MasterNodeAI
news

Horizon3.ai raises $250M at $2B+ valuation for autonomous pentesting

Horizon3.ai raised $250M Series E at $2B+ valuation, tripling its June 2025 valuation. NodeZero now runs 300K+ pentests for 6,500 organizations including NSA and CISA.

news

Horizon3.ai raises $250M at $2B+ valuation for autonomous pentesting

What Happened

Horizon3.ai announced a $250 million Series E funding round at a valuation exceeding $2 billion, co-led by existing investors NightDragon and New Enterprise Associates. New backers include Acrew Capital, Blue Cloud Ventures, EDBI, Demeter Group, PSG Equity, SAIC Ventures, and Sapphire, with returning investors Craft Ventures, Qualcomm Ventures, Ridge Ventures, and SignalFire also participating.

The round represents a dramatic valuation leap. Horizon3.ai's Series D closed in June 2025 at a $650 million valuation — meaning the company roughly tripled its valuation in approximately 14 months. Total funding to date now stands at $428.5 million.

The company's NodeZero platform performs autonomous penetration testing against customers' own live production networks. A single run chains together weak credentials, misconfigurations, and identity gaps into a working attack path — the same sequence a real intruder would exploit — then provides remediation guidance and re-runs to confirm the path is closed. NodeZero can also deploy honeypots during testing to catch attackers already inside a network.

Customer count has more than doubled: from approximately 3,000 organizations at the Series D to over 6,500 today. The customer roster includes the U.S. National Security Agency, the Cybersecurity and Infrastructure Security Agency, four Fortune 10 companies, multinational banks, and healthcare networks. Annual recurring revenue grew 120% year-over-year, and the platform has now executed over 300,000 pentests in production environments.

NightDragon founder and CEO Dave DeWalt — previously CEO of FireEye and McAfee — takes a board seat alongside NightDragon Managing Director Morgan Kyauk.

Why It Matters

A 3x valuation increase in 14 months is not normal organic growth — it signals that autonomous security testing has crossed a procurement tipping point. When the NSA and CISA are both customers, the technology has cleared the highest possible security bar. That validation matters for every enterprise CISO who has been waiting for proof that autonomous pentesting won't break production systems.

The 300,000+ pentests figure is the strategic asset. Each run generates real-world attack-path data — which credentials fail, which misconfigurations chain together, which identity gaps create exploitable routes. This dataset compounds with every customer and every test, creating a moat that competitors cannot replicate without equivalent scale. Horizon3.ai explicitly treats this volume of attack data as its hardest asset to copy.

The round also funds autonomous blue-team agents — software designed to remediate what NodeZero finds without waiting for human intervention. This is the next logical step: if you can autonomously find vulnerabilities, autonomously fixing them collapses incident response timelines from days to minutes. For operators, this means the gap between detection and remediation is about to shrink dramatically.

Geographic expansion into Australia and Singapore (with EMEA to follow) indicates the company believes its product-market fit is strong enough to replicate globally without heavy localization. The inclusion of EDBI (Singapore's Economic Development Board investment arm) as a new investor signals government-level interest in the Asia-Pacific region.

Who Is Affected

Enterprise security teams and CISOs now have a federally-validated autonomous pentesting platform at scale. The question shifts from "is this safe?" to "how fast can we deploy it?" The 6,500-customer base and NSA/CISA references effectively de-risk the procurement decision.

AI security startups building offensive or defensive automation face a well-capitalized incumbent with a deep dataset moat. Direct competition in autonomous pentesting is now significantly harder. Adjacent opportunities — remediation automation, compliance mapping, vertical-specific testing, or API security testing — may offer more viable entry points.

Mid-market IT buyers who couldn't afford traditional penetration testing (which typically costs $15,000–$50,000 per engagement) now have a SaaS alternative with proven production-safe execution. The economics of continuous testing versus annual audits have fundamentally changed.

Strategic Implications

For AI startup founders

Horizon3's 300K+ pentest dataset is a moat you can't replicate from scratch. If you're building in AI security, consider adjacent niches — automated remediation, compliance evidence generation, or vertical-specific security testing for healthcare/finance — rather than head-on autonomous pentesting competition. The capital advantage ($428.5M total funding) and data advantage (300K+ production tests) create high barriers.

For developers and operators building with AI APIs

Autonomous pentesting tools like NodeZero can now safely probe your production infrastructure. Integrate continuous pentesting into your CI/CD pipeline rather than relying on annual third-party audits. The cost per test has effectively collapsed, and the remediation guidance that comes with findings is immediately actionable. If you're deploying AI agents that interact with sensitive systems, autonomous pentesting should be part of your pre-deployment checklist.

For non-technical business owners evaluating AI tools

If your organization handles sensitive data, autonomous pentesting is now a credible, affordable alternative to hiring penetration testers. Horizon3's federal agency customer base provides third-party validation that the technology is production-safe. However, evaluate whether your team can act on the findings — the tool identifies vulnerabilities, but someone still needs to implement the fixes. The upcoming autonomous blue-team agents may address this gap, but they're not yet deployed.

What to Watch Next

Monitor Horizon3.ai's progress on autonomous blue-team remediation agents — if they deliver on auto-remediation, it changes the economics of security operations teams. Also watch for competitor responses from established security vendors (CrowdStrike, Palo Alto Networks, SentinelOne) who may accelerate their own autonomous testing roadmaps. The Australia and Singapore expansion results in Q4 2026 will indicate whether the product travels well or requires localization.

Frequently Asked Questions

Q: What is autonomous pentesting and how does it differ from traditional penetration testing?

A: Autonomous pentesting uses AI agents to continuously probe your own networks for exploitable attack paths — chaining weak credentials, misconfigurations, and identity gaps — without requiring human security consultants. Traditional pentesting involves manual engagements that are expensive, periodic (usually annual), and produce static reports. Autonomous platforms like NodeZero run on demand against live production systems and re-test after fixes are applied.

Q: Is autonomous pentesting safe to run against production systems?

A: According to Horizon3.ai, NodeZero runs against live production systems without causing outages, and the platform is used by the NSA and CISA — agencies with the most sensitive networks in the world. The company states that over 300,000 pentests have been run in production environments. However, as with any security testing tool, operators should start with a scoped engagement and expand gradually.