Autonomous pentesting · Sovereign AI · On-premise · Air-gap ready

An autonomous AI red team for your network, on hardware you own.

Autonomous penetration testing for networks and infrastructure: Zero Hunt attacks your environment the way a skilled adversary would, proves every finding with evidence, and walks your team through the fix — continuously, on its own AI models, with a human in the loop, and without your data ever leaving your network.

specialist AI agents
10
validated attack skills
142+
compliance frameworks worldwide
34
calls to an external LLM
0
Zero Hunt Operations Center: quick actions to launch an autonomous red-team campaign, recon or traffic intercept, with 737 findings and 573,467 CVEs indexed
Operations Center — the console your team works in, served from the appliance.
The problem

Annual tests, signatures and spreadsheets cannot keep pace.

Attackers now use AI to find and weaponize weaknesses in hours. A yearly pentest, rule-based detection and hand-built compliance evidence describe last quarter's network, not today's.

A pentest is a snapshot

By the time the report arrives, the environment has changed: new assets, new vulnerabilities, new misconfigurations. Exposure has to be validated continuously — and proven, not estimated from a CVSS score.

Signatures only catch what is already known

Rule-based SIEM and NDR tools match known patterns. Novel command-and-control, living-off-the-land techniques and encrypted exfiltration pass underneath them.

Compliance evidence is assembled by hand

NIS2, DORA, ISO 27001, SOC 2, NIST, HIPAA, CMMC — regulators and auditors increasingly want continuous, signed evidence, not a binder assembled once a year.

The platform

Four capabilities, one appliance

Autonomous offensive testing, AI traffic analysis, continuous compliance evidence and AI-guided remediation, running together on private AI inside your perimeter — from proven finding to verified fix.

Zero Hunt agent status with Pause and Kill controls above the live campaign feed of sandboxed exploit runs

Agent status with pause and kill controls, and the live campaign feed — the operator stays in charge.

01

AI Generative Pentest

An autonomous red team, running continuously

Zero Hunt deploys a swarm of 10 specialist AI agents that autonomously discover, plan, and execute attacks against your infrastructure. The generative engine writes custom exploit scripts in real-time — not from a static database, but crafted specifically for your environment.

10-Agent AI Swarm

Recon, Vulnerability, Exploit, Web, Credential, Post-Exploit, Pivot, Tactic, Source Analyst and Report — coordinated by an AI Controller

Generative Exploits

LLM-powered code generation creates novel attack scripts for each target, not copy-paste from ExploitDB

142+ Self-Evolving Skills

AI Gym automatically evolves, tests, and backtests new exploitation techniques

Zero-Day Detection

Novelty validation engine identifies previously unknown vulnerabilities via CVE lookup + semantic similarity + LLM analysis

Recursive Pivoting

Compromised hosts become launch pads — the system automatically maps lateral movement paths

Isolated Sandbox Execution

Every exploit runs in a disposable Docker container, optionally hardened with gVisor, and only inside the approved scope and autonomy level

Zero Hunt traffic analysis: 3D globe with live flow arcs from the appliance, threat classification legend and traffic timeline

AI Traffic Analysis — 3D Threat Globe with real-time flow visualization

02

AI Traffic Analysis

Deep-Packet ML Intelligence at Wire Speed

A proprietary deep-learning architecture trained on billions of real-world PCAP sequences, running in real-time directly on the appliance GPU. Four parallel inference heads see what signature-based tools miss: novel C2 channels, encrypted malware beacons, ransomware staging patterns, data exfiltration, and anomalous lateral movement — without ever sending a packet to the cloud.

