weaknesses it could reach, and is mapped to the Cyber Defense Matrix. [f1]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Emerging 21 /40 Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 ZeroThreat states its problem plainly, selling continuous testing against the cost of periodic manual pentesting, but the pain is the company's own account and no cited source outside it quantifies the gap. [s4, s12]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 ZeroThreat's engine page gives real mechanism, a KNN payload selector over public CVE data feeding an analysis layer the company says runs on large language models such as GPT-4 Turbo and Gemini Ultra, while the one outside technical read in the record declines to verify the accuracy claim and lists agentic pentesting and single-page-application scanning as not yet shipped. [s6, s12, s15, s16]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 The enabler is AI applied to exploit generation and validation, which ZeroThreat's engine and agentic pages describe and which arrived with a product an independent review dates to 2023 and public since late 2024, but the demand signals in the record are the company's own argument and one product review rather than buyer-side evidence. [s12, s15, s16]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 2/5 Dharmesh Acharya's role is verifiable in two places, ZeroThreat's own newsroom and an aggregator profile that records him as founder, so the background is plausible and stops at the title, and the reviewed record adds no prior in-domain build, exit or publication for him or anyone else. [s6, s11, s14]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 3/5 Two customers are named in the vendor's own stories, Code House and OnPrintShop, and the 5,000-organization headline reads as organizations signed up on the homepage and as organizations that trust the platform in the newsroom, with no third party in the record reporting customer scale or revenue. [s1, s5, s6, s17]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 2/5 The one aggregator covering ZeroThreat's funding contradicts itself, stating both that the company has raised nothing and that it is funded through a single round whose amount sits behind a paywall, and no other source in the reviewed record reports a raise either way. [s14]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 Dynamic application security testing is a recognized category and an independent review files ZeroThreat there against named alternatives, but the company layers continuous pentesting and agentic AI language over it and no analyst coverage confirms the placement. [s1, s12]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 2/5 The independent review positions ZeroThreat as the cheaper option against enterprise scanners and names a free open-source scanner as the baseline against which any paid tool should be evaluated, so the capability is already sold by established vendors and given away by one open-source project. [s12]
Business Risks The accuracy figure ZeroThreat leads with is its own and is inconsistent, at 99.9 percent on the site against the 98.9 percent an outside review records the company marketing, so a buyer who wants an outside read has to run the free tier and measure it…
  • The accuracy figure ZeroThreat leads with is its own and is inconsistent, at 99.9 percent on the site against the 98.9 percent an outside review records the company marketing, so a buyer who wants an outside read has to run the free tier and measure it.
  • One aggregator records four employees at ZeroThreat as of May 2026, and no source in the reviewed record names a second person at the company, so a buyer cannot see who keeps the product running.
  • ZeroThreat describes its platform as driven at its core by large language models such as GPT-4 Turbo and Gemini Ultra, and its payload library as compiled from public vulnerability data, so a buyer weighing what is proprietary here should ask which parts of the detection ZeroThreat builds itself.
  • The one aggregator covering ZeroThreat's funding contradicts itself and no other reviewed source reports a raise, leaving a buyer no way to size how long the company can fund the roadmap it advertises.
  • An outside review lists ZeroThreat as ISO certified and SOC 2 certified and no report or trust page appears on the probed surfaces, while the service takes target URLs, API specifications and authentication credentials, so a security-conscious buyer has to request the reports directly.
  • Both named customer stories are the vendor's own accounts, and one testimonial in the whole record identifies its author's employer, so the reference base a buyer can check is two companies.
Problem & Market ZeroThreat sells against the cost of manual penetration testing…

ZeroThreat sells against the cost of manual penetration testing. Its free-tool pages pitch the product as a way to save thousands on manual pen tests and tooling, and its paid plan prices continuous scanning at $100 a month for one application.

The pain is the company's own account of it. No source outside ZeroThreat in the reviewed record measures the gap it describes. Its CISO page frames the buyer as security leadership, offering a dashboard for monitoring dev and security team progress. An independent review names small and mid-sized teams buying at a fraction of enterprise pricing as the product's fit.

