ZeroPath

AI-native AppSec that verifies findings before flagging them.

Security & Safety Freemium Has API
Researched · Published · Reviewed
RECATOOLS Score
7.8 / 10
Capability
8.5
Value for money
6.5
Ease of use
8
ASEAN readiness
6.5
API quality
7.5
Founded
2024
HQ
San Francisco, California, USA
Users
1,000+ organisations, 200k+ scans/month (Mar 2026)
Launched
Public launch Jan 22, 2025; v1 August 2025
Developer
ZeroPath Corp.

Overview

AI-native AppSec platform, founded 2024 by ex-Tesla and Google security engineers, that replaces SAST/SCA/secrets scanners with an LLM engine that verifies findings before flagging them. As of May 2026 it runs 200,000+ scans/month across 1,000+ organizations.

Advertisement

Pricing

Pricing shown for reference only. These figures reflect RECATOOLS research as of 11 Jul 2026 and may be out of date or incomplete. This is not financial or purchasing advice — always confirm the current price on the provider’s official website before making any decision.

Enterprise
Custom
Self-hosted and compliance-heavy deployments.
  • On-prem / BYO LLM key
  • Volume discounts
  • Dedicated SLA support
  • SCIM + policy engine

Use cases

Replacing a sprawling stack of SAST, SCA, secrets, and IaC tools with a single AI-native platform Automating security review of every pull request in under two minutes without blocking developer velocity Detecting business logic flaws and authentication bypasses in complex codebases (e.g., blockchain, fintech) that rule-based scanners miss Running a lean AppSec programme without a large dedicated security team via the managed Zero AI agent Generating evidence for SOC 2, ISO 27001, and compliance audits through automated GRC platform integrations

What you can produce with ZeroPath

  • PR-level vulnerability report with CVSS 4.0 ratings delivered in under 2 minutes
  • Automated remediation pull requests submitted directly to GitHub / GitLab / Bitbucket
  • Full-repo SAST + SCA + secrets + IaC scan with reachability-aware dependency analysis
  • Custom security policy rules authored in plain English via the policy engine
  • Compliance evidence exports (SARIF, CSV) synced to Jira, Linear, Vanta, Drata, ServiceNow
  • ZERO AI agent managing triage, CVE response, and escalation workflows inside Slack
  • Executive security posture dashboards and custom CISO-ready reports
Advertisement

ASEAN Perspective

ZeroPath in Southeast Asia

ZeroPath counts HitPay — a Singapore-based fintech serving Southeast Asian merchants — among its confirmed customers, providing some proof of regional fit, particularly for fintech and crypto-native teams across SG, MY, and PH. The platform's cloud-hosted default with US-based infrastructure may be a consideration for MAS-regulated Singapore institutions or Indonesian BSSN-compliance scenarios where data residency matters. On-premises and self-hosted deployment (Enterprise tier) mitigates this but requires a custom engagement. No dedicated ASEAN sales presence or localised compliance reporting (MAS TRM, OJK, BNM) has been announced as of mid-2026, so regional procurement teams should factor in potential onboarding friction.

RECATOOLS Verdict

ZeroPath's LLM-plus-verification pipeline demonstrably catches business-logic and auth vulnerabilities that pattern-matching scanners miss — the Aptos Labs case study (1M+ line Rust codebase, a replay bug that Semgrep, Checkmarx and Snyk all missed) is a solid, checkable reference. Sub-two-minute PR scans with one-click autofix, and the May 2026 "Zero" agent living inside Slack to triage and escalate autonomously, push it past scan-and-report into real AppSec workflow ownership.

The headline "2x vulnerabilities, 75% fewer false positives" figures trace to ZeroPath's own benchmark, not an independent audit — treat as directional. Team pricing starts at $1,000/month plus $60/developer with no free tier (a 50% startup discount helps). The company's own May 2026 figures put it at 1,000+ organizations and 200,000+ monthly scans, notably lower than the 300,000+ figure sometimes cited. APAC presence remains unconfirmed.