Proprietary AI Traffic Model

Deep-learning architecture trained on billions of labeled PCAP sequences — 4 inference heads: suspicious traffic, malware classification, attack type identification, application fingerprinting

Real-Time GPU Inference

Runs directly on the appliance GPU — no cloud, no external API calls. Every packet is classified as it traverses your network

2.7+ Gbit/s Baseline Throughput

On standard GPU-accelerated hardware — scales upward with higher-tier accelerators, no performance impact on production traffic

Ransomware Detection

Behavioral analysis detects encryption-stage traffic patterns before files are locked

C2 Channel Detection

Identifies covert command-and-control traffic even over HTTPS, DNS tunneling, and domain fronting

Multi-Subnet Sensors

Deploy sensors across network segments for complete visibility, including OT/ICS networks

3D Threat Globe

Real-time geospatial visualization of traffic flows with threat correlation and ISP attribution

Zero Hunt Compliance Hub showing 34 frameworks, an 85% average score, ten market segments and the framework list

Compliance Hub — 34 frameworks, market segments, continuous gap analysis

03

Automatic Compliance

Continuous Assessment Across 34 Frameworks Worldwide

Zero Hunt automatically maps every finding, configuration, and evidence artifact to the compliance frameworks that matter to your business. NIS2, DORA, ISO 27001, SOC 2, PCI DSS, HIPAA, NIST CSF — all assessed continuously, not once a year.

34 Frameworks Covered

NIS2, DORA, TIBER-EU, ISO 27001, SOC 2, PCI DSS, NIST CSF, NIST 800-53, CMMC, HIPAA, NYDFS Part 500, GLBA, SEC rules, CBEST, MAS TRM, Saudi NCA and 18 more — EU, US, UK, APAC, Middle East

Continuous Gap Analysis

Real-time control assessment with weighted scoring — not a checkbox once a year

Auto-Evidence Collection

Every scan, finding, and remediation is automatically mapped as compliance evidence

ECDSA-Signed Reports

Cryptographically signed PDF reports with full chain-of-custody for auditors

Remediation Tracking

Automated remediation tasks with priority scoring tied to compliance impact

Cross-Framework Mapping

One control satisfies multiple frameworks — reduce redundant audit work by up to 70%

PRIORITIZED PLAN
P1EXPLOITED

Unauth RCE · web-01 :8080

P2VERIFIED

SSH weak creds · 10.0.4.12

P3VERIFIED

Exposed admin panel · db-02

How do I remediate the RCE on web-01 first?

reading evidence + KB…

Confirmed exploitable via the deserialization sink.

Patch to 2.4.6, drop :8080 at the edge, rotate the leaked token. Want the hardening script?

grounded · 3 KB sources

Remediation Advisor — prioritized fix plan + agentic chat grounded on the internal KB

04

AI Remediation Advisor

An Agentic Chat That Fixes, Not Just Finds

Finding the vulnerability is half the job. Zero Hunt closes the loop with an agentic advisor that turns a campaign's findings into a prioritized, step-by-step fix plan — then lets your team chat through each remediation in depth. Every answer is grounded on an internal knowledge base of exploitation techniques, CVE intelligence, and the engine's own evidence, so the guidance is specific to what was actually proven exploitable on your estate.

Priority-First Fix Plan

Findings are ranked by real, demonstrated risk — exploited and verified first — so your team fixes what matters before what's merely theoretical

Agentic Remediation Chat

A conversational AI that reasons over the campaign, pulls in the evidence it needs on demand, and walks you through each fix interactively — not a static report

Grounded on an Internal KB

Every recommendation is RAG-anchored to a curated knowledge base of attack techniques, CVE intelligence, and the engine's own findings — no generic, hallucinated advice

Confirmed-Only by Design

Remediation covers only findings proven exploitable (verified / exploited). Unconfirmed noise is excluded, so effort goes where the risk is real

On-Demand Fix Scripts

Ask the advisor to generate ready-to-run remediation and hardening scripts tailored to the specific finding and your environment

Campaign-Scoped Context

Each advisor session is bound to its campaign — the AI always knows exactly which hosts, services, and findings it is reasoning about

New — Generative Zero-Day PoC

From the vulnerable line of code to a proof of concept that runs.

A scanner compares signatures. Even most "AI" tools generate one script and stop there. Zero Hunt reads the exact version of the software you are actually running, finds the weakness in its source — including the ones no CVE catalog lists — and then keeps working the exploit, turn after turn, until it fires against your system for real.