Price sets the segment more plainly than the positioning does. A free plan gives one scan credit a month against one target, the paid plan is $100 a month for one target application with further targets at $75, and scan credits sell at $25 each. [s2, s4, s7, s12]

Product Capabilities The product tests a customer's web applications and APIs, discovers shadow endpoints, and executes real-world attack workflows against them…

The product tests a customer's web applications and APIs, discovers shadow endpoints, and executes real-world attack workflows against them. ZeroThreat's pages describe authenticated testing across SSO and multi-factor login, API coverage spanning REST, GraphQL and SOAP with checks for broken object and function level authorization, and Playwright rendering for modern single-page applications that the independent review lists among features still marked coming soon.

ZeroThreat picks the payloads itself and names the language models behind the analysis. Its engine page states that a KNN algorithm selects payloads from a library compiled out of public CVE databases, vulnerability disclosures and reported attack patterns, and its newsroom describes the platform as driven at its core by large language models such as GPT-4 Turbo and Gemini Ultra. Its payload library is therefore built from public sources, which is one part of the design a buyer can check.

Coverage is counted differently depending on the source. ZeroThreat's pricing page lists 130,000 vulnerabilities of coverage, its award submission counts 100,000 attack paths, and the independent review records more than 40,000 vulnerabilities. That reviewer also listed Playwright single-page-application scanning, agentic pentesting and Nuclei template support as marked coming soon and recorded on-premises deployment as proxy-only, and the agentic pentesting page carries a Coming Soon label. [s1, s2, s6, s12, s13, s15, s16]

Competitive Positioning ZeroThreat is placed in dynamic application security testing by the one independent review in the record, which sets it below the enterprise tools on price…

ZeroThreat is placed in dynamic application security testing by the one independent review in the record, which sets it below the enterprise tools on price. That review names StackHawk as the developer-first alternative for teams that want scanning inside engineering pipelines, and names the free open-source scanner ZAP as the baseline against which any paid tool should be evaluated.

ZeroThreat leads on proof rather than detection. Its homepage argues that detection is easy and proof is hard, and offers reproducible proof of each exploit path as the thing a scanner does not deliver. That contrast is drawn by ZeroThreat against a category rather than against a named rival, and no cited source outside the company tests it.

An aggregator profile lists F5 Networks, A10 Networks and Traceable Security among its closest tracked competitors, which is a different peer set from the one the product review uses. Neither list is corroborated by analyst coverage in the reviewed record. [s1, s12, s14]

Go-to-Market & Traction Two customers are named in the reviewed pages…

Two customers are named in the reviewed pages. Code House, an accounting and payroll software company in Australia, runs a payroll and debtors platform called Workforce One and adopted ZeroThreat for pre-release validation alongside penetration testing already part of its security program. OnPrintShop, a web-to-print software platform, integrated ZeroThreat into its release process to validate its security posture before releases.

The homepage labels the headline figure as organizations signed up. An October 2025 newsroom item restates the same number as organizations that trust the platform and, in the founder's words, as a 5,000-customer mark, without either page stating what any of them pays. No third party in the reviewed record reports a customer count, a revenue figure or a renewal rate.

The rest of the proof is testimonial. The customer stories page carries seven testimonials across six roles, three of them under full names, and names no employer beside any of them, while the Code House story identifies its own speaker as that company's managing director. Entry is self-serve, with a free tier, published list prices and a scan that starts without a credit card. [s1, s2, s5, s6, s8, s17]

Team & Credibility One person is publicly attached to ZeroThreat…

One person is publicly attached to ZeroThreat. Co-founder Dharmesh Acharya is quoted in the company's own October 2025 newsroom item, and an aggregator profile records him as the company's founder.

No other person is identified as working for ZeroThreat. Its About Us page returns 404. No engineering leader, security researcher or advisory board appears in the reviewed sources, and the reviewed sources record no prior build, exit or publication for the founder.

How big ZeroThreat is depends on which entity a reader counts, and the record does not settle it. One aggregator puts ZeroThreat at four employees as of May 2026, the awards program's own entry records a company size of one to nine, and the same aggregator lists the company as associated with Radix Software Services Private Limited, an Indian software firm incorporated in 2010 that it records at 524 employees as of August 2025. That association is the aggregator's alone, nothing in the reviewed sources corroborates it or describes what work passes between the two, and it is the one item in this record that would change the size reading if it turned out to be substantive. [s6, s11, s13, s14]

Trust Readiness ZeroThreat's terms of use name ZeroThreat, Inc…

ZeroThreat's terms of use name ZeroThreat, Inc. at a Wilmington, Delaware address and set Delaware law as governing. Its privacy policy gives the same postal address, and the footer on every page in the record carries a second address in Carol Stream, Illinois.

