DrochaidHorizon3.aiHorizon3.ai
NodeZero/Proof
Evidence, not opinion

Proof

Don’t take our word for it.

Everything this site claims about NodeZero should be checkable. This page collects the evidence in one place — independent ratings, named customer stories, and benchmark results — each linked to its source so you can read it where it was published.

Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner
4.7 / 5
Gartner Peer Insights

Horizon3.ai holds a 4.7/5 rating on Gartner Peer Insights from roughly 140 verified customer reviews, and was named a Customers’ Choice in the October 2025 Voice of the Customer report for adversarial exposure validation.

Peer Insights reviews are submitted by verified customers and moderated by Gartner — read them, and the G2 and PeerSpot reviews, via horizon3.ai/customer-reviews.

Named customers, in their own words.

Summarised here; published in full on horizon3.ai. Each link goes to the original story.

Financial services

From Patch Tuesday to Pentest Wednesday

A regulated financial services organisation moved from annual, compliance-driven pentests to weekly validation across cloud and hybrid infrastructure. One AWS credential turned out to sit on 39 distinct attack paths; full AWS account compromise took under 10 minutes; remediation time fell from months to days.

Education

Compliance evidence without the annual pentest bill

A university that had relied on one expensive pentest a year moved to continuous assessment with actionable remediation guidance — and found weaknesses its annual engagements had never surfaced.

The things that you are finding, we didn’t know existed.
Jim Beers, Director of Information Security, Moravian University
Security consulting

Defence in depth, tested from the attacker’s side

The consultancy behind the line on our homepage: defence in depth helps, but without the attacker’s perspective you cannot know you are ready. NodeZero let JTI test continuously and surface what manual engagements had missed.

…without taking an attacker’s perspective by considering actual attack vectors that they can use to get in, you really can’t be ready.
Jon Isaacson, Principal Consultant, JTI Cybersecurity

Benchmark and program results.

These figures are Horizon3’s own reporting — a vendor benchmark, not an independent test — which is why each carries its source. The Game of Active Directory (GOAD) is a widely used community benchmark for Active Directory exploitation.

14 min
to fully solve the Game of Active Directory — the first AI to do so, by Horizon3’s own benchmark report.
Horizon3.ai press release, August 2025
50×
faster than an expert human on the same benchmark, with the full attack chain executed end to end — as reported by Horizon3.
Horizon3.ai press release, August 2025
< 5 min
to reach CAD drawings of aircraft carriers and nuclear submarines — an operational result reported from the NSA CAPT program, which NodeZero powers.
Horizon3.ai press release, August 2025

Proof in practice: Dynatrace’s continuous security program.

One of the world’s leading observability companies moved from periodic scans to continuous, autonomous testing — surfacing and remediating real issues before attackers could exploit them.

Lessons from the front lines: Dynatrace's journey with NodeZero
Awards and recognition
Rising in Cyber Award 2025Global InfoSec Awards 2025Fast Company Most Innovative Companies 2026Deloitte Technology Fast 500 Award 2025Black Unicorn Awards 2025 WinnerSaaS Awards 2025 — Best SaaS Product for Cybersecurity2025 AI in Cybersecurity Innovation Award
Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

The next proof point should be your environment.

Book a walkthrough — we'll run NodeZero against a live environment and show you the attack paths, the evidence, and the fix guidance.