How the proof gets built

01

Version-exact identification

It fingerprints the product AND the precise version you run — from generator metadata, headers, paths and JavaScript — then fetches that version of the source, from the public repository or from your own source mirror. Not the latest one, which may already be patched.

02

The weakness in the source

A taint scan follows request input to the sinks it can reach: SQL, command execution, path traversal, SSRF, deserialization, unauthenticated upload and actions. What comes back is the request shape — the action, the parameters, the handler — not a vulnerability name.

03

The Exploit Forge

A sealed container stays open while a coding agent writes the proof-of-concept, runs it against the target, reads what actually came back, corrects it and runs it again — stopping the moment the exploit demonstrably works.

What you get is not an opinion

A runnable proof-of-concept, filed against the campaign, alongside the before-and-after evidence of what it did. Not "you may be vulnerable" — this is the request, this is the effect it had, run it yourself.

The proof is also the fix

The same PoC is readable by the operator in chat and by the AI Remediation Advisor, because it names the exact request, parameter and source line the weakness lives on. No advisory describes a fix as precisely as the exploit that broke it.

Why the forge cannot be turned against you

No thread to your systems

The forge has no access to the host it runs on. Your files, your keys and the operator network simply do not exist inside it.

Injection neutralized, not hoped away

Every piece of downloaded source and every target response is sealed and labeled as data before the AI sees it. A booby-trapped comment is treated as evidence, never as an instruction.

No way out

It sits on a network with no route to the internet. It can reach the target under test and the reasoning model — nothing else. There is no channel to send a byte anywhere it should not go.

Least privilege, hard ceilings

Stripped of every system capability, unable to escalate, under fixed memory, CPU and process limits — and destroyed the instant the work is done.

This is the difference between a demo and something you can put inside a bank: the generative power of an AI that writes exploits, wrapped in a containment model designed by people who assume the code under examination is hostile — because it is.

Human in the loop

Autonomous when you want it. Supervised when it matters.

Every campaign runs at an autonomy level you choose, and collaborative mode can also pause it at the decision points you pick — before exploitation, pivoting or planning — until an operator approves, denies or redirects. Anything outside the chosen level waits for a person, and every approval, action and verdict is recorded.

  1. 1

    Observe

    Passive only; any active scan needs approval.

  2. 2

    Light

    Scanning; exploitation and credential tests need approval.

  3. 3

    Standard

    Credential testing; exploitation and availability tests need approval.

  4. 4

    High

    Exploit verification; availability tests need approval.

  5. 5

    Full

    Full assessment in a scheduled window, chosen explicitly.

Review before anything risky runs

A proof of concept the level does not allow goes to a review tab. Running it takes recorded consent, a fresh scope check, a per-script permission and a lock on the host.

A signed record of who did what

Every execution — by an agent or an operator — writes a signed row with its identity, target and outcome, and lands in the evidence chain.

A stop control that works

Operators can pause or stop a campaign at any time, and the final verdict on every finding is theirs.

Black box or gray box, by design

Campaigns start black-box — no credentials, no source. Gray-box adds authenticated testing and source-informed analysis when you provide them.

Human-in-the-loop in AI security testing →

Our Philosophy

An AI Team That Lives Inside Your Walls.

Zero Hunt is not a cloud service. It is an AI security team that runs entirely inside your perimeter — on your hardware, on your network, on private AI, under your control. No customer data goes to a third party, nobody outside can switch it off, and the cost does not grow with every token the agents use.

Zero Hunt — Inside the Perimeter
Runs on-premise, on your own appliance — nothing leaves your network
A resident AI team that knows your infrastructure intimately, every day
No third-party operators, no shared SaaS tenancy, no data exhaust to the cloud
Trust boundary = your boundary. You own the hardware, the data, and the findings
Always present, continuously assessing — not parachuting in for a one-week engagement
External Cloud Services & Outside Teams
Your traffic, credentials and findings sent to someone else's cloud
External consultants you must onboard, trust, and grant deep access to
A point-in-time snapshot that is stale before the report is delivered
Black-box vendor: you can't see what they store or how long they keep it
You depend on people and infrastructure outside your control

Same intelligence as the best external red team — but it lives with you, answers only to you, and never leaves the building.