The certifications in the record come from an outside reviewer rather than a published report. That review lists the product as ISO certified and SOC 2 certified without naming a report, a scope or a date, and no trust page, portal or attestation report appears on the surfaces recorded in the sources. A buyer whose procurement needs the underlying audit has to request it from the company.

The service holds what a scanner needs and a buyer guards. Its privacy policy states that customers supply target URLs, API specifications and authentication credentials for authenticated scans, and that the platform stores scan results and evidence captures. The paid plans offer region-based storage and access control, and the compliance reporting covers GDPR, ISO 27001, PCI DSS and HIPAA. [s1, s2, s3, s9, s11, s12]

Competitors StackHawk, Invicti, ZAP, Traceable Security…
Company Relationship Note
StackHawk competes with An independent review of ZeroThreat names it the developer-first alternative for teams that want scanning inside engineering pipelines.
Invicti competes with The same review positions ZeroThreat below this enterprise platform on price for the same web and API testing job.
ZAP competes with The review calls this free open-source scanner the baseline against which any paid dynamic application security testing tool should be evaluated.
Traceable Security adjacent An aggregator profile lists it among ZeroThreat's closest tracked competitors.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Exposed 12 /21 Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software. pivot urgently

ZeroThreat sells software a customer points at a URL and runs, so leaving means cancelling a plan and wiring a different scanner into the same pipeline. Its attack payloads come from public vulnerability databases, published disclosures and reported attack patterns. The company describes the platform as driven at its core by large language models such as GPT-4 Turbo and Gemini Ultra. No testing corpus of its own appears in the reviewed sources, and the two attestations an outside review lists are backed by no report on the probed surfaces. Its differentiators are reproducible by a funded rival, so what remains is a low price and a scan that starts without setup.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 ZeroThreat sells software the customer points at a URL and runs, priced per target application, with findings and remediation text produced by the product rather than by people who accept accountability for them.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Leaving means cancelling a plan and pointing a different scanner at the same targets, with pipeline and tracker connectors to rebuild, and the reviewed record documents no state that cannot be exported and no dependent system that would need re-architecting.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 An outside review lists the product as ISO certified and SOC 2 certified and no report or trust page appears on the probed surfaces, and both attestations are preparation any funded competitor selling into the enterprise market undertakes rather than a requirement that blocks a replacement.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Crawling single-page applications, replaying multi-factor logins, testing REST, GraphQL and SOAP endpoints and then validating exploitability is years of specialized scanner engineering, even though the reasoning layer on top is licensed from outside model vendors.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 2/3 The evidenced buyers are a payroll software company and a web-to-print platform, testimonials come from engineering and security practitioners rather than procurement, and an independent review names small and mid-sized teams as the product's fit at a price starting at zero.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 ZeroThreat runs beside a customer's applications and pipelines and offers custom API and webhook support, a platform with application features rather than infrastructure other systems depend on to operate.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 ZeroThreat's own engine page traces its payload library to public CVE databases, published disclosures and reported attack patterns, and no non-public corpus of its own appears in the reviewed sources.
Strategic Market Segmentation ZeroThreat addresses teams that ship faster than their testing cycle…

ZeroThreat addresses teams that ship faster than their testing cycle. Its CISO page frames the buyer as security leadership, and its free-tool pages pitch the product as a way to save thousands on manual pen tests and tooling.

Price draws the real segment line. The free plan covers one target and one scan credit a month, the paid plan is $100 a month for a single target application, and additional targets cost $75 each. An independent review reaches the matching conclusion, naming small and mid-sized teams buying at a fraction of enterprise pricing as the product's fit.

The plans include compliance reporting, and the named customers sit outside the regulated core. The Professional plan lists continuous compliance coverage for GDPR, ISO 27001, PCI DSS and HIPAA, and the two customers ZeroThreat names are a payroll software company and a web-to-print platform.

Product Capabilities & AI Advantages The scanning work is the part ZeroThreat built…

The scanning work is the part ZeroThreat built. Its pages describe discovery of endpoints the customer did not supply, authenticated testing across SSO and multi-factor login, API coverage across REST, GraphQL and SOAP with broken object and function level authorization checks, and Playwright rendering for modern single-page applications that the independent review lists among features still marked coming soon.

