Horizon3.ai did complete the $100 million financing. TechCrunch reported on May 28, 2025, that the autonomous-penetration-testing company was seeking that amount and had secured at least $73 million in an SEC filing. On June 10, Horizon3.ai confirmed a completed $100 million Series D. The company’s financing story moved on again in August 2026, when it reportedly raised a $250 million Series E at a valuation above $2 billion.
What happened to the reported $100 million raise?
The original report was accurate as a snapshot of May 28, 2025, but it described a round that was still being assembled. TechCrunch said an SEC filing showed at least $73 million secured, that New Enterprise Associates (NEA) was leading, and that the final amount and valuation had not been independently verified. The report also cited approximately $30 million in annual recurring revenue and a possible valuation above $750 million; those figures came from sources familiar with the company rather than audited disclosures.
On June 10, 2025, Horizon3.ai announced that the financing had closed as a $100 million Series D. NEA led the round, with SignalFire, Craft Ventures and 9Yards Capital participating. Lila Tretikov of NEA joined the board. Horizon3.ai said the financing brought its total funding to $178.5 million. The company did not disclose a Series D valuation in its announcement.
Primary-source confirmation is available in Horizon3.ai’s announcement and the accompanying BusinessWire release.
#1 Best Overall
Horizon3.ai funding timeline
| Date | Event | What is established |
|---|---|---|
| June 8, 2021 | Earlier Series A | SpyVC lists an $8.5 million SignalFire-led round, based on secondary reporting: SpyVC. |
| May 28, 2025 | Proposed new financing | TechCrunch reported a target of $100 million and at least $73 million in an SEC filing: TechCrunch. |
| June 10, 2025 | Series D closed | $100 million completed; NEA led, with SignalFire, Craft Ventures and 9Yards Capital participating. Company-reported cumulative funding: $178.5 million. |
| March 19, 2026 | Operating update | Horizon3.ai reported 102% year-over-year ARR growth, 125% net dollar retention and more than 5,200 organizations using NodeZero: company release. |
| August 3, 2026 | Series E reported | SiliconANGLE reported a $250 million round at a valuation above $2 billion. NightDragon confirmed the financing and said it co-led with NEA. |
What Horizon3.ai sells
Horizon3.ai’s main product is NodeZero, an autonomous penetration-testing and proactive-security platform. In the company’s description, NodeZero performs controlled attacks, identifies exploitable attack paths, explains what an attacker could reach, recommends remediation and retests to verify fixes. It is intended to run repeatedly, including in production environments, without installing agents or disrupting systems—claims that remain vendor claims rather than independent certifications.
Coverage areas
- Internal and external network penetration testing
- Web-application testing
- Active Directory and identity attack paths
- Cloud environments
- Vulnerability and exposure validation
- Remediation verification
- Threat-actor intelligence and rapid-response capabilities
- Integrations with defensive tools, including Microsoft Defender features described in 2026 company material
This differs from a conventional vulnerability scanner. A scanner may report that software is exposed to a known weakness; an autonomous test attempts to establish whether a path can actually be exploited under the authorized conditions. That evidence can help a security team prioritize, but it does not prove that every attack path has been tested.
Why investors are funding autonomous security
Horizon3.ai positions continuous validation as an answer to the gap between periodic penetration tests and constantly changing infrastructure. The investment thesis is that security teams need repeatable evidence of exploitability, not just large lists of theoretical vulnerabilities, while AI-enabled attacks can operate at higher speed and scale.
NightDragon linked its Series E investment to an “AI-versus-AI” security environment and said NodeZero had safely run more than 310,000 autonomous penetration tests in live production. That count is investor- or company-reported and has not been independently audited. The category also promises to make some red-team expertise more scalable, although it does not eliminate the need for experienced human testers.
Recommended Free Tools
Business traction and the 2026 update
TechCrunch’s May 2025 report put Horizon3.ai at approximately $30 million in ARR, based on a source familiar with the company; this was not presented as audited financial information. In March 2026, Horizon3.ai reported 102% year-over-year ARR growth, 125% net dollar retention and more than 5,200 customer organizations.
SiliconANGLE reported after the Series E that NodeZero was used by more than 6,500 organizations. It said the new capital would fund sales expansion and entry into Australia and Singapore. NightDragon described the valuation as more than $2 billion and characterized the increase from the Series D valuation as roughly tripling in just over a year. Because the Series D valuation was not publicly disclosed in the company’s announcement, that comparison should be treated as the investor’s characterization rather than a precisely calculated multiple.
