:novee-gym: Elite AI hackers aren’t born. They’re trained.

Step into the gym at Black Hat 2026.

:novee-gym: Elite AI hackers aren’t born. They’re trained.

Step into the gym at Black Hat 2026.

Novee vs. Horizon3

Pattern-matching creates noise, but finding and fixing exploitable flaws is what proves your application is secure.

Horizon3 is proven for infrastructure and network red teaming, but its web app testing is new, its exploits are deterministic, and it has no proprietary AI stack. Novee is built for the application layer and chains business logic like an attacker.

See Novee in action

Thank you!

We’ll be in touch as soon as we can.

Chosen by teams that take attackers seriously

Novee vs. Horizon3 at a glance

Challenges with Horizon3

Strong infrastructure coverage doesn’t secure the application layer, where most breaches actually start and the business logic hides.

Challenges with Horizon3:

  • No proprietary offensive model.

    Horizon3 scopes third-party LLMs to specific exploit decisions. The reasoning ceiling is set by the general models underneath.
  • Web app testing is still new.

    Its deterministic exploit execution finds known vulnerability classes reliably but can't adapt to the unique business logic flaws that lead to real breaches.
  • Lighter validation for web apps.

    For infrastructure, Horizon3 delivers deterministic exploit proof, but web application testing has no multi-agent pipeline, leaving more room for false positives to reach your team.
  • Siloed from the tools devs use.

    Horizon3 integrates through a proprietary MCP only, with no CI/CD, Jira, or GitHub support. Fixes never reach the code level, so teams tab constantly between dashboards.
  • No closed loop on the fix.

    Horizon3 delivers exploit proof but no stack-specific remediation and no automatic retesting, so a verified fix is left to your team.

Why Novee Over Horizon3?

Application-layer security is only as strong as what it finds in your business logic, how confidently you can act, and whether the fix holds.

Where Novee goes further:

  • A proprietary offensive AI stack.

    Novee post-trained its own offensive reasoning model on real attacker tradecraft, and orchestrates it with best-in-class frontier models using a proprietary harness. Owning and optimizing the entire AI stack means maximized efficiency gains and accuracy.
  • Validation built for zero false positives.

    Every finding runs through three independent agents. One exploits, a second re-exploits blind with no shared context, a third validates independently, with deterministic checks inserted where possible. If any stage fails, it's never reported. Every finding comes with a working exploit, replication steps, and a PoC script.
  • A closed loop to a verified fix.

    Remediation is tailored to your WAF, backend, and codebase, not generic OWASP references. Once a fix ships, Novee retests automatically to confirm it held, and checks for new risks the change introduced.
  • Built into your workflow.

    Native CI/CD and change-triggered testing fire the moment code ships. Connected to CI/CD, fixes go to the code level, aligned to your actual codebase.
  • Predictable per-asset pricing.

    Depth and frequency don't cost extra, so continuous, deep testing never gets rationed against a budget.
  • Full application-layer coverage.

    Web apps, APIs, mobile, and AI agents and LLMs: built for the layers where most breaches start.

Novee vs. Horizon3 Across Key Areas

Capability Novee AI Pentesting Horizon3
Testing depth

Infrastructure and network exploitation only. Deterministic execution finds known vulnerability classes but can’t adapt to novel business logic.

Coverage

Infrastructure and network. Web application testing is Early Access; no mobile or AI app testing.

Offensive AI stack

No proprietary model. Scopes third-party general-purpose LLMs to specific exploit decisions; the capability ceiling is set by those models.

Validation architecture

Deterministic validation for infrastructure, no independent multi-agent architecture for web app testing.

Closed-loop remediation & retesting

No stack-specific remediation and no automatic retesting.

Compounding application context

Each run is scoped independently; context does not compound across runs.

Continuous, change-triggered testing

Continuous for infrastructure; no change-triggered testing for web applications.

Workflow and CI/CD Integration

Integrates through a proprietary MCP only. No CI/CD, Jira, or GitHub integration.

What security leaders say

“As the leading agentic orchestration platform for the enterprise, data isolation between our customers is non-negotiable. We need to prove that continuously, not once a year. Novee adapted to our multi-tenant SaaS product within days.”

Scott Roberts
CISO
john

“Our pen tests took weeks and consistently missed critical issues. Novee found them immediately and gave us instant remediation guidance. It showed us what we'd been missing.”

John Barrow
CISO

"Traditional DAST produced either zero or irrelevant results. We needed something that could identify complex vulnerabilities like server-side request forgery. Novee consistently surfaces findings we simply weren't seeing before."

Robert Kugler
Head of Security, IT & Compliance

“Novee rethinks penetration testing for how attacks actually happen today. Continuous, attacker-level validation that proves what’s exploitable and shows teams exactly how to fix it is a meaningful shift for modern security programs.”

Troy Wilkinson
Former Fortune 500 CISO
tamir ronen

"The hardest vulnerabilities for us to catch aren’t misconfigurations or known patterns. They’re business logic issues that only show up when someone understands how the application is supposed to work. That’s exactly the gap Novee closes."

Tamir Ronen
CISO, HiBob

"We had EASM tools and manual pentests that produced mostly noise. Novee came in black-box with zero credentials and within days found dozens of real vulnerabilities we could actually fix."

Itzik Menashe
CISO, Global VP IT InfoSec & productivity

“As an AI researcher, what stood out about Novee is that they built a proprietary offensive AI model designed to think like an attacker, rather than wrapping generic LLMs. That matters for enterprise-grade results.”

Tal Shapira
PhD, CTO

“This was by far the deepest and fastest security assessment we’ve had. Novee uncovered issues across our web and mobile applications that had gone undetected before, and the level of depth was unlike anything we’d seen from other vendors.”

Amir Tito
CISO

“We had urgent compliance need and we couldn’t wait weeks for DAST findings, an external exposure audit, and an in-depth pentest report. Instead Novee came in and delivered immediate value with their AI pentesting platform; with their findings, we closed our gaps and quickly met the criteria we needed for certification.”

Ron Reiter
CTO

"Before Novee, we were getting a snapshot once a year. Now we have continuous coverage across our application portfolio, we're already finding things that prior manual pentests missed completely, and I have real confidence that our security posture reflects what's actually in our environment."

Abhijeet Patkar
Cