Private AI · On-premise · Human in the loop

An on-premise AI red team, running on private AI.

Zero Hunt is an autonomous AI red team that runs entirely on hardware you own: its own models on its own GPU, inside your perimeter. Your data never reaches a third party, no outside provider can switch it off or change what it does, and the cost is flat — the same whether it works one hour or around the clock. People set the scope and approve every action that matters.

Three reasons an AI red team has to run on your premises

01

Your data never reaches a third party

An AI red team works with the most sensitive material you have: network maps, unpatched weaknesses, recovered credentials, proof that a system can be compromised. With a cloud AI service, all of it crosses your perimeter on every model call and is processed under another company's jurisdiction and retention rules. On the appliance, the models, the evidence store and the console run locally — no cloud callbacks, no telemetry, air-gap supported.

02

Nobody outside can switch it off or tamper with it

A cloud AI provider can change its usage policy (general-purpose models routinely refuse offensive-security work), throttle you, retire the model you depend on, suspend the account, suffer an outage, or be compelled by the law of its own country. For the capability that tests your defences, that is a dependency you cannot accept. On-premise you own the hardware and run the weights locally; signed updates are applied when you decide — offline, in air-gapped sites.

03

Cost you can plan: flat, 24/7, no per-token meter

Agentic AI is token-hungry. An autonomous campaign is thousands of model calls — reconnaissance, planning, writing and retrying code, verification, reporting — each carrying thousands of tokens of context. Billed per token, the bill grows with every hour the AI works, and the behaviour you want most (continuous, exhaustive, retrying until it has proof) is the most expensive. On-premise the cost is the appliance: the same for one campaign or a hundred, office hours or around the clock.

Private AI: our own models, not a wrapper around someone else's

Zero Hunt runs on ZeroHunt Apex, our own family of models fine-tuned for authorised offensive security: Apex (27B parameters) on the appliance GPU, and Apex Pro (284B) for higher-tier appliances and sovereign private-cloud deployments. There is no external inference endpoint in the loop and no per-token cost.

Because we own the weights, the red team does not stop at a refusal, does not change behaviour when a provider updates a model, and keeps working with the internet cable unplugged.

What private AI means in cybersecurity →

Autonomous — with a human in the loop

Every campaign runs at one of five autonomy levels, from passive observation only to full assessment reserved for planned maintenance windows. Each level defines what the agents may do on their own and what waits for a person: at the lowest level any active scan needs approval, intermediate levels require approval for exploitation, credential and availability tests, and only the highest level — chosen explicitly — runs without approval gates inside its scope.

When the engine wants to run a proof of concept that the campaign level does not allow, it does not run it. It places it in a review tab, where execution requires a recorded consent, a fresh scope check, a per-script permission, a lock on the host and a signed record of who approved it. Operators can pause or stop any campaign, and the final verdict on every finding is theirs.

Human-in-the-loop in AI security testing →

Black box and gray box, the way real attackers work

Black box

The default. The engine starts from the authorised scope with no credentials and no source — only what your systems reveal, like an external or unauthenticated attacker.

Gray box: authenticated

With credentials you provide, it drives real login flows and tests web applications and APIs as a signed-in user would.

Gray box: source-informed

It identifies the exact version of the software you run, studies that version's source and validates a finding with a proof of concept — the Generative Zero-Day PoC.

Black-box vs gray-box penetration testing →

Who has to run it on-premise

For some organisations on-premise is a regulatory requirement; for others it is the only defensible strategic choice. Typical cases, worldwide:

  • Governments, ministries and public administration

    National-security and data-classification rules — such as Italy's national cybersecurity perimeter, NIST SP 800-53 / FedRAMP in the US and the national frameworks of Saudi Arabia, the UAE and Qatar — and the principle that the tools defending the state must stay under its control.

  • Defence, armed forces, intelligence and the defence industrial base

    Classified and controlled information (CMMC for US defence suppliers, national accreditation regimes in Europe and the Gulf) and networks that are air-gapped by rule.

  • Critical infrastructure: energy, water, transport, telecom, digital infrastructure

    NIS2 essential entities in the EU, the NCSC Cyber Assessment Framework in the UK, national CI frameworks elsewhere — plus OT networks that are deliberately isolated.

  • Banks, insurers, payment and market infrastructure

    ICT third-party and concentration risk under DORA and threat-led testing under TIBER-EU in the EU; CBEST in the UK; NYDFS Part 500 in New York; MAS TRM in Singapore; APRA CPS 234 in Australia; OSFI B-13 in Canada.

  • Hospitals, healthcare and life sciences

    Special categories of personal data under GDPR Art. 9, HIPAA business-associate obligations in the US, and hospitals classed as essential entities under NIS2.

