The One-Line Difference
NodeZero is an autonomous pentesting platform built to exploit real weaknesses at scale across internal networks, external assets, and cloud - with no human review step in the product itself.
Lory is an AI pentester that runs the same kind of automated exploitation, plus web, mobile, and source code review, with a named Lorikeet Security pentester signing every finding before it reaches you.
NodeZero's flagship strength is internal network pentesting - lateral movement, credential attacks, and Active Directory attack paths - a surface Lory also covers via a mesh connector, but where NodeZero has a longer, more specialised track record.
At a Glance
| Dimension | Horizon3.ai (NodeZero) | Lory by Lorikeet |
|---|---|---|
| Model | Autonomous pentesting, no human review step | Autonomous testing, human-signed before findings ship |
| Flagship strength | Internal network + Active Directory attack paths | Full-estate coverage in one engagement |
| Cloud pentest | AWS and Azure, gray-box, including autonomous escalation to Entra ID Global Admin | AWS, Azure, GCP, Kubernetes, containers, serverless |
| Human vs. agent (third-party finding) | Top human found 13 valid vulns vs. the agent's 9 in a public head-to-head; gap was creative chaining and business-logic flaws | Human pentester reviews chaining and business logic before signing |
| Pricing | Not published; enterprise subscription, per-asset, 100-asset minimum, quote required | Prepaid credits, itemised quote within 24 hours |
| Market signal | $250M raised at a $2B valuation, August 2026 | Not published in comparable terms |
| Benchmark result | First AI to fully solve the GOAD (Game of Active Directory) benchmark | Not published in comparable terms |
| Asset coverage | Internal network, external network, cloud | Web, API, mobile, network (internal and external), cloud, source code |
| Recurring coverage | Repeatable "Discover, Authorize, Pentest, Repeat" workflow | Weekly, biweekly, monthly, quarterly, or yearly, queued and started automatically |
Coverage, Side by Side
| Asset Type | NodeZero | Lory |
|---|---|---|
| Internal network / Active Directory | Yes, the flagship product | Yes, via the mesh connector |
| External network | Yes, OSINT and DNS-based discovery | Yes, services, versions, exposure |
| Cloud | Yes, AWS and Azure | Yes, AWS, Azure, GCP, Kubernetes, containers, serverless |
| Web app | Not published as a dedicated application-layer product | Yes |
| API | Not published | Yes, crawl, auth testing, injection, access control |
| Mobile | Not published | Yes, iOS and Android plus their backends |
| Source code review | Not published | Yes, secret hunting, sink tracing, supply chain |
| Physical | Not published | Human-led, never run by Lory |
Where Horizon3.ai Differentiates
- The deepest internal network story in this space. Autonomous lateral movement, credential attacks, and full domain compromise chains, including becoming the first AI to fully solve the GOAD benchmark, is a specific, hard technical achievement.
- Cloud escalation without relying on CVEs. Autonomous escalation to Microsoft Entra ID Global Admin through native attacks and harvested data, rather than only known vulnerabilities, reflects a mature attack methodology.
- Institutional confidence at scale. Raising $250M at a $2B valuation in August 2026 - tripling its worth in fourteen months - is a strong market signal for a category this new.
- A repeatable, structured workflow. "Discover, Authorize, Pentest, Repeat" gives external testing a clear, auditable cadence.
Where Lory Differentiates
- A human signs every finding. A publicly reported head-to-head found a skilled human tester still out-performed the autonomous agent on creative exploit chaining and business-logic judgment - exactly the gap a human review step is built to close. Lory's pentester reviews the chain and context before anything ships.
- Application-layer and mobile coverage. NodeZero's public material centers on network, AD, and cloud; it does not describe a dedicated web application testing product, mobile app testing, or source code review the way Lory does.
- One vendor across the whole estate. Web, API, mobile, and source code sit in the same engagement and credit balance as network and cloud.
- A coverage record. Every run reports which vectors were planned, run, and never reached, and why.
- Scoped, on-demand pricing. An itemised quote within 24 hours, rather than an enterprise subscription with a 100-asset minimum.
Picking Between Them
- Your primary concern is internal network and Active Directory exposure at enterprise scale
- You want a large-asset-count subscription with a repeatable discover-and-test cadence
- You're comfortable with a fully autonomous result with no human review step
- You need web, API, mobile, or source code coverage alongside network and cloud
- You need a named person to stand behind every finding for a customer, auditor, or board
- You want business-logic and chaining judgment calls reviewed by a human before they ship
- You'd rather scope and pay per engagement than commit to an asset-count subscription
A large enterprise defending a complex internal network may reasonably run NodeZero for that surface and Lory for everything else - web, mobile, cloud, and source code - under one signed engagement.
See a Signed Engagement in Action
Book a scoping call and we'll walk you through what a Lory engagement covers across your whole estate, and how a named pentester signs off before anything reaches your report.
Book a Consultation