Proof
Don’t take our word for it.
Everything this site claims about NodeZero should be checkable. This page collects the evidence in one place — independent ratings, named customer stories, and benchmark results — each linked to its source so you can read it where it was published.
Horizon3.ai holds a 4.7/5 rating on Gartner Peer Insights from roughly 140 verified customer reviews, and was named a Customers’ Choice in the October 2025 Voice of the Customer report for adversarial exposure validation.
Peer Insights reviews are submitted by verified customers and moderated by Gartner — read them, and the G2 and PeerSpot reviews, via horizon3.ai/customer-reviews.
Named customers, in their own words.
Summarised here; published in full on horizon3.ai. Each link goes to the original story.
From Patch Tuesday to Pentest Wednesday
A regulated financial services organisation moved from annual, compliance-driven pentests to weekly validation across cloud and hybrid infrastructure. One AWS credential turned out to sit on 39 distinct attack paths; full AWS account compromise took under 10 minutes; remediation time fell from months to days.
Compliance evidence without the annual pentest bill
A university that had relied on one expensive pentest a year moved to continuous assessment with actionable remediation guidance — and found weaknesses its annual engagements had never surfaced.
“The things that you are finding, we didn’t know existed.”
Defence in depth, tested from the attacker’s side
The consultancy behind the line on our homepage: defence in depth helps, but without the attacker’s perspective you cannot know you are ready. NodeZero let JTI test continuously and surface what manual engagements had missed.
“…without taking an attacker’s perspective by considering actual attack vectors that they can use to get in, you really can’t be ready.”
Benchmark and program results.
These figures are Horizon3’s own reporting — a vendor benchmark, not an independent test — which is why each carries its source. The Game of Active Directory (GOAD) is a widely used community benchmark for Active Directory exploitation.
Proof in practice: Dynatrace’s continuous security program.
One of the world’s leading observability companies moved from periodic scans to continuous, autonomous testing — surfacing and remediating real issues before attackers could exploit them.
The next proof point should be your environment.
Book a walkthrough — we'll run NodeZero against a live environment and show you the attack paths, the evidence, and the fix guidance.






