Horizon3.ai (NodeZero) vs Lory: Autonomous Network Pentesting vs a Human-Signed Engagement | Lorikeet Security Skip to main content
Back to Blog
Vendor Comparison

Horizon3.ai (NodeZero) vs Lory: Autonomous Network Pentesting vs a Human-Signed Engagement

Lorikeet Security · September 7, 2026 · 10 min read
Disclosure: This is written by Lorikeet Security. The Horizon3.ai column reflects NodeZero's public product pages and 2026 press coverage, including the August 2026 $250M funding round. Anything not stated publicly is marked not published rather than guessed at, and the human-vs-agent comparison cited below is a third-party finding, not a claim from either company.

The One-Line Difference

NodeZero is an autonomous pentesting platform built to exploit real weaknesses at scale across internal networks, external assets, and cloud - with no human review step in the product itself.

Lory is an AI pentester that runs the same kind of automated exploitation, plus web, mobile, and source code review, with a named Lorikeet Security pentester signing every finding before it reaches you.

NodeZero's flagship strength is internal network pentesting - lateral movement, credential attacks, and Active Directory attack paths - a surface Lory also covers via a mesh connector, but where NodeZero has a longer, more specialised track record.


At a Glance

DimensionHorizon3.ai (NodeZero)Lory by Lorikeet
ModelAutonomous pentesting, no human review stepAutonomous testing, human-signed before findings ship
Flagship strengthInternal network + Active Directory attack pathsFull-estate coverage in one engagement
Cloud pentestAWS and Azure, gray-box, including autonomous escalation to Entra ID Global AdminAWS, Azure, GCP, Kubernetes, containers, serverless
Human vs. agent (third-party finding)Top human found 13 valid vulns vs. the agent's 9 in a public head-to-head; gap was creative chaining and business-logic flawsHuman pentester reviews chaining and business logic before signing
PricingNot published; enterprise subscription, per-asset, 100-asset minimum, quote requiredPrepaid credits, itemised quote within 24 hours
Market signal$250M raised at a $2B valuation, August 2026Not published in comparable terms
Benchmark resultFirst AI to fully solve the GOAD (Game of Active Directory) benchmarkNot published in comparable terms
Asset coverageInternal network, external network, cloudWeb, API, mobile, network (internal and external), cloud, source code
Recurring coverageRepeatable "Discover, Authorize, Pentest, Repeat" workflowWeekly, biweekly, monthly, quarterly, or yearly, queued and started automatically

Coverage, Side by Side

Asset TypeNodeZeroLory
Internal network / Active DirectoryYes, the flagship productYes, via the mesh connector
External networkYes, OSINT and DNS-based discoveryYes, services, versions, exposure
CloudYes, AWS and AzureYes, AWS, Azure, GCP, Kubernetes, containers, serverless
Web appNot published as a dedicated application-layer productYes
APINot publishedYes, crawl, auth testing, injection, access control
MobileNot publishedYes, iOS and Android plus their backends
Source code reviewNot publishedYes, secret hunting, sink tracing, supply chain
PhysicalNot publishedHuman-led, never run by Lory

Where Horizon3.ai Differentiates


Where Lory Differentiates

Honest Weak Spots for Lory NodeZero's internal-network and Active Directory depth is more specialised and has a longer track record than Lory's mesh-connector approach to the same surface. Its $250M raise and GOAD benchmark result are concrete, third-party-verifiable proof points of technical maturity in exactly the domain it's built for. And for a large enterprise already comfortable with a per-asset subscription and a 100-asset minimum, that pricing model may be simpler to plan around than a per-engagement credit balance.

Picking Between Them

Horizon3.ai may fit if...
  • Your primary concern is internal network and Active Directory exposure at enterprise scale
  • You want a large-asset-count subscription with a repeatable discover-and-test cadence
  • You're comfortable with a fully autonomous result with no human review step
Lory may fit if...
  • You need web, API, mobile, or source code coverage alongside network and cloud
  • You need a named person to stand behind every finding for a customer, auditor, or board
  • You want business-logic and chaining judgment calls reviewed by a human before they ship
  • You'd rather scope and pay per engagement than commit to an asset-count subscription

A large enterprise defending a complex internal network may reasonably run NodeZero for that surface and Lory for everything else - web, mobile, cloud, and source code - under one signed engagement.

See a Signed Engagement in Action

Book a scoping call and we'll walk you through what a Lory engagement covers across your whole estate, and how a named pentester signs off before anything reaches your report.

Book a Consultation
-- views
Link copied!
Lorikeet Security

Lorikeet Security Team

Penetration Testing & Cybersecurity Consulting

Lorikeet Security helps modern engineering teams ship safer software. Our work spans web applications, APIs, cloud infrastructure, and AI-generated codebases — and everything we publish here comes from patterns we see in real client engagements.