Compare

HackZero vs.
Horizon3.

These are not the same product, and the useful comparison starts by saying so. NodeZero hunts attack paths across your internal network. We test the application you ship and bring the auditor's attestation with it. If your risk is Active Directory, buy theirs.

A year of testing

$2,990

HackZero

Published. Under 10 people, paid annually

$18,600

NodeZero

Median contract, per asset (Vendr)

Horizon3.ai publishes no prices. The figure on the right is buyer-reported median contract value, not a quote, and observed contracts run to $59,720.

Side by side

Horizon3 NodeZero HackZero
What it actually tests Attack paths across your internal estate: Active Directory, lateral movement, credential reuse, hundreds of hosts The application layer of one product, plus the infrastructure it runs on
Published pricing None. Four tiers with no figures, demo required for a quote Every price on the pricing page, no sales call to see it
What buyers actually pay Median near $18,600 a year, per asset, observed up to $59,720 (Vendr) $299 a month under 10 people, $499 above
Test cadence Unlimited pentests folded into every tier Continuous, with a fresh pentest every month at any tier
Compliance attestation Not part of the product SOC 2 controls plus an independent CPA who attests them, billed to you directly
104-challenge benchmark No public score exists 93% no hints, 100% with source (self-reported, not independently verified)
Funding and scale $250M raised at a $2B+ valuation, enterprise sales motion Seed stage, founder-led, no enterprise minimum
Best for Security teams validating attack paths across a large internal network Product teams that ship monthly and need an auditor to accept the result

Two notes against our own interest. NodeZero folding unlimited pentests into every tier is a genuinely good model, and on a large internal estate the per-asset price can be the cheaper answer. And there is no public 104-challenge score for NodeZero, so nobody, including us, can claim a benchmark win here. We will not invent one to fill the row.

Which one

The network,
or the product.

Pick Horizon3 when

  • Your risk lives inside the network. Active Directory, flat internal segments, credential reuse and lateral movement across hundreds of hosts is exactly what NodeZero was built to find, and we do not do that job.
  • You have a security team to act on continuous internal findings, and an estate large enough that per-asset pricing makes sense.
  • You want unlimited runs against a broad, changing internal surface rather than depth on one application.
  • You are an enterprise buyer who is comfortable with a quote-based contract and wants a vendor with $250M behind it.

Pick HackZero when

  • Your risk lives in the product you ship, not the corporate network. One application, tested at the layer your customers actually reach.
  • You need the SOC 2 attestation as well as the test. We fold in the controls and bring an independent CPA you pay directly.
  • You want the price before the sales call. Ours is published; theirs requires a demo.
  • You are a small team. $2,990 for a year of monthly pentests, paid annually, is a real line item where an $18,600 median contract is not.