Independent AI-assisted assessment by RECATOOLS.

What people say

ZeroPath's own numbers, from its most recent (May 2026) company announcement, put it at 1,000-plus organizations running 200,000-plus scans a month — worth noting since some secondary listings round that up further than ZeroPath's own press releases support. Founded by engineers out of Tesla's red team and Google security, the pitch is straightforward: replace pattern-matching SAST with an LLM that models your codebase and verifies findings before flagging them.

The Aptos Labs case study is a solid, checkable data point — a 1M+ line Rust codebase, production-ready in under two days, and a replay-related vulnerability the team says Semgrep, Checkmarx and Snyk all missed. G2 reviewers echo that, with several calling out logic-vulnerability detection as ahead of Aikido, Checkmarx and Fortify. The core "2x more real vulnerabilities, 75% fewer false positives" claim, though, still traces back to ZeroPath's own benchmark rather than an independent audit.

Team pricing starts at $1,000/month plus $60 per developer with no free tier, which puts it out of reach for small teams unless they qualify for the 50% startup discount. The May 2026 "Zero" agent, living inside Slack to triage and escalate autonomously, is a genuine step past scan-and-report. APAC presence is unconfirmed — no named regional customers, no local data residency story yet.

Summary of public user & expert reviews, compiled by RECATOOLS.

Notable facts

  • ZeroPath's co-founders from Tesla Red Team and Google Security started the company after growing frustrated that their own security tools generated thousands of alerts — but flagged almost no real bugs.
  • ZeroPath's published benchmark shows it detected 87.5% of business logic and authentication vulnerabilities — while Snyk and Bearer detected 0% on the same test set.
  • Within seven months of its January 2025 public launch, ZeroPath grew to 750+ customers and 125,000 monthly scans; by mid-2026 that had scaled to 1,000+ orgs and 300,000+ scans.
  • ZeroPath was selected as a Top 10 finalist in the RSAC 2026 Innovation Sandbox — the cybersecurity industry's most-watched startup competition — just 14 months after its public launch.

Frequently asked questions

How is ZeroPath different from Semgrep or Snyk?
Traditional SAST tools like Semgrep use pattern-matching rules that miss business logic flaws and generate high false-positive rates. ZeroPath combines LLMs with abstract syntax tree analysis to understand code intent, trace data flows, and validate exploitability before raising a finding. In ZeroPath's own benchmarks (forked from the XBOW framework), it detected 87.5% of business logic/auth vulnerabilities where Semgrep scored 12.5% and Snyk scored 0%.
Does ZeroPath fix vulnerabilities automatically?
Yes. When ZeroPath is confident in a finding it submits a remediation pull request directly to your repository. Fixes can be triggered one-click from the PR review UI, and the platform re-scans after the fix is applied to confirm resolution. For the May 2026 'Zero' agentic tier, workflows and approval chains are handled autonomously inside Slack.
What languages and platforms are supported?
ZeroPath covers 30+ programming languages including Python, JavaScript/TypeScript, Java, Go, Rust, C/C++, C#, PHP, Ruby, Swift, Kotlin, Dart, Elixir, Scala, and Nim. It integrates with GitHub, GitLab, Bitbucket, and Azure DevOps for version control, and exports findings in SARIF and CSV formats compatible with Jira, Linear, Vanta, Drata, and ServiceNow.

About this listing

Researched on
Published on
Last reviewed

This entry was compiled from publicly available data including ZeroPath's official website, press releases, documentation, and reputable third-party publications. RECATOOLS is not affiliated with ZeroPath unless explicitly stated.

Data accuracy

Third-party AI tools update their pricing, features, availability, and policies frequently. Information here may be outdated by the time you read this — we make reasonable efforts to keep listings current, but cannot guarantee absolute accuracy.

For the latest details, please refer to ZeroPath directly →

Spotted something out of date? Suggest an update →

Advertisement