Why on-premise and private AI: data, control, cost — and who has to →

We Build Our Own AI — We Don't Rent It

Powered by ZeroHunt Apex

Zero Hunt runs on ZeroHunt Apex — our own family of sovereign offensive-AI models, fine-tuned in-house on real exploit intelligence and executed 100% inside your perimeter. While other vendors wrap third-party cloud LLMs that refuse offensive work and send your data outside, we own the weights. Two tiers, the same red-team brain: choose efficiency or maximum capability.

Flagship

ZeroHunt Apex

27B

On-Premise Flagship

The red-team model that runs inside your perimeter.

A 27-billion-parameter model fine-tuned for autonomous offensive security. Compact enough to run entirely on-premise — air-gappable, no data ever leaves your network — yet trained to reason across the full attack kill-chain.

27B parameters · on-premise, air-gappable
Runs on a single GPU appliance — zero cloud dependency
Powers live campaigns: recon → exploit → privesc → post-ex

ZeroHunt Apex Pro

284B

Maximum Capability

Frontier-scale reasoning for the hardest targets.

A 284-billion-parameter model for the most demanding engagements. Deeper multi-step reasoning, broader exploit coverage and stronger novel-vulnerability discovery — for higher-tier appliances and sovereign private-cloud deployments.

284B parameters · same curated red-team training
Deeper chaining & novel zero-day discovery
For higher-tier appliances / sovereign private cloud
Why owning the model changes everything

A security tool on rented AI inherits someone else's rules

Most "AI security" products call a third-party cloud LLM. Your data leaves on every call, the provider decides what the model will and will not do, and the bill grows per token. Owning the models removes all three constraints.

Others — static tools + third-party cloud LLM

Wrap OpenAI / Anthropic / Google cloud APIs — your data leaves the perimeter on every call
General-purpose models refuse offensive tasks ("I can't help with that") — the red team hits a wall
Vendor lock-in: rate limits, price hikes, deprecations and outages you don't control
Static signature/playbook databases — no novel exploits, no adaptation to your environment
Incompatible with air-gapped, NIS2 / DORA sovereign deployments

ZeroHunt Apex — models we fine-tuned and own

Runs entirely on-premise — air-gappable, zero data egress, sovereign by design
Built for authorized offensive security: it runs the tests you have approved, inside the scope and autonomy level you set
We own the weights: no per-token cost, no vendor lock, no kill-switch over your operations
Generative & self-evolving — writes novel exploits and improves continuously via the AI Gym
Two tiers (27B on-prem / 284B max-capability) we can tune, ship and harden on our own roadmap

Trained on curated offensive intelligence — not scraped text

A proprietary, hand-curated corpus

Both models share the same training foundation: a proprietary corpus of ~130,000 high-signal offensive-security examples, assembled from a dozen-plus independent streams and refined through a rigorous data pipeline.

~130,000 curated examples
Over 145,000 raw examples collected, then reduced via near-duplicate removal (MinHash) — variety, not repetition.
Verified quality
Deterministic + LLM-judged filters strip refusals, truncation and templated boilerplate. Uniqueness is measured on the answer body, so semantic filler never reaches training.
Grounded in reality
Derived from real exploit code, live CVE intelligence, detection rules, attacker tooling and battle-tested red-team methodology — not generic synthetic chatter.
Full kill-chain coverage
Reconnaissance, web exploitation, privilege escalation, payload construction, post-exploitation, threat intelligence and exploit-script coding.
Eval-clean
Decontaminated against every benchmark we test on, so our internal evaluations measure skill, not memorization.
Hardware + Software, Delivered On-Premise

A Complete Security Appliance

Zero Hunt is not just software — it's a purpose-built appliance combining dedicated AI hardware and a pre-configured security platform. You rack it, connect it to your network, and it immediately becomes an autonomous member of your security team. Nothing leaves your perimeter.

