Companies

ZeroPath

zeropath.com

ZeroPath is an AI-native application-security platform that autonomously finds, verifies, and fixes code vulnerabilities.

HQSan Francisco, California, United States
Employees1-50
6 active roles
Jobs checked 3h ago
CybersecurityAI Agent / AutomationB2B SaaS

About

ZeroPath builds an AI-native application security platform that autonomously detects, verifies, and submits fixes for vulnerabilities in code. It sells to developers and companies, differentiating through AI that understands code context and developer intent to reduce false positives while identifying real vulnerabilities.

Market

ZeroPath competes in the application-security and DevSecOps market, positioning itself as an AI-native, agentic platform that unifies SAST, SCA, secrets, IaC, container, PR, and runtime testing across cloud, hybrid, and on-premises applications. It differentiates through contextual detection of business-logic and authentication flaws, AI-generated fixes, natural-language policy creation, and visibility into AI models, agents, and MCP servers, rather than focusing only on conventional rule-based code scanning.

Target Customers

ZeroPath targets security-conscious software companies, particularly regulated or data-sensitive organizations in fintech and finance, healthcare and healthtech, cryptocurrency, and other industries handling customer or payment data. Its primary buyers are AppSec, security engineering, and DevSecOps leaders at startups through enterprises; its managed offering is especially relevant to teams that need comprehensive coverage without hiring a large security staff.

At a Glance

Problem

Modern development teams need to ship quickly while securing increasingly complex cloud, hybrid, on-premises, and AI-enabled applications. Traditional SAST tools generate overwhelming false positives and often miss business-logic, broken-authentication, and authorization flaws; vulnerabilities found late in production are more expensive and risky to fix, while developers may lack the security expertise to remediate them safely. ZeroPath’s core economic promise is to reduce wasted security-review and triage time while preventing exploitable defects from reaching production. Its clearest use case is payment and other mission-critical application security: ZeroPath says a fintech customer found 12 critical business-logic flaws missed by traditional SAST, cut review time from two weeks to two hours, and reduced 5,000-plus Checkmarx findings to 127 actionable issues.

Product / Service

ZeroPath is an AI-native application-security platform combining contextual SAST with software-composition analysis, secrets detection, infrastructure-as-code scanning, threat modeling, policy enforcement, and automated patching. Its analysis uses AST-based code understanding and AI to reason about application context, security models, authentication flows, and developer intent, while teams can express custom policies in natural language. The product runs automated pull-request reviews, full-repository and scheduled scans, and provides explanations and context-aware fixes intended to preserve functionality rather than apply generic patches.

The delivery model is enterprise-oriented: customers can connect repositories for rapid scans and CI/CD workflows, use the CLI, and deploy through SaaS, on-premises, or private-cloud options. ZeroPath reports sub-60-second PR scans, one-click setup, and materially lower alert noise; its published materials cite reductions in vulnerabilities reaching production, penetration-test findings, and false positives. The platform’s benefit is therefore not simply finding more issues, but turning security analysis into a faster developer workflow with prioritized, actionable remediation.

Market

ZeroPath competes in application security, particularly the AI-native SAST and broader AppSec-platform category. Its own benchmark names Bearer by Cycode, Semgrep, and Snyk as comparable SAST tools, positioning ZeroPath around detection of business-logic and authentication vulnerabilities that it says conventional scanners often miss. The broader competitive environment also includes incumbent tools whose findings ZeroPath describes consolidating, such as Checkmarx, Veracode, and Fortify.

The company has disclosed meaningful usage traction rather than a verified revenue figure: its August 2025 v1 announcement claimed that more than 750 companies were using ZeroPath and that the platform performed more than 125,000 code scans per month, alongside reported zero-day discoveries in repositories associated with Netflix, Hulu, and Salesforce. It is clearly being marketed and deployed as a commercial product, including personalized demos and enterprise deployment options, but the gathered evidence does not establish revenue or ARR; it is therefore more accurate to describe ZeroPath as commercially launched with reported adoption than to call it definitively pre-revenue.

Founders & Leadership

Dean ValentineFounder
Co-Founder & CEO
Nathan HrncirikFounder
Co-Founder & CIO
Raphael KargerFounder
Co-Founder & CTO
Etienne LunettaFounder
Co-Founder & COO
John WalkerHead of Security Research
Peter PurcellHead of Marketing

Funding History

2024-06
Seed$500K

Y Combinator

2024-07
Seed$7.03M

HOF Capital, SurgePoint Capital, Crosspoint Capital

Recent News

2026-05-19product
Zero - AI AppSec Agent

ZeroPath’s product page describes Zero as a persistent agent that uses the company’s scanning, code intelligence, and policy engine to coordinate entire application-security workflows.

2026-05-12product
ZeroPath Launches Zero, the First AI Built to Run an Entire Application Security Program

ZeroPath launched Zero, a persistent AI agent designed to integrate with security teams and build and manage an organization’s entire application-security program.

2026-05-11partnership
ZeroPath Outperforms Mythos In Real World Test

ZeroPath highlighted an open-source MCP server that integrates with Claude, Cursor, Windsurf, and other tools to surface SAST issues, secrets, and patches within developer workflows.

2026-05-11partnership
Zero: AI Assistant For AppSec

ZeroPath introduced its Zero AppSec assistant and described integrations through an open-source MCP server supporting Claude, Cursor, Windsurf, and other developer tools.

2026-03-13
ZeroPath Named a Top 10 Finalist in the RSAC 2026 Innovation Sandbox

Business Wire reported that ZeroPath was selected as a Top 10 finalist in the RSAC 2026 Innovation Sandbox, where it would showcase technology that autonomously finds and fixes exploitable vulnerabilities.

2026-02-10
Finalists Announced for RSAC Innovation Sandbox Contest 2026

RSA Conference announced the 2026 Innovation Sandbox finalists and identified ZeroPath as a code-security tool replacing traditional SAST, SCA, and secrets-scanning products.

2025-12-15
ZeroPath at Black Hat USA 2026 — Booth #7908

ZeroPath announced that it would exhibit at Black Hat USA 2026 in Las Vegas from August 4–6, 2026.

2025-08-12product
The Security Platform That Actually Understands Your Code

ZeroPath announced the official v1 launch of its AI-powered application-security platform, reporting that it was trusted by more than 750 companies and performing over 125,000 code scans per month.

Active Roles

6

Business Model

ZeroPath sells paid application-security subscriptions, with pricing starting at $1,000 per month plus $60 per developer. It also offers a free Personal Workspace tier for individual developers and team-oriented plans.

Products

AI-native SASTSoftware composition analysis (SCA)Secrets scanningInfrastructure-as-code securityPull-request security reviewsPolicy Engine for natural-language custom security rulesRisk ManagementAI-powered SAST AutofixDynamic application security testing (DAST)Container ScanningAI InventoryManaged Application Security

Customers

Aptos LabsExodus

Tech Stack

Large language models (LLMs) and agentic AIAI-native SAST across 15+ programming languagesSoftware composition analysis (SCA) with reachability-aware dependency analysisDynamic application security testing (DAST) and runtime exploit verificationSecrets scanning and credential detectionInfrastructure-as-code security for Terraform, CloudFormation, and KubernetesContainer-image vulnerability and misconfiguration scanningMCP integrations and AI-component inventory for LLM SDKs, models, agents, and MCP servers

Competitors

Semgrep
Snyk
Checkmarx
Veracode
SonarQube
Fortify
Synopsys