What 250 million dollars just bought

Horizon3 closed a 250 million dollar Series E at a valuation above 2 billion dollars, having raised 100 million at roughly 650 million in May 2025. NightDragon and NEA, both existing backers, co-led. The new names span an unusual range for a security round: Acrew, Blue Cloud Ventures, Demeter Group, PSG Equity and Sapphire alongside Singapore's state-linked EDBI and SAIC Ventures, the venture arm of the American defence contractor, with Craft Ventures, Qualcomm Ventures, Ridge Ventures and SignalFire returning. The company is approaching 100 million dollars in annual recurring revenue with 120 percent year-on-year growth and counts roughly 7,200 customers, from managed service providers to Fortune 10 enterprises.

The product is NodeZero, which the company markets as autonomous penetration testing and describes in-house as AI hackers. Founders Snehal Antani and Anthony Pillitiere came out of Joint Special Operations Command, and the pitch carries that lineage: rather than hiring a consultancy to attack a defined scope for two weeks, you run an attacker continuously against everything. Horizon3 says it has spent around 100 million dollars on research and development building automated systems designed to stay predictable and controllable, which is a revealing thing to have to say about your own product.

The coverage argument is the strong one

Matt Hartley, the company's chief revenue officer, makes the comparison in terms that are hard to argue with. A conventional penetration test examines 2 to 3 percent of a network, once. NodeZero scans the whole infrastructure continuously. Anyone who has commissioned an annual test knows the shape of the problem: you pay for a scoped engagement, the scope is negotiated down to what fits the budget and the window, and the report describes the state of a subset of your estate on a fortnight that ended before the findings were written up.

Continuous testing against the real environment fixes a genuine defect, and it is the reason this category is growing rather than a marketing conceit. Hartley's second claim is the load-bearing one: the platform can test live systems without shutting down operations. That is the capability the whole proposition rests on, because a tool that occasionally takes production down is not a tool anybody runs continuously, however good its coverage.

310,000 tests, and who counted them

The evidence offered for that safety claim is 310,000 production security tests with zero disruptions. It is a substantial number and there is no reason to think it false. It is also, unavoidably, the vendor counting its own outcomes against its own definition of what counts as a disruption, and those two facts sit together without contradiction. A test that briefly degraded a service, or that triggered an alert someone spent an hour clearing, may or may not be inside that denominator depending on a definition nobody outside the company has seen.

The practical instruction is small and worth following. When that figure reaches a board paper or a risk committee, it should arrive labelled as a supplier statistic rather than an independent finding, and the procurement conversation should ask what the company classes as a disruption and whether customers can see their own incident counts. A vendor confident in the number will answer both without difficulty. The answer also gives you something to hold the contract against later, which a headline figure never does.

The question is authorisation, not efficacy

The decision this round should prompt is not whether autonomous testing works. It is who authorised the action. A traditional engagement produces a signed rules-of-engagement document naming a scope, a window and a human being who approved both. A continuously running agent produces findings, and the approval that covers it was given once, at procurement, for a class of activity rather than an act. Most organisations' change-control processes were written for the first model and have not been revisited for the second.

That gap becomes concrete under European operational-resilience expectations, where an institution has to be able to reconstruct who did what in a production system and under whose authority. The workable answer is not to avoid the tooling, which would be a poor trade for the coverage it buys. It is to write the authorisation down before deployment: which systems the agent may touch, what it may not do without a fresh human decision, who holds that decision, and how an action taken at three in the morning is reconstructed six months later. Horizon3 opened its Amsterdam office in June and is spending this round on EMEA, so European buyers will face that question inside the current budget cycle.