Zero Hunt desktop appliance: a compact tower unit with a Zero Hunt badge on the front grille, standing in a security operations room
Form factor 01

Desktop appliance

For branch offices, single sites and smaller organizations. Arrives pre-configured and hardened: power it on, authorize a scope, and the red team starts working.

Zero Hunt 2U rack appliance: a black rack-mount server with the Zero Hunt logo on the lid and front panel and red-lit handles
Form factor 02

2U rack appliance

For enterprises, data centers and multi-site perimeters. Higher-tier GPUs for wire-speed traffic analysis and more campaigns running at the same time.

Same software on both units. Air-gapped deployment is supported on either.

Dedicated AI Hardware

GPU-accelerated inference

Ships with dedicated GPU accelerators running our proprietary traffic-analysis model (trained on billions of PCAP sequences) and LLM-driven exploit generation — baseline 2.7+ Gbit/s, scaling with higher-tier hardware.

On-Premise Only

Your network, your data

No customer data leaves the appliance and no external LLM API is involved. Connected, it only fetches signed updates, public threat intelligence and, for gray-box analysis, published source code; in air-gap mode nothing goes out at all — the mode classified and regulated environments use.

Pre-Configured Software Stack

Zero-touch deployment

FastAPI backend, React dashboard, PostgreSQL + pgvector, Redis, sandboxed Docker execution — all baked in. Plug it in, onboard your network, start hunting.

Sandboxed Execution

Isolated by design

Every exploit runs in an ephemeral Docker container with optional gVisor hardening. The appliance itself is hardened — the attacks never touch the host OS.

01

Ship

Appliance arrives pre-configured and hardened

02

Rack

Install in your datacenter, connect to the network

03

Hunt

Autonomous security operations begin immediately

Continuous DAST — Inside & Public-Facing

Your Internal Surface and Everything You Expose to the World.

Zero Hunt's first job is continuous assessment of the infrastructure inside your perimeter. But your attack surface doesn't stop at the firewall. The same resident AI team can drive full dynamic application security testing (DAST) against the public endpoints, web apps, APIs and appliances you expose to the internet — including assets you run on public cloud.

Internal Integrity

Always-on validation of the infrastructure inside your perimeter — the continuous assessment that keeps your network honest, day after day.

Public-Facing Coverage

On demand, the same engine pivots outward to test the web apps, portals, APIs and appliances you publish to the internet — the surface real attackers actually reach first.

What the DAST Engine Does

Authenticated Testing

Drives real login flows and reuses the session, so it tests the app as a logged-in user — not just the public shell.

Cloud Provider Fingerprinting

Passively detects where an endpoint actually lives — AWS, Azure, Alibaba Cloud, GCP — and adapts the assessment profile accordingly.

API & OpenAPI Ingestion

Parses your API specs and exercises each endpoint with injection, IDOR and auth-bypass probes instead of testing blind.

Web App Exploitation

25+ web exploit skills: injection, IDOR, open redirect, CORS, security-header and misconfiguration testing on live targets.

Appliance & Edge Testing

Probes the gateways, VPN portals and management consoles you expose at the edge — the appliances attackers love.

Same Trust Boundary

It is still your own internal AI team reaching outward — not an outsourced cloud scanner with a copy of your data.

Tests endpoints on
AWSMicrosoft AzureAlibaba CloudGoogle CloudCustomer VMsOn-Prem Edge

This is not a "public-only pentest" service like the cloud tools or external hacking teams you can never fully trust. It is the AI team that already lives inside your walls — now also watching the doors you leave open to the outside world.

Market Comparison

How Zero Hunt compares with the tools buyers shortlist

Side by side with automated pentesting, network detection, compliance platforms and scanners. The difference is architectural: one on-premise appliance on private AI instead of several cloud services.