The payload library is compiled from public sources and the company names the language models behind the analysis. ZeroThreat's engine page states that a KNN algorithm picks payloads from a library compiled out of public CVE databases, vulnerability disclosures and reported attack patterns, and its newsroom describes the platform as driven at its core by large language models such as GPT-4 Turbo and Gemini Ultra. Its agentic page, which carries a Coming Soon label, describes customer-managed models naming GPT, Claude and Grok.

What the AI is claimed to buy is fewer false alarms, and that claim is unaudited. The site records 99.9 percent detection accuracy, the outside review records the company citing 98.9 percent, and that reviewer states the figures come from the company's own testing rather than an independent benchmark.

Sales Engagement & Go-to-Market Entry is self-serve…

Entry is self-serve. A prospect signs up, receives five scan credits valid for 15 days without a card, and reads a published price for every tier.

Publicity does work a sales team would. ZeroThreat runs a newsroom, and its own nominee page in the Cybersecurity Excellence Awards asks readers to cast votes for it by sharing that page, each share counting as one Community Choice vote. The program states that jury winners are chosen by expert judges while Community Choice winners are determined by public voting, so the two recognitions are not the same kind of signal.

Both customer stories are published by ZeroThreat itself. They name Code House and OnPrintShop, and the customer stories index adds seven testimonials across six roles without naming an employer beside any of them, so a buyer checking references has two accounts and no independent one.

Pricing Model ZeroThreat publishes every price, which is unusual in this category and useful to a buyer sizing a deal alone…

ZeroThreat publishes every price, which is unusual in this category and useful to a buyer sizing a deal alone. The Free plan costs nothing and gives one scan credit a month against one target with a limited preview of findings. Professional is $100 a month for one target application, with additional targets at $75 each. Pay Per Scan sells credits at $25 each.

The free tier is the entry rung of the same ladder rather than a separate product. The pricing page states that the free plan uses the same detection engine as the paid plans and shows a limited insights preview, and the free scanner and free pentesting pages route a visitor into the same signup.

The unit is the target application, which suits a team with a handful of applications and works against one with many. A buyer with twenty applications pays for twenty targets, so the per-target plan fits a team scanning a few applications constantly while the credit pool fits a team scanning many applications occasionally.

Product Delivery & Operations An unauthenticated scan asks nothing of the customer's infrastructure…

An unauthenticated scan asks nothing of the customer's infrastructure. That is the whole content of the zero-setup claim ZeroThreat leads with. Scanning behind a login adds a step, and the review describes a Chrome extension that records the login flow for the scanner to replay.

Pipeline wiring is where the product embeds. ZeroThreat's integrations page lists connectors for the build systems and issue trackers a development team already runs. Wired that way, a periodic scan becomes a step in a release.

Deployment options stop short of self-hosting. Internal applications are reached through an on-premises proxy rather than a full self-hosted install, and the paid plans offer region-based storage and access control for customers with data residency obligations.

Earning Customers' Trust The legal identity is documented and the assurance is not…

The legal identity is documented and the assurance is not. ZeroThreat's terms of use name ZeroThreat, Inc. at a Wilmington, Delaware address under Delaware law, and its privacy policy repeats that address while the footer on every page in the record also carries a Carol Stream, Illinois address.

The certifications in the record come from an outside reviewer rather than a published report. That review lists the product as ISO certified and SOC 2 certified without naming a report, a scope or a date, and no trust page, portal or attestation report appears on the surfaces recorded in the sources.

The data at stake raises the bar. ZeroThreat's privacy policy states that it processes target URLs, API specifications and authentication credentials supplied for authenticated scans, along with scan results and evidence captures. A customer running authenticated scans hands its own application credentials to a company the record sizes at four employees in one source and at one to nine in another.

Platform Strategy & Ecosystem Positioning Nothing in the reviewed record is built on ZeroThreat by anyone else…

Nothing in the reviewed record is built on ZeroThreat by anyone else. It consumes the ecosystem through connectors into pipelines and trackers and offers custom API and webhook support, and the record shows no marketplace and no partner program, so every capability a buyer gets here comes off ZeroThreat's own roadmap.

