Secure the unknown.
Continuous Penetration Testing
Run continuous security testing across your websites, APIs, cloud assets, and private environments. Review findings, reports, and live agent activity in one unified dashboard.
Building with the best
We partner with the teams shaping security, cloud, and frontier AI to keep your defenses ahead of the threat.
How it works
From setup to report, the platform tracks what is tested, maps your scope boundaries, and streams findings in real time.
Connect what you want to test
Add a website, API, repository, or private target. NullSquare maps the scope and prepares the run from a clean starting point.
Let the agent do the work
The agent explores the target, runs the right tools, follows evidence, and validates supported issues before reporting.
Turn findings into action
Review validated findings, inspect the retained proof, share the report, and rerun checks after fixes land.
Track readiness continuously
Run compliance assessments that review controls, attach evidence, and show what is passing, failing, or needs more proof.
Ready to explore?
Explore the live interactive platform demo in seconds. No configuration required.
Core capabilities
Built for security and engineering teams that need clear, actionable findings without the noise.
Execute anywhere
Deploy agents inside your VPC, on-prem, or across global cloud regions.
Code-aware analysis
Continuous exploitability vetting for every PR and repository transmission.
Critical findings verified in PR #128.
Automated scan completed: 0 issues.
Unencrypted bucket detected in STAGE.
Always-on coverage
Schedule recurring tests, watch runner health, and track automation activity over time.
Global connect
Native support for the tools your security and engineering teams live in.
Compliance audit readiness
Run framework-specific readiness checks where every control outcome cites what was tested, what evidence was used, and what still needs work.
SOC 2
Trust Services Criteria
Unauthenticated access was rejected on tested routes; cross-role depth improves with scoped test accounts.
Basis · Agent-tested access boundary
Fails cleanly when evidence shows missing HSTS, plaintext redirects, or weak transport posture.
Basis · HTTP/TLS proof package
Scanner findings, HTTP exchanges, and retained artifacts link to the exact control check.
Basis · Scanner and artifact evidence
The agent requests monitoring coverage evidence instead of silently marking a control reviewed.
Basis · Integration or uploaded evidence
NullSquare prepares the control evidence story. It does not certify, attest, provide legal advice, replace a DPO or QSA, or replace an independent auditor.
Trust badge
Show customers you take security seriously — and let them verify it.
Sites running NullSquare display a badge that shows they are continuously monitored for security. It links to a public page anyone can open and verify — the proof is public, your findings stay private.
Click the badge — anyone can open the public verification page for the site.
Select the plan built for your scope
Start testing public boundaries instantly, expand test cycles, and deploy secure Private Runner networks when needed.
Starter
Basic boundary scans.
- 500 credits/month
- Low model access
- 1 organization user
- 1 concurrent runs
- 1 active scopes
Plus
Ideal for fast-growth applications.
- 5,000 credits/month
- Low and medium model access
- 1 organization user
- Scheduled Automations
- 2 concurrent runs
- 1 active scopes
Pro
Complete offensive vulnerability pipeline.
- 50,000 credits/month
- All model tiers
- Unlimited organization users
- Scheduled Automations
- Repository assignment for whitebox analysis
- Code review
- Compliance workspace
- Live terminal and activity details
- Internal Node Execution
- Alert integrations
- 3 concurrent runs
- 5 active scopes
Enterprise
Tailored scope, private runners & high capacity.
- Custom credit pool
- Custom run capacity
- Custom scope limits
- All model tiers
- Repository assignment for whitebox analysis
- Code review
- Compliance workspace
- Live terminal and activity details
- Alert integrations
- 24h support
Request a pentest scope review
Share your details and we'll get back to you to confirm scope, schedule, and testing windows.
Pricing & Scope FAQ
Common questions regarding deployments
Latest from the blog
Security thinking from the latest release.
Read the newest NullSquare field note, or open the full blog for more articles on AI security, continuous testing, release gates, and attack surface coverage.
Compliance
Compliance tools are not all solving the same problem
Compliance tools are not all solving the same problem
A practical comparison of compliance automation platforms, where NullSquare fits, and why evidence review depth matters as much as audit workflow coverage.