MCP server

Your AI agent,
now a pentester.

Connect HackZero to your AI coding agent. Ask in plain English, and it runs the pentest, opens the fixes, and pulls the report, right where you work.

Works with Claude Code, Cursor, Windsurf, VS Code, and any MCP client.

Join the waitlist

Early access. Same credits, no extra cost.

A brushed concrete labyrinth on warm cream paper, dissolving into ink. Your codebase, worked from where you already are.

In your editor

Ask in plain English.
It does the rest.

Tell Claude Code or Cursor what you want. It calls HackZero, runs the work, and brings the results back, without leaving your editor.

A Claude Code terminal driving HackZero over MCP. The user asks to fix the critical findings and get the report. The agent calls the HackZero tools, opens the fix as a pull request, and returns a report with SOC 2 evidence. Install it in Claude Code with: claude mcp add --transport http hackzero https://mcp.hackzero.ai/mcp

What it can do

The whole loop,
in your editor.

One conversation, start to finish:

  • Launch a pentest on the branch you just pushed.
  • Pull the findings straight into the chat.
  • Open the fix as a pull request.
  • Get the report, with SOC 2 evidence.
A lone figure in a vast vaulted chamber lit by a single beam. The whole loop, run from one place.

Frequently asked

Questions.

It is in early access. Join the waitlist and we will bring you in.

The Model Context Protocol, the standard way AI tools call outside services. We expose HackZero over it, so your agent can drive a pentest directly.

Claude Code, Cursor, Windsurf, VS Code, and any MCP client.

No. It runs the same engine and the same monthly credits. MCP is just a new way in.

Yes. It is scoped to exactly what your token allows, and every run still follows your signed rules of engagement.