The open-source ecosystem shows up as input, and the sources disagree about whether it has arrived. ZeroThreat's pricing page lists Nuclei inside the coverage a paid plan buys, while the independent review lists Nuclei template support as still coming soon.

The model layer is the one place the product plans to open outward. Its agentic page describes customer-managed models, which would make the reasoning layer something the customer supplies rather than something ZeroThreat owns.

Team & Execution Capability One name carries the company in public…

One name carries the company in public. Dharmesh Acharya appears as co-founder in ZeroThreat's own October 2025 newsroom item and as the founder on an aggregator profile, and no other person is identified as working for the company anywhere in the reviewed sources.

The site does not introduce anyone. Its About Us page returns 404, so a buyer evaluating who builds the scanner has the founder's name and little else. Neither a prior build nor an exit nor a publication record for him appears in the record.

The headcount figure needs its second entity to read correctly. An aggregator records ZeroThreat at four employees as of May 2026, the awards program's entry records a company size of one to nine, and the same aggregator lists the company as associated with Radix Software Services Private Limited, an Indian firm incorporated in 2010 that it records at 524 employees. That association is the aggregator's alone, nothing else in the record corroborates it, and it would change the size reading if it turned out to be substantive.

Sources

Company Detail Sources (2)
Id Source Tier Accessed
f1 ZeroThreat: homepage official 2026-08-18
f2 AppSec Santa: ZeroThreat review research 2026-08-18
Profile Analysis Sources (18)
Id Source Tier Accessed
s1 ZeroThreat: homepage
“ZeroThreat is an automated pentesting tool for web apps and APIs. With zero setup, it detects 130K+ vulnerabilities and ensures near-zero false positives.”
official 2026-08-18
s2 ZeroThreat: pricing page
“Run real scans with a limited preview of detected vulnerabilities across your applications & APIs.”
official 2026-08-18
s3 ZeroThreat: terms of use
“Legal Department ZeroThreat, Inc. 108 W. 13th Street, Suite 100 Wilmington, DE 19801-1145, USA”
official 2026-08-18
s4 ZeroThreat: free vulnerability scanner page
“Proactively secure your web apps and APIs for FREE with ZeroThreat’s online vulnerability scanner. Instantly detect OWASP Top 10 and CWE Top 25 in your web app. No cost, no setup, just actionable insights.”
official 2026-08-18
s5 ZeroThreat: Code House customer story
“How Code House Strengthened Platform Security with ZeroThreat’s Automated Web & API Pentesting”
official 2026-08-18
s6 ZeroThreat: newsroom item on 5,000 organizations
“Published Date: Oct 13, 2025”
official 2026-08-18
s7 ZeroThreat: CISO solutions page
“Gain a comprehensive overview of your security posture through our CISO-friendly dashboard. Monitor your dev and security team’s progress and enhance their self-reliance in addressing security issues.”
official 2026-08-18
s8 ZeroThreat: customer stories index
“Real-world examples of how enterprises rely on ZeroThreat to reduce exploitable risks”
official 2026-08-18
s9 ZeroThreat: privacy policy
“ZeroThreat Inc 108 W. 13th Street, Suite 100, Wilmington, DE 19801-1145, USA”
official 2026-08-18
s10 ZeroThreat: free pentesting tool page
“Identify exploitable weaknesses in your web apps and APIs with ZeroThreat’s free automated pentesting tool.”
official 2026-08-18
s11 Trust and leadership probe 2026-08-18: /trust, /security, /compliance and /about-us return 404, and trust. and security. do not resolve, nor does a control other 2026-08-18
s18 ZeroThreat: integrations page
“From GitHub Actions to Jira, ZeroThreat plugs into your favorite CI/CD and project management tools to automate discovery, testing, and remediation.”
official 2026-08-18
s12 AppSec Santa: ZeroThreat review
“ZeroThreat markets 98.9% detection accuracy with near-zero false positives — vendor figures from its own testing, not an independent benchmark, and its own materials elsewhere cite 99.9%.”
research 2026-08-18
s13 Cybersecurity Excellence Awards: ZeroThreat 2026 nominee page
