
Secure the unknown.
Continuous Penetration Testing
Run continuous security testing across your websites, APIs, cloud assets, and private environments. Review findings, reports, and live agent activity in one unified dashboard.
Building with the best
We partner with the teams shaping security, cloud, and frontier AI to keep your defenses ahead of the threat.
How it works
From setup to report, the platform tracks what is tested, maps your scope boundaries, and streams findings in real time.
Connect what you want to test
Add a website, API, repository, or private target. NullSquare maps the scope and prepares the run from a clean starting point.
Let the agent do the work
The agent explores the target, runs the right tools, follows evidence, and validates supported issues before reporting.
Turn findings into action
Review validated findings, inspect the retained proof, share the report, and rerun checks after fixes land.
Ready to explore?
Explore the live interactive platform demo in seconds. No configuration required.
Core capabilities
Built for security and engineering teams that need clear, actionable findings without the noise.
Execute anywhere
Deploy agents inside your VPC, on-prem, or across global cloud regions.
Code-aware analysis
Continuous exploitability vetting for every PR and repository transmission.
Critical findings verified in PR #128.
Automated scan completed: 0 issues.
Unencrypted bucket detected in STAGE.
Always-on coverage
Schedule recurring tests, watch runner health, and track automation activity over time.
Global connect
Native support for the tools your security and engineering teams live in.
Continuous control mapping
Null-Ai continuously maps offshore execution telemetry and vulnerability findings directly to active compliance controls.
This compliance mapping is in active development and testing. The frameworks, controls, and readiness shown here are illustrative samples — not a live audit of your environment.
SOC 2 Type II
Continuous automated offensive vulnerability scans mapping directly to CC7 security controls with complete log trails.
Agent tests container credential boundaries and RBAC mapping.
Autonomous scans verify VPC ingress/egress policies and WAF rules.
CRITICAL: Port 22 open directly to public gateway on stage-runner-01.
Splunk integration connection waiting for event log ingestion handshake.
Select the plan built for your scope
Start testing public boundaries instantly, expand test cycles, and deploy secure Private Runner networks when needed.
Starter
Basic boundary scans.
- 100 credits/month
- 1 concurrent runs
- 1 active scopes
Plus
Ideal for fast-growth applications.
- 5,000 credits/month
- 2 concurrent runs
- 1 active scopes
Pro
Complete offensive vulnerability pipeline.
- 50,000 credits/month
- Scheduled Automations
- Internal Node Execution
- Alert integrations
- 3 concurrent runs
- 5 active scopes
Enterprise
Tailored scope, private runners & high capacity.
- Custom credit pool
- Custom run capacity
- Custom scope limits
- Alert integrations
- 24h support
Request a pentest scope review
Share your details and we'll get back to you to confirm scope, schedule, and testing windows.
Pricing & Scope FAQ
Common questions regarding deployments
Latest from the blog
Security thinking from the latest release.
Read the newest NullSquare field note, or open the full blog for more articles on AI security, continuous testing, release gates, and attack surface coverage.

The Fable ban is really a scope-control warning
Anthropic Fable 5 showed the hard truth of frontier AI safety: stronger coding and bug-finding models are also stronger cyber systems.