NullSquare

Secure the unknown.

Continuous Penetration Testing

Run continuous security testing across your websites, APIs, cloud assets, and private environments. Review findings, reports, and live agent activity in one unified dashboard.

Want to see it in action?

Building with the best

We partner with the teams shaping security, cloud, and frontier AI to keep your defenses ahead of the threat.

Product Flow

How it works

From setup to report, the platform tracks what is tested, maps your scope boundaries, and streams findings in real time.

01
SET UP YOUR SCOPE

Connect what you want to test

Add a website, API, repository, or private target. NullSquare maps the scope and prepares the run from a clean starting point.

02
RUN THE ASSESSMENT

Let the agent do the work

The agent explores the target, runs the right tools, follows evidence, and validates supported issues before reporting.

03
REVIEW FINDINGS

Turn findings into action

Review validated findings, inspect the retained proof, share the report, and rerun checks after fixes land.

04
MAP COMPLIANCE

Track readiness continuously

Run compliance assessments that review controls, attach evidence, and show what is passing, failing, or needs more proof.

Ready to explore?

Explore the live interactive platform demo in seconds. No configuration required.

// LIVE DEMO|FULL PLATFORM PREVIEW
Platform

Core capabilities

Built for security and engineering teams that need clear, actionable findings without the noise.

Global runner network

Execute anywhere

Deploy agents inside your VPC, on-prem, or across global cloud regions.

6 Nodes Active
Exploitability Analysis

Code-aware analysis

Continuous exploitability vetting for every PR and repository transmission.

GitHub WebhookLIVE

Critical findings verified in PR #128.

Runner EU-WEST2m

Automated scan completed: 0 issues.

S3 Monitor4m

Unencrypted bucket detected in STAGE.

Continuous Automation

Always-on coverage

Schedule recurring tests, watch runner health, and track automation activity over time.

July 2026
SMTWTFS
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
Done
Active
Planned
Live
Enterprise Integrations

Global connect

Native support for the tools your security and engineering teams live in.

GitHubSecure Code
JiraTicket Sync
SlackInstant Alerts
SplunkSIEM Ingest
Compliance & audits

Compliance audit readiness

Run framework-specific readiness checks where every control outcome cites what was tested, what evidence was used, and what still needs work.

Control workspace

SOC 2

Trust Services Criteria

12 controls monitored·31 evidence items
CC6.1Logical access boundaries
Passing

Unauthenticated access was rejected on tested routes; cross-role depth improves with scoped test accounts.

Basis · Agent-tested access boundary

CC6.7Transmission protection
Needs action

Fails cleanly when evidence shows missing HSTS, plaintext redirects, or weak transport posture.

Basis · HTTP/TLS proof package

CC7.1Vulnerability detection
Passing

Scanner findings, HTTP exchanges, and retained artifacts link to the exact control check.

Basis · Scanner and artifact evidence

CC4.1Continuous monitoring
Needs evidence

The agent requests monitoring coverage evidence instead of silently marking a control reviewed.

Basis · Integration or uploaded evidence

Scope-bound evidence sync active

NullSquare prepares the control evidence story. It does not certify, attest, provide legal advice, replace a DPO or QSA, or replace an independent auditor.

Trust badge

Show customers you take security seriously — and let them verify it.

Sites running NullSquare display a badge that shows they are continuously monitored for security. It links to a public page anyone can open and verify — the proof is public, your findings stay private.

Get your badgeInstall an app or drop in one line — verified sites only.

Click the badge — anyone can open the public verification page for the site.

Flexible pricing

Select the plan built for your scope

Start testing public boundaries instantly, expand test cycles, and deploy secure Private Runner networks when needed.

MonthlyAnnual
Lite Plan

Starter

Basic boundary scans.

Free
  • 500 credits/month
  • Low model access
  • 1 organization user
  • 1 concurrent runs
  • 1 active scopes
Most Popular
Plus Plan

Plus

Ideal for fast-growth applications.

$50/mo
  • 5,000 credits/month
  • Low and medium model access
  • 1 organization user
  • Scheduled Automations
  • 2 concurrent runs
  • 1 active scopes
Pro Plan

Pro

Complete offensive vulnerability pipeline.

$500/mo
  • 50,000 credits/month
  • All model tiers
  • Unlimited organization users
  • Scheduled Automations
  • Repository assignment for whitebox analysis
  • Code review
  • Compliance workspace
  • Live terminal and activity details
  • Internal Node Execution
  • Alert integrations
  • 3 concurrent runs
  • 5 active scopes
Enterprise Plan

Enterprise

Tailored scope, private runners & high capacity.

Custom
  • Custom credit pool
  • Custom run capacity
  • Custom scope limits
  • All model tiers
  • Repository assignment for whitebox analysis
  • Code review
  • Compliance workspace
  • Live terminal and activity details
  • Alert integrations
  • 24h support
All plans include automated logging • secure sandbox isolation • continuous audit mapping
Organizational Verification

Request a pentest scope review

Share your details and we'll get back to you to confirm scope, schedule, and testing windows.

Encrypted connection

Pricing & Scope FAQ

Common questions regarding deployments

Direct security support