“By simulating 100,000+ real-world attack paths, delivering rapid assessments aligned with OWASP and CWE, and combining pentest-level depth with automation speed, ZeroThreat helps security teams shift from reactive testing to continuous, proactive risk reduction.”
other 2026-08-18
s15 ZeroThreat: AI engine page
“The ZeroThreat AI Engine is an autonomous security intelligence layer between your application and our DAST engine.”
official 2026-08-18
s16 ZeroThreat: agentic AI pentesting page
“Validate real exploit paths with controlled, AI-driven reasoning.”
official 2026-08-18
s14 Tracxn: ZeroThreat company profile
“ZeroThreat is an unfunded company based in Wilmington (United States), founded in 2024 by Dharmesh Acharya .”
other 2026-08-18
s17 ZeroThreat: OnPrintShop customer story
“How OnPrintShop Strengthened Product Security with ZeroThreat’s Automated DAST”
official 2026-08-18
Deep-Dive Sources (18)
Id Source Tier Accessed
s1 ZeroThreat: homepage
“ZeroThreat is an automated pentesting tool for web apps and APIs. With zero setup, it detects 130K+ vulnerabilities and ensures near-zero false positives.”
official 2026-08-18
s2 ZeroThreat: pricing page
“Run real scans with a limited preview of detected vulnerabilities across your applications & APIs.”
official 2026-08-18
s3 ZeroThreat: terms of use
“Legal Department ZeroThreat, Inc. 108 W. 13th Street, Suite 100 Wilmington, DE 19801-1145, USA”
official 2026-08-18
s4 ZeroThreat: free vulnerability scanner page
“Proactively secure your web apps and APIs for FREE with ZeroThreat’s online vulnerability scanner. Instantly detect OWASP Top 10 and CWE Top 25 in your web app. No cost, no setup, just actionable insights.”
official 2026-08-18
s5 ZeroThreat: Code House customer story
“How Code House Strengthened Platform Security with ZeroThreat’s Automated Web & API Pentesting”
official 2026-08-18
s6 ZeroThreat: newsroom item on 5,000 organizations
“Published Date: Oct 13, 2025”
official 2026-08-18
s7 ZeroThreat: CISO solutions page
“Gain a comprehensive overview of your security posture through our CISO-friendly dashboard. Monitor your dev and security team’s progress and enhance their self-reliance in addressing security issues.”
official 2026-08-18
s8 ZeroThreat: customer stories index
“Real-world examples of how enterprises rely on ZeroThreat to reduce exploitable risks”
official 2026-08-18
s9 ZeroThreat: privacy policy
“ZeroThreat Inc 108 W. 13th Street, Suite 100, Wilmington, DE 19801-1145, USA”
official 2026-08-18
s10 ZeroThreat: free pentesting tool page
“Identify exploitable weaknesses in your web apps and APIs with ZeroThreat’s free automated pentesting tool.”
official 2026-08-18
s11 Trust and leadership probe 2026-08-18: /trust, /security, /compliance and /about-us return 404, and trust. and security. do not resolve, nor does a control other 2026-08-18
s18 ZeroThreat: integrations page
“From GitHub Actions to Jira, ZeroThreat plugs into your favorite CI/CD and project management tools to automate discovery, testing, and remediation.”
official 2026-08-18
s12 AppSec Santa: ZeroThreat review
“ZeroThreat markets 98.9% detection accuracy with near-zero false positives — vendor figures from its own testing, not an independent benchmark, and its own materials elsewhere cite 99.9%.”
research 2026-08-18
s13 Cybersecurity Excellence Awards: ZeroThreat 2026 nominee page
“By simulating 100,000+ real-world attack paths, delivering rapid assessments aligned with OWASP and CWE, and combining pentest-level depth with automation speed, ZeroThreat helps security teams shift from reactive testing to continuous, proactive risk reduction.”
other 2026-08-18
s15 ZeroThreat: AI engine page
“The ZeroThreat AI Engine is an autonomous security intelligence layer between your application and our DAST engine.”
official 2026-08-18
s16 ZeroThreat: agentic AI pentesting page
“Validate real exploit paths with controlled, AI-driven reasoning.”
official 2026-08-18
s14 Tracxn: ZeroThreat company profile
“ZeroThreat is an unfunded company based in Wilmington (United States), founded in 2024 by Dharmesh Acharya .”
other 2026-08-18
s17 ZeroThreat: OnPrintShop customer story
“How OnPrintShop Strengthened Product Security with ZeroThreat’s Automated DAST”
official 2026-08-18

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.