How the Series D money was supposed to be used
Horizon3.ai said the 2025 financing would fund product innovation, expansion into web-application penetration testing and vulnerability management, and “precision defense”—remediation support and tuning of defensive tools. The stated goal was to broaden autonomous security beyond recurring network tests.
What deployment involves
Horizon3.ai’s documentation says customers can begin through a sales engagement or the AWS Marketplace, register an account, sign in to the NodeZero portal, confirm network requirements, deploy a preconfigured OVA, validate the host and run an initial internal penetration test.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchA published documentation PDF lists these minimum NodeZero host requirements, which may vary by deployment type or later release:
Rank #4
- Ubuntu 20.04 LTS or later, or RHEL 9 or later
- At least two CPU cores; four recommended
- At least 4 GB RAM; 8 GB or more recommended for heavier workloads
- At least 40 GB free storage; 80 GB SSD preferred
- Stable internet connection and internal network access
- Git and Bash
- Docker 20.10 or later, or Podman 4 or later
Buyers should authorize every target, define boundaries, coordinate with the SOC and establish rollback procedures before testing production. Internal and identity tests may require credentials, so procurement should ask how those credentials are scoped, stored, rotated and isolated. Testing can also trigger EDR, SIEM and incident-response workflows. Horizon3.ai’s June 2026 release notes describe a redesigned Real-Time View intended to help analysts distinguish NodeZero activity from hostile activity.
Where autonomous pentesting stops
NodeZero can supplement a human-led program, but autonomous testing is not equivalent to a full red-team engagement. Human specialists may still be needed for:
- Novel exploit research and unusual protocols
- Business-logic flaws and complex application workflows
- Social engineering and physical security
- Safety-sensitive or highly bespoke environments
- Executive-level adversary emulation
Coverage also depends on scope and configuration. Cloud permissions, SaaS services, segmented networks and proprietary systems may require separate methods. A successful automated test demonstrates what the platform could reach under the configured conditions; it is not a general security guarantee.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
Regulatory and operational questions
- Is the deployment permitted in the relevant country and industry?
- Where are test data, credentials and logs stored?
- What authorization, retention and evidence controls are available?
- Are government or FedRAMP-related requirements actually met for the chosen service?
- How are findings assigned, retested and retained for audits?
Horizon3.ai documentation references Federal and FedRAMP-related controls, but buyers should verify the exact authorization status for the service and region they plan to use. See the company’s March 2026 release notes for the referenced controls.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Competitive context
Horizon3.ai sits in a broad market that includes automated security validation, breach-and-attack simulation, exposure management and autonomous penetration testing. The products below overlap, but they are not interchangeable:
| Provider | Common emphasis | Official site |
|---|---|---|
| Horizon3.ai | Autonomous attack-path discovery, exploitation and recurring validation | horizon3.ai |
| Pentera | Automated security validation and breach-and-attack simulation | pentera.io |
| XM Cyber | Exposure management and attack-path prioritization across hybrid environments | xmcyber.com |
| Picus Security | Breach-and-attack simulation and defensive-control validation | picussecurity.com |
| Cymulate | Exposure validation across multiple attack vectors | cymulate.com |
| XBOW | Autonomous offensive-security and penetration testing | xbow.com |
The right comparison depends on whether a buyer wants autonomous exploitation, control validation, attack-path analysis, bundled human services, MSSP support, government controls, or deep web and identity coverage. Vendor-hosted market reports, including Frost & Sullivan materials circulated by XM Cyber and Pentera, provide context but should not be treated as neutral rankings.
Who should consider NodeZero?
- Enterprises with large, changing attack surfaces
- Security teams that need repeatable testing after remediation or infrastructure changes
- Organizations that want attack-path evidence instead of severity scores alone
- MSSPs and service providers running recurring assessments for customers
- Teams with the authority and maturity to authorize controlled testing
It may be a poor fit for a small organization seeking one occasional compliance test, an environment that cannot support the required connectivity, or a buyer needing social engineering, physical testing or bespoke business-logic research. Horizon3.ai does not publish list pricing in the cited official sources as of August 16, 2026, so buyers should expect a sales-led quote.
Free tools Windows power users keep installed
One-click scans. No signup required.
Bottom line
The $100 million figure was not merely a target: Horizon3.ai closed it as a Series D on June 10, 2025. The round funded expansion of NodeZero, its autonomous penetration-testing platform, while the reported $250 million Series E in August 2026 placed the company above a $2 billion valuation. That progression shows strong investor conviction in autonomous security validation, but customers should treat it as a way to increase testing frequency and evidence—not as a complete replacement for human red-team expertise or security governance.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