AI Generative Penetration Testing
ZERO HUNT
Pentera
Darktrace
Vanta
Rapid7
AI-Powered Network Traffic Analysis
ZERO HUNT
Pentera
Darktrace
Vanta
Rapid7
Automated Compliance (34 Frameworks)
ZERO HUNT
Pentera
Darktrace
Vanta
Rapid7
Unified Offense + Defense + Compliance
ZERO HUNT
Pentera
Darktrace
Vanta
Rapid7
Autonomous 24/7 Multi-Agent Operation
ZERO HUNT
Pentera
Darktrace
Vanta
Rapid7
Self-Evolving AI Skills (AI Gym)
ZERO HUNT
Pentera
Darktrace
Vanta
Rapid7
Zero-Day Discovery & Validation
ZERO HUNT
Pentera
Darktrace
Vanta
Rapid7
Agentic AI Remediation Advisor (Prioritized)
ZERO HUNT
Pentera
Darktrace
Vanta
Rapid7
Offense → Defense → Compliance → Fix Loop
ZERO HUNT
Pentera
Darktrace
Vanta
Rapid7
On-Premise / Full Air-Gap Deployment
ZERO HUNT
Pentera
Darktrace
Vanta
Rapid7
Single Platform, No Tool Sprawl
ZERO HUNT
Pentera
Darktrace
Vanta
Rapid7

Key insight: Pentera does automated pentesting. Darktrace does network detection. Vanta does compliance. None combines all four — let alone an agentic advisor that walks your team through the fix. Zero Hunt puts autonomous offensive security, AI traffic intelligence, continuous compliance and AI-guided remediation on one on-premise appliance, on private AI.

Based on publicly available product documentation, reviewed September 2026.

Want a deeper head-to-head?

Pick the comparison that matches the tool you are evaluating today.

Threat intelligence

21 intelligence sources, kept current on the appliance

Every campaign starts from current vulnerability, exploit and technique data, synced from the public sources below — or imported as offline update bundles when the appliance runs air-gapped. Nothing about your environment goes the other way.

Vulnerabilities

  • NVD — NIST National Vulnerability Database
  • MITRE CVE — CVE list
  • CISA KEV — Known exploited vulnerabilities
  • OSV — Open-source package advisories
  • VulnCheck — Exploit maturity ratings
  • EPSS — Exploit prediction scores

Exploits and proofs of concept

  • Exploit-DB — Public exploit archive
  • GitHub PoC — Proof-of-concept repositories
  • Metasploit — Exploit module index
  • Nuclei — Community detection templates

Techniques and detection

  • MITRE ATT&CK — Enterprise, Mobile, ICS
  • CAPEC — Attack patterns
  • Atomic Red Team — Detection tests
  • Sigma — Detection rules
  • GTFOBins · LOLBAS — Living-off-the-land binaries

Enrichment

  • NIST CPE — Software identification
  • SecLists — Default credentials
  • HIBP — Breached-password hash ranges, cached locally
  • Fingerbank — Device fingerprints
  • MaxMind GeoIP — IP geolocation

Also on the appliance: AI Gym: skills tested and evolved against vulnerable labs · Mobile assessment lab for iOS and Android · Knowledge base recalling every past run · Red Team Chat · Scheduled campaigns · Trust Center evidence portal.

Frequently Asked

What CISOs actually ask

The questions we hear most often on a first technical call — deployment, private AI, cost, control and compliance.

Is Zero Hunt really on-premise, or does it phone home?

Truly on-premise. The full stack — the AI models, embeddings, traffic model, evidence store and console — runs on the appliance inside your perimeter. No customer data leaves it, and there are no external LLM API calls. When connected, the appliance makes outbound requests only to fetch signed product updates, public threat intelligence (NVD, CISA KEV, EPSS and similar feeds) and, for gray-box analysis, the published source of the software version under test — which you can switch off or point at your own source mirror. Update-status reporting (release ID, status, timestamp) is opt-in. In air-gap mode nothing goes out: updates arrive as signed offline bundles and intelligence as offline imports.

