NullSquareNullSquare

Secure the unknown.

Need a demo?

The unknown

Secure the unknown.

Every company runs more than it can see. A machine somebody set up years ago, a subdomain nobody decommissioned, a port opened for an afternoon and never closed. The unknown is not the attack you have not seen. It is the surface you have never looked at.

Building with the best

We build on the platforms you already run — your cloud, your code host, and the frontier models underneath the agents.

  • Microsoft
  • Amazon Web Services
  • Google
  • OpenAI
  • Anthropic
  • xAI
  • Moonshot AI
  • DeepSeek
  • GLM
  • GitHub
  • npm
  • Docker
  • Linux
  • Cloudflare
  • Cisco
  • Slack
  • Resend
  • Apollo
  • WordPress
  • Shopify
  • Wix
  • Squarespace

Meet your security team.

Four agents, each expert in one discipline, working your scope around the clock. They also hand work to each other: the watch agent finds a new CVE, the pentest agent proves whether it reaches you, and the code review agent stops the next one from shipping.

PENTEST

Continuous pentesting that proves every finding

Our fox runs continuous black-box assessments against your live services. It chains techniques the way a real attacker would, and proves every vulnerability with a working exploit. Then it re-tests after your fix, so a finding closes only when the agent cannot get in again.

CODE REVIEW

Every pull request reviewed before it merges

Our lizard reads the codebase you already have and reports the bugs sitting in it today. Then it watches every pull request you open. It comments on the exact line, says what an attacker does with it, and blocks the merge until an owner decides. Ask it, and it writes the patch.

READINESS

Audit-ready every day, not just audit week

Our owl works as your internal auditor. It keeps your policies and evidence in one place, tests every control it can test, and reads the documents behind the rest. It re-checks all of them on a schedule, so you are ready the day an auditor calls.

WATCH

Know within the hour whether a new CVE reaches you

Our eye watches new disclosures around the clock. The moment a CVE lands on something in your stack, it alerts you and hands the case to the pentest agent. That agent tries it against your own surface, so you learn whether it reaches you — not just that it exists.

Trust badge

Show customers you take security seriously.

Every trust seal on the internet is an image file. Ours opens a verification page on nullsquare.net — not on the site that showed it — so any customer can check the claim at its source.

Secured by NullSquare

200 × 32 PX

Select the plan built for your scope

Test anything on the public internet today. Add runs as you grow, and deploy a private runner when you need to reach inside your own network.

Watch
Website owners$19/moper scheduled test
  • Automated scans each month
  • One target
  • Dashboard and alerts
  • Standard models
Get started
Control
Security teams$50/moper seat
  • Credits you can refill
  • The full platform
  • The strongest models
Get started
Customize
Tailored operationsCustom
  • Custom deployment
  • Bring your own model
  • Everything in Control
Contact Us

Every plan includes a full activity log • isolated sandboxes • evidence mapped to your compliance controls

What does NullSquare actually do?
NullSquare puts four security agents on your systems. They pentest your websites, APIs and cloud, review every pull request before it merges, and map what they prove to your compliance controls as they go.
Do I need to install anything on my servers?
No install is required for public targeting. If you need to test internal private networks or keep testing payloads completely inside your isolated VPC boundaries, you can deploy a Private Runner with a single container execution command.
How does credit usage work?
A credit is spent while an agent is actively working a target. How fast you spend depends on three things: how large the scope is, how deep you set the test, and how long the runner stays active. You can add credits at any time.
What types of security assessments are supported?
The agents test five surfaces:
  • Web applications, tested continuously
  • APIs, including broken authentication and authorization
  • Cloud perimeter, across every provider you use
  • Container and sandbox escape
  • Source code, for flaws an attacker can actually reach
Where can I learn how to operate the platform?
We maintain comprehensive customer documentation that covers everything from your first discovery run to deploying private runners. Read the documentation for a complete operating guide.
NullSquare

Secure the unknown.

Platform

Legal

© 2026 NullSquare inc. All rights reserved. • Toronto, Canada