Autonomous penetration testing has quietly become one of the more closely watched corners of enterprise cybersecurity, and San Francisco-based Horizon3.ai sits near the center of that shift. Since its founding in 2019, the company has built its NodeZero platform around a simple but consequential idea: instead of hiring humans to simulate an attack once or twice a year, let software do it continuously, safely, and without installing agents on production systems. That idea has translated into a steady string of funding rounds, an expanding roster of enterprise and government customers, and a product roadmap that keeps pace with a threat landscape increasingly shaped by AI-driven attacks.
This piece takes an accurate look at where Horizon3.ai actually stands today — its real funding history, its product, its recent expansion moves, and why the rise of AI-powered offensive tooling is pushing more security teams toward autonomous defense platforms like NodeZero.
Horizon3.ai at a Glance
Before getting into the funding details, it helps to understand what Horizon3.ai actually does and who is behind it. The company was co-founded by Snehal Antani, a former CTO of the U.S. Joint Special Operations Command's intelligence directorate and a former Splunk executive, alongside Anthony Pillitiere, who previously served as deputy CTO for U.S. Special Operations Command. That background shows up directly in the product: NodeZero was built to think like an attacker, not just scan for known vulnerabilities.
| Attribute | Detail |
|---|---|
| Founded | 2019 |
| Founders | Snehal Antani (CEO), Anthony Pillitiere |
| Headquarters | San Francisco, California, with a newly opened EMEA hub in Amsterdam |
| Flagship Product | NodeZero — autonomous, agentless penetration testing platform |
| Employees | Roughly 400–480, according to third-party data providers tracking 2026 headcount |
| Total Funding Raised | Approximately $180–210 million across five-plus rounds |
It's worth flagging upfront that Horizon3.ai is privately held and has not publicly disclosed an official post-money valuation for every round. The figures cited throughout this article come from a combination of company announcements and independent data providers such as PitchBook, Crunchbase, and Tracxn, which sometimes estimate valuation using revenue multiples rather than reporting a disclosed number. Where a figure is an estimate rather than a company-confirmed number, we've noted that distinction.
The Funding Journey: From Seed to Series D
Horizon3.ai has taken a fairly conventional path through the venture funding stages, but the pace and size of its rounds have accelerated noticeably as its customer base has grown. Rather than a single blockbuster raise, the company's growth story is really one of consistent, compounding rounds over roughly six years.
| Round | Approximate Timing | Notable Investors |
|---|---|---|
| Seed | Early 2020 | Ridge Ventures and early angel backers |
| Series A | Early 2021 | SignalFire and existing seed investors |
| Series B | Late 2021 (~$30M) | Led by SignalFire |
| Series C | 2023 (~$40M) | Led by Craft Ventures |
| Series D | 2025 (~$100M) | Led by New Enterprise Associates (NEA), with participation from NewView Capital, NightDragon, and Prosperity7 Ventures |
Taken together, these rounds put Horizon3.ai's cumulative funding somewhere in the $180–210 million range, depending on which data provider's tally you use. That's a meaningful war chest for a company in the autonomous security space, though it's well short of unicorn territory — independent estimates place the company's valuation somewhere between roughly $115 million and $190 million depending on methodology and timing, not the multi-billion-dollar figures sometimes associated with the very largest cybersecurity unicorns.
Key takeaway: Horizon3.ai's growth has been funded through disciplined, staged rounds rather than a single mega-raise — a pattern common among cybersecurity companies whose product needs deep engineering investment before enterprise sales fully scale.
What Powers NodeZero
NodeZero is built around the idea of continuous, production-safe autonomous pentesting. Traditional penetration tests are typically point-in-time engagements: a security firm is hired, a team runs an assessment over a few days or weeks, and a report is delivered weeks later. By the time findings are remediated, the environment has often already changed. NodeZero instead runs as a SaaS platform that continuously probes an organization's internal, external, cloud, and hybrid environments to find exploitable attack paths.
Key Capabilities
- Agentless deployment — NodeZero doesn't require installing persistent software agents, which reduces operational overhead and risk when running assessments in live production environments.
- Attack path prioritization — rather than flooding security teams with a long list of every possible vulnerability, the platform focuses on which weaknesses are actually exploitable and chainable into a real compromise.
- Verification of fixes — after a vulnerability is remediated, NodeZero re-tests to confirm the fix actually closed the exploitable path, rather than just assuming a patch worked.
- Tripwires — deployable honeytoken-style detection points designed to catch malicious activity and exploitable exposures early.
- Kubernetes and cloud testing — extending autonomous assessment into containerized and hybrid-cloud workloads, which have become common blind spots for traditional pentesting vendors.
This combination has resonated particularly with organizations in regulated industries — finance, healthcare, and government — where compliance frameworks increasingly expect more frequent and evidence-backed security testing than an annual manual engagement can realistically provide.
Why AI Cyber Threats Are Reshaping the Security Market
The broader backdrop for Horizon3.ai's growth is a security industry grappling with a fundamental shift: offensive tooling is getting faster and cheaper thanks to AI. Attackers no longer need to manually chain together reconnaissance, exploitation, and lateral movement — large language models and automated tooling can now assist with generating phishing content, discovering misconfigurations, and even scripting exploit chains at a pace that outstrips traditional, manual defensive testing cycles.
This has pushed many CISOs and security leaders to reconsider how often they can afford to test their own defenses. An annual pentest, however thorough, simply can't keep up with an environment where new cloud assets, third-party integrations, and employee accounts are added weekly, and where attacker tooling itself is evolving in near real time.
Autonomous Security as a Response
Autonomous security platforms are essentially a defensive answer to that same automation trend. If attackers can move faster with AI-assisted tooling, the argument goes, defenders need continuous, machine-speed validation of their own exposure — not just periodic manual checks. That's the core thesis behind Horizon3.ai's product positioning, and it's echoed across a growing set of competitors building similar continuous validation and exposure management tools.
Recent Expansion Moves
Beyond funding, Horizon3.ai has been notably active on the product and go-to-market side through 2026. Several announcements stand out:
- EMEA headquarters in Amsterdam — the company opened a new regional headquarters to support growing demand for AI-native proactive security across Europe, the Middle East, and Africa.
- Partnership with Brinqa — a strategic integration combining attack-path validation with exposure intelligence and remediation orchestration, aimed at helping security teams prioritize which risks to fix first.
- Rapid Response capability — a new feature designed to help organizations identify, prioritize, and respond to emerging threats faster, including validating exposure and verifying that fixes actually worked.
- Tradewinds Marketplace “Awardable” status — NodeZero achieved a designation that accelerates its accessibility to U.S. government organizations procuring security tooling.
- Expanded partner and channel investment — unveiled at the company's 2026 Global Partner Conference, signaling a push toward broader distribution through resellers and managed security service providers.
Collectively, these moves suggest a company focused less on a single flashy funding headline and more on methodically expanding its footprint — geographically, technically, and across public and private sector customers.
Competitive Landscape
Horizon3.ai operates in a crowded and increasingly well-funded segment of the security market. Competitors range from established penetration-testing-as-a-service providers to newer entrants focused specifically on AI-driven offensive testing.
| Competitor | General Focus |
|---|---|
| AttackIQ | Breach and attack simulation |
| SafeBreach | Continuous security validation |
| XM Cyber | Attack path management |
| CyCognito | External attack surface management |
| Cobalt, Synack, Bugcrowd | Human- and crowd-sourced pentesting-as-a-service |
| XBOW | AI-driven autonomous vulnerability discovery, a newer, well-funded entrant |
What differentiates Horizon3.ai within this group is largely its emphasis on production-safe, agentless deployment paired with a founding team whose background is rooted in offensive military and intelligence operations rather than traditional enterprise software.
What This Means for Enterprises
For security leaders evaluating whether autonomous pentesting platforms like NodeZero fit into their stack, a few practical considerations stand out:
- Continuous validation can catch drift — new misconfigurations, exposed assets, or expired patches — between the gaps left by annual manual testing cycles.
- Agentless architectures reduce the operational burden of deploying and maintaining testing infrastructure across large, distributed environments.
- Compliance frameworks in finance, healthcare, and government are increasingly expecting more frequent, evidence-backed testing, which continuous platforms are well positioned to support.
- No single tool replaces a full security program — autonomous pentesting is best understood as one layer among detection, response, and governance capabilities, not a standalone solution.
- Budget and procurement conversations should weigh total cost against existing manual pentest spend, since continuous platforms are often priced as ongoing subscriptions rather than one-off engagements.
Looking Ahead
Horizon3.ai's trajectory reflects a broader pattern playing out across cybersecurity: as offensive tooling gets faster and more automated, defenders are being pushed toward platforms that can match that pace. The company's methodical, multi-round funding path, expanding international footprint, and steady stream of product announcements through 2026 point to a business scaling deliberately rather than chasing a single headline valuation number.
Whether or not Horizon3.ai eventually crosses into unicorn territory, the underlying demand driver isn't going anywhere. As long as AI continues to lower the barrier for attackers to probe, exploit, and adapt quickly, the market for autonomous, continuous security validation is likely to keep growing — and Horizon3.ai remains one of the more established names positioned to benefit from that shift.
Related Topics: #Cybersecurity #Horizon3AI #NodeZero #AutonomousSecurity #PenetrationTesting #AICyberThreats #VentureCapital #EnterpriseSecurity #CloudSecurity #ThreatDetection