What is private AI, and why does it matter for an AI red team?

Private AI means the models run on infrastructure you control. Zero Hunt runs its own models — ZeroHunt Apex (27B) on the appliance GPU, Apex Pro (284B) for higher-tier and sovereign deployments. An AI red team handles network maps, unpatched weaknesses and recovered credentials: with private AI none of it reaches a third party, and no external provider can refuse, throttle, change or switch off the capability your defense depends on.

How does the cost compare with AI tools billed per token?

Agentic security testing is token-hungry: an autonomous campaign makes thousands of model calls, each with thousands of tokens of context, so metered AI gets more expensive the harder and longer it works. On the appliance the models run on hardware you own: a flat cost, 24/7, whether you run one campaign or a hundred.

How is the generative pentest engine different from a tool that runs Nuclei or Metasploit?

Tools like Nuclei and Metasploit execute curated modules from a static library. Zero Hunt's agents write new exploit code for each target with local models and validate every new skill in a sealed AI Gym (Vulhub, NYU CTF Bench, Cybench) before it reaches production — and, where authorized, turn a weakness found in the source of the exact version you run into a runnable proof of concept.

Is there a human in the loop?

Yes, as much as you want. Campaigns run at one of five autonomy levels, from passive observation to full assessment in planned windows; each level defines what waits for human approval. Actions outside the chosen level go to a review tab with recorded consent and a signed audit trail, operators can pause or stop any campaign, and the final verdict on every finding is theirs.

Does it test black-box or gray-box?

Both. Campaigns are black-box by default: no credentials, no source, only what your systems reveal. Gray-box adds authenticated testing with credentials you provide and source-informed analysis of the exact software version you run.

Which compliance frameworks are mapped out of the box — is it only for EU rules?

No. 34 frameworks across the EU, the US, the UK, Canada, Asia-Pacific, the Middle East, Latin America and Africa: NIS2, DORA and TIBER-EU; NIST CSF, NIST SP 800-53, CMMC, HIPAA, NYDFS Part 500, SOX and SEC rules; CBEST and the NCSC CAF; MAS TRM, APRA CPS 234 and RBI; Saudi NCA, UAE IA and Qatar NCSA; plus ISO 27001, SOC 2, PCI DSS, SWIFT CSP and CIS. Findings, scans and remediation are mapped automatically with cross-framework control deduplication, every record is signed at write time, and exported reports are ECDSA-signed.

What hardware does the appliance require?

It ships as a dedicated GPU appliance, pre-configured and hardened — a desktop unit for smaller sites and a 2U rack for enterprises and data centers. The baseline configuration delivers 2.7+ Gbit/s of AI traffic inference alongside the offensive engine; higher-tier GPUs scale throughput. You rack it, connect it to the segments you want covered, and run the onboarding wizard.

Does it work air-gapped?

Yes. Air-gap is a first-class deployment mode: no outbound connections; engine updates arrive as signed images loaded offline, and intelligence as offline bundle imports. Two capabilities depend on the internet and are switched off there: public-OSINT reconnaissance and downloading published source code for gray-box analysis, so those assessments run black-box. Networks that keep the appliance off the internet but give it access to their own source mirrors (GitHub Enterprise, GitLab, an artifact server) keep source-informed testing. It is designed for regulated and classified environments where vendor-cloud touch points are excluded by policy.

How does Zero Hunt fit into an existing SOC?

Two integration points. Findings, alerts and signed evidence flow out via REST, WebSocket and webhooks into your SIEM, SOAR, EDR or GRC. And the interactive Red Team chat lets a senior operator drive targeted tests on specific hypotheses in natural language, without repeating the reconnaissance the engine has already done.

Next step

See the red team work on your own infrastructure.

A 30-minute call to map your environment, regulations and deployment constraints — then a guided demo of the platform. On-premise, on private AI, with a human in the loop.

  • On-premise
  • Air-gap capable
  • Private AI — no external LLM API
  • Human in the loop