Compare
HackZero vs.
Horizon3.
These are not the same product, and the useful comparison starts by saying so. NodeZero hunts attack paths across your internal network. We test the application you ship and bring the auditor's attestation with it. If your risk is Active Directory, buy theirs.
A year of testing
$2,990
HackZero
Published. Under 10 people, paid annually
$18,600
NodeZero
Median contract, per asset (Vendr)
Horizon3.ai publishes no prices. The figure on the right is buyer-reported median contract value, not a quote, and observed contracts run to $59,720.
Side by side
| Horizon3 NodeZero | HackZero | |
|---|---|---|
| What it actually tests | Attack paths across your internal estate: Active Directory, lateral movement, credential reuse, hundreds of hosts | The application layer of one product, plus the infrastructure it runs on |
| Published pricing | None. Four tiers with no figures, demo required for a quote | Every price on the pricing page, no sales call to see it |
| What buyers actually pay | Median near $18,600 a year, per asset, observed up to $59,720 (Vendr) | $299 a month under 10 people, $499 above |
| Test cadence | Unlimited pentests folded into every tier | Continuous, with a fresh pentest every month at any tier |
| Compliance attestation | Not part of the product | SOC 2 controls plus an independent CPA who attests them, billed to you directly |
| 104-challenge benchmark | No public score exists | 93% no hints, 100% with source (self-reported, not independently verified) |
| Funding and scale | $250M raised at a $2B+ valuation, enterprise sales motion | Seed stage, founder-led, no enterprise minimum |
| Best for | Security teams validating attack paths across a large internal network | Product teams that ship monthly and need an auditor to accept the result |
Two notes against our own interest. NodeZero folding unlimited pentests into every tier is a genuinely good model, and on a large internal estate the per-asset price can be the cheaper answer. And there is no public 104-challenge score for NodeZero, so nobody, including us, can claim a benchmark win here. We will not invent one to fill the row.
Which one
The network,
or the product.
Pick Horizon3 when
- Your risk lives inside the network. Active Directory, flat internal segments, credential reuse and lateral movement across hundreds of hosts is exactly what NodeZero was built to find, and we do not do that job.
- You have a security team to act on continuous internal findings, and an estate large enough that per-asset pricing makes sense.
- You want unlimited runs against a broad, changing internal surface rather than depth on one application.
- You are an enterprise buyer who is comfortable with a quote-based contract and wants a vendor with $250M behind it.
Pick HackZero when
- Your risk lives in the product you ship, not the corporate network. One application, tested at the layer your customers actually reach.
- You need the SOC 2 attestation as well as the test. We fold in the controls and bring an independent CPA you pay directly.
- You want the price before the sales call. Ours is published; theirs requires a demo.
- You are a small team. $2,990 for a year of monthly pentests, paid annually, is a real line item where an $18,600 median contract is not.
The other comparisons
vs. Vanta
The compliance leader, with the pentest sold separately.
Readvs. Drata
Enterprise compliance automation; the test is a separate budget line.
Readvs. XBOW
$4,000 to $8,000 a test, against a monthly subscription.
Readvs. Strix
Open source, self-hosted, and what it costs you to run.
Readvs. Manual pentest
A yearly engagement against continuous coverage.
Read