ZeroPath
AI-native AppSec that verifies findings before flagging them.
Overview
AI-native AppSec platform, founded 2024 by ex-Tesla and Google security engineers, that replaces SAST/SCA/secrets scanners with an LLM engine that verifies findings before flagging them. As of May 2026 it runs 200,000+ scans/month across 1,000+ organizations.
Pricing
Pricing shown for reference only. These figures reflect RECATOOLS research as of 11 Jul 2026 and may be out of date or incomplete. This is not financial or purchasing advice — always confirm the current price on the provider’s official website before making any decision.
- AI-native SAST
- SCA + reachability
- PR autofix
- SSO/SAML
- On-prem / BYO LLM key
- Volume discounts
- Dedicated SLA support
- SCIM + policy engine
Use cases
What you can produce with ZeroPath
- PR-level vulnerability report with CVSS 4.0 ratings delivered in under 2 minutes
- Automated remediation pull requests submitted directly to GitHub / GitLab / Bitbucket
- Full-repo SAST + SCA + secrets + IaC scan with reachability-aware dependency analysis
- Custom security policy rules authored in plain English via the policy engine
- Compliance evidence exports (SARIF, CSV) synced to Jira, Linear, Vanta, Drata, ServiceNow
- ZERO AI agent managing triage, CVE response, and escalation workflows inside Slack
- Executive security posture dashboards and custom CISO-ready reports
ASEAN Perspective
ZeroPath in Southeast Asia
ZeroPath counts HitPay — a Singapore-based fintech serving Southeast Asian merchants — among its confirmed customers, providing some proof of regional fit, particularly for fintech and crypto-native teams across SG, MY, and PH. The platform's cloud-hosted default with US-based infrastructure may be a consideration for MAS-regulated Singapore institutions or Indonesian BSSN-compliance scenarios where data residency matters. On-premises and self-hosted deployment (Enterprise tier) mitigates this but requires a custom engagement. No dedicated ASEAN sales presence or localised compliance reporting (MAS TRM, OJK, BNM) has been announced as of mid-2026, so regional procurement teams should factor in potential onboarding friction.
ZeroPath's LLM-plus-verification pipeline demonstrably catches business-logic and auth vulnerabilities that pattern-matching scanners miss — the Aptos Labs case study (1M+ line Rust codebase, a replay bug that Semgrep, Checkmarx and Snyk all missed) is a solid, checkable reference. Sub-two-minute PR scans with one-click autofix, and the May 2026 "Zero" agent living inside Slack to triage and escalate autonomously, push it past scan-and-report into real AppSec workflow ownership.
The headline "2x vulnerabilities, 75% fewer false positives" figures trace to ZeroPath's own benchmark, not an independent audit — treat as directional. Team pricing starts at $1,000/month plus $60/developer with no free tier (a 50% startup discount helps). The company's own May 2026 figures put it at 1,000+ organizations and 200,000+ monthly scans, notably lower than the 300,000+ figure sometimes cited. APAC presence remains unconfirmed.
What people say
ZeroPath's own numbers, from its most recent (May 2026) company announcement, put it at 1,000-plus organizations running 200,000-plus scans a month — worth noting since some secondary listings round that up further than ZeroPath's own press releases support. Founded by engineers out of Tesla's red team and Google security, the pitch is straightforward: replace pattern-matching SAST with an LLM that models your codebase and verifies findings before flagging them.
The Aptos Labs case study is a solid, checkable data point — a 1M+ line Rust codebase, production-ready in under two days, and a replay-related vulnerability the team says Semgrep, Checkmarx and Snyk all missed. G2 reviewers echo that, with several calling out logic-vulnerability detection as ahead of Aikido, Checkmarx and Fortify. The core "2x more real vulnerabilities, 75% fewer false positives" claim, though, still traces back to ZeroPath's own benchmark rather than an independent audit.
Team pricing starts at $1,000/month plus $60 per developer with no free tier, which puts it out of reach for small teams unless they qualify for the 50% startup discount. The May 2026 "Zero" agent, living inside Slack to triage and escalate autonomously, is a genuine step past scan-and-report. APAC presence is unconfirmed — no named regional customers, no local data residency story yet.
Summary of public user & expert reviews, compiled by RECATOOLS.
Notable facts
- ZeroPath's co-founders from Tesla Red Team and Google Security started the company after growing frustrated that their own security tools generated thousands of alerts — but flagged almost no real bugs.
- ZeroPath's published benchmark shows it detected 87.5% of business logic and authentication vulnerabilities — while Snyk and Bearer detected 0% on the same test set.
- Within seven months of its January 2025 public launch, ZeroPath grew to 750+ customers and 125,000 monthly scans; by mid-2026 that had scaled to 1,000+ orgs and 300,000+ scans.
- ZeroPath was selected as a Top 10 finalist in the RSAC 2026 Innovation Sandbox — the cybersecurity industry's most-watched startup competition — just 14 months after its public launch.
Frequently asked questions
About this listing
This entry was compiled from publicly available data including ZeroPath's official website, press releases, documentation, and reputable third-party publications. RECATOOLS is not affiliated with ZeroPath unless explicitly stated.
Third-party AI tools update their pricing, features, availability, and policies frequently. Information here may be outdated by the time you read this — we make reasonable efforts to keep listings current, but cannot guarantee absolute accuracy.
For the latest details, please refer to ZeroPath directly →
Spotted something out of date? Suggest an update →
ZeroPath in the news
Cybersecurity
Microsoft's Largest-Ever Patch Tuesday: 600-Plus Fixes, Two Live Zero-Days, and a Triage P...
Cybersecurity
Miasma Returns With 'Phantom Gyp': npm Worm Sidesteps the Install-Script Defences Teams Ju...
Developer Tools
Miasma: How a Hijacked CI Pipeline Shipped Malicious npm Packages With Valid Provenance
Alternatives to ZeroPath
More in Security & Safety