Secure the unknown.
Need a demo?
Secure the unknown.
Every company runs more than it can see. A machine somebody set up years ago, a subdomain nobody decommissioned, a port opened for an afternoon and never closed. The unknown is not the attack you have not seen. It is the surface you have never looked at.
Building with the best
We build on the platforms you already run — your cloud, your code host, and the frontier models underneath the agents.
- Microsoft
- Amazon Web Services
- OpenAI
- Anthropic
- xAI
- Moonshot AI
- DeepSeek
- GLM
- GitHub
- npm
- Docker
- Linux
- Cloudflare
- Cisco
- Slack
- Resend
- Apollo
- WordPress
- Shopify
- Wix
- Squarespace
Meet your security team.
Four agents, each expert in one discipline, working your scope around the clock. They also hand work to each other: the watch agent finds a new CVE, the pentest agent proves whether it reaches you, and the code review agent stops the next one from shipping.
Continuous pentesting that proves every finding
Our fox runs continuous black-box assessments against your live services. It chains techniques the way a real attacker would, and proves every vulnerability with a working exploit. Then it re-tests after your fix, so a finding closes only when the agent cannot get in again.
Every pull request reviewed before it merges
Our lizard reads the codebase you already have and reports the bugs sitting in it today. Then it watches every pull request you open. It comments on the exact line, says what an attacker does with it, and blocks the merge until an owner decides. Ask it, and it writes the patch.
Audit-ready every day, not just audit week
Our owl works as your internal auditor. It keeps your policies and evidence in one place, tests every control it can test, and reads the documents behind the rest. It re-checks all of them on a schedule, so you are ready the day an auditor calls.
Know within the hour whether a new CVE reaches you
Our eye watches new disclosures around the clock. The moment a CVE lands on something in your stack, it alerts you and hands the case to the pentest agent. That agent tries it against your own surface, so you learn whether it reaches you — not just that it exists.
Your posture, and where it is going.
Open exposure across the scope, what to fix first, and the line that matters — whether the backlog is closing or growing. A healthy board is mostly black, and that is the argument.
Good evening, Operator.
demo.acme.io
Vulnerability trajectory
Open and resolved backlog by day
Top risks
Ranked by highest CVSS impact
Severity distribution
Risk density mapped across assets
Show customers you take security seriously.
Every trust seal on the internet is an image file. Ours opens a verification page on nullsquare.net — not on the site that showed it — so any customer can check the claim at its source.
200 × 32 PX
Select the plan built for your scope
Test anything on the public internet today. Add runs as you grow, and deploy a private runner when you need to reach inside your own network.
- Automated scans each month
- One target
- Dashboard and alerts
- Standard models
- Credits you can refill
- The full platform
- The strongest models
- Custom deployment
- Bring your own model
- Everything in Control
Every plan includes a full activity log • isolated sandboxes • evidence mapped to your compliance controls
What does NullSquare actually do?
Do I need to install anything on my servers?
How does credit usage work?
What types of security assessments are supported?
- Web applications, tested continuously
- APIs, including broken authentication and authorization
- Cloud perimeter, across every provider you use
- Container and sandbox escape
- Source code, for flaws an attacker can actually reach