  • Manufacturing, industry and OT

    Trade secrets and IP, air-gapped plant networks, and defence supply-chain obligations such as CMMC.

  • Law firms, consultancies and professional services

    Legal privilege and client confidentiality that cannot be shared with an external AI provider.

  • Managed security service providers (MSSPs)

    Client findings cannot be pooled in a shared third-party AI; each client's evidence has to stay segregated and under contractual control.

  • Listed companies and large enterprises

    SEC cybersecurity disclosure and SOX in the US, board-level accountability everywhere — and security data that is market-sensitive.

What the rules actually require

Few regulations say "on-premise" in so many words. What they require is control over every third party that touches your security data: NIS2 Art. 21 (supply-chain security), DORA Chapter V (ICT third-party risk, concentration risk, exit strategies), GDPR Art. 28 and Chapter V (processors and international transfers), NYDFS Part 500 (third-party service providers), HIPAA (business associates), and the EU AI Act Art. 14 (human oversight of high-risk AI).

A cloud AI in your red team is one more third party to assess, contract, monitor and plan an exit from — for the most sensitive data you hold. Running the red team on-premise, on private AI, removes that third party instead of documenting it.

Compliance, worldwide

34 frameworks across 8 regions, mapped automatically

Every finding, piece of evidence and remediation is mapped to the frameworks your auditors, regulators and customers use — in the EU, the United States, the United Kingdom, Canada, Asia-Pacific, the Middle East, Latin America and Africa. The appliance runs on-premise wherever you operate; the evidence never leaves your jurisdiction.

Global / cross-industry
  • ISO/IEC 27001:2022
  • SOC 2
  • NIST Cybersecurity Framework
  • CIS Critical Security Controls v8
  • PCI DSS
  • SWIFT Customer Security Programme
  • OWASP ASVS
  • CSA STAR
European Union
  • NIS2 Directive
  • DORA
  • TIBER-EU
United States
  • NIST SP 800-53 / FedRAMP
  • CMMC
  • HIPAA Security Rule
  • NYDFS Part 500
  • GLBA / FTC Safeguards Rule
  • SOX IT controls
  • SEC cybersecurity disclosure rules
  • CCPA / CPRA cybersecurity audit
United Kingdom
  • CBEST / STAR-FS
  • NCSC Cyber Assessment Framework
Canada
  • OSFI Guideline B-13
Asia-Pacific
  • APRA CPS 234
  • MAS Technology Risk Management
  • Singapore Cybersecurity Act / PDPA
  • RBI Cybersecurity Framework
  • FISC Security Guidelines
  • Korea ISMS-P
Middle East
  • Saudi NCA ECC / SAMA CSF
  • UAE Information Assurance (NESA)
  • Qatar NCSA framework
  • Bank of Israel Directive 361
Latin America
  • Brazil LGPD
Africa
  • South Africa POPIA

Questions we hear about on-premise AI red teaming

What is an on-premise AI red team?

An autonomous AI red team whose models, agents, evidence and console all run on hardware inside your own network. It tests your infrastructure continuously the way an adversary would, and nothing it sees or produces leaves your perimeter.

What does private AI mean for a security tool?

That the AI models run on infrastructure you control, with no external AI API in the loop. Zero Hunt runs its own ZeroHunt Apex models on the appliance GPU: no cloud callbacks, no telemetry, and it works air-gapped.

Why not use a cloud AI service for autonomous pentesting?

Three reasons: your most sensitive data would leave the perimeter on every call; the provider could refuse, throttle, change or suspend the service your defence depends on; and per-token billing makes continuous, thorough testing expensive exactly when it is most useful.

How does the cost compare with per-token AI?

An autonomous campaign makes thousands of model calls, each with thousands of tokens of context, so metered AI costs grow with every hour of testing. On-premise the models run on the appliance you own: a flat cost, 24/7, however many campaigns you run.

Is there a human in the loop, or does it run on its own?

Both, by your choice. Five autonomy levels define what runs automatically and what waits for approval; actions outside the chosen level go to a review tab with recorded consent and a signed audit trail. Operators can pause or stop any campaign at any time.

Does it test black-box or gray-box?

Both. Campaigns are black-box by default — no credentials, no source. Gray-box adds authenticated testing with credentials you provide and source-informed analysis of the exact software version you run.

Can it run in an air-gapped network?

Yes. Air-gap is a first-class deployment mode: no external connectivity at runtime and updates delivered as signed offline bundles.

Keep the red team inside the walls it is testing

A 30-minute call is enough to see whether your environment, regulation and deployment constraints fit — desktop appliance for smaller sites, 2U rack for enterprises and data centres, air-gapped where required.