Audience
Companies in need of a solution to detect human-targeted cyber threats and train employees to prevent social engineering attacks
About ZeroThreat.ai
ZeroThreat.ai is an AI-powered penetration testing platform that identifies and validates real, exploitable vulnerabilities across modern web applications and APIs. Using Agentic AI, it executes adaptive attacker workflows to simulate real-world attack paths, proving impact and eliminating false positives.
The platform leverages continuously updated vulnerability checks with proof-based validation, real-time CVE coverage and Application Journeys (Playwright-powered) to test authenticated flows, APIs, and complex business logic beyond traditional crawling. It also integrates custom and community-driven attack templates to extend coverage and reflect real-world attack techniques.
By focusing on verified findings rather than raw vulnerability counts, ZeroThreat.ai reduces manual triage by over 90% and enables security teams to prioritize and remediate actual risk with confidence, while maintaining continuous, production-safe testing across environments.
Pricing
Integrations
Company Information
Product Details
ZeroThreat.ai Frequently Asked Questions
ZeroThreat.ai Product Features
ZeroThreat.ai Additional Categories
ZeroThreat.ai Verified User Reviews
Write a Review-
Probability You Would Recommend?1 2 3 4 5 6 7 8 9 10
"Tested it against a known-vulnerable environment before trusting it in production" Posted 2026-05-25
Pros: BOLA and broken function-level authorization testing is genuinely strong — better than competitors I've evaluated.
Transparent about what it can and can't detect, which I appreciate more than overpromising.
API discovery found three endpoints in our staging environment that weren't in our internal docs.Cons: Mass assignment vulnerabilities and some rate limiting issues need more manual follow-up — the tool doesn't catch everything.
Would like to see more granular control over which test modules run. Right now it's a bit all-or-nothing.
Documentation for edge-case authentication setups is thin. Had to contact support for our custom JWT flow.Overall: I don't deploy tools into our pipeline without validating them first. I set up a deliberately vulnerable API environment — OWASP API Security Top 10 style — and ran ZeroThreat.ai against it before touching anything real. It caught 8 of the 10 categories. Missed a rate limiting issue and a mass assignment vulnerability that needed more application context to detect. That's a reasonable hit rate for an automated tool and honestly better than I expected.
Read More...
In production it's been running for four months. It's found two genuine access control issues that our quarterly manual assessment hadn't caught. The BOLA detection in particular is better than anything I've seen from an automated scanner. -
Probability You Would Recommend?1 2 3 4 5 6 7 8 9 10
"Found a bunch of APIs we forgot about" Edited 2026-05-01
Pros: - Strong API discovery, including hidden endpoints
- Tests for complex logic vulnerabilities like BOLA
- Clear, developer-friendly reports
- Provides actionable remediation guidanceCons: - Initial mapping may require fine-tuning for large systems
- Some advanced configurations need security expertiseOverall: After moving to microservices, we lost visibility into some endpoints and were concerned about shadow APIs. ZeroThreat.ai helped map our API ecosystem quickly, including endpoints we thought were inactive. What stood out was its ability to test business logic issues like BOLA, which usually requires manual pentesting. The reports were simple and included actionable code fixes.
Read More...
- Previous
- You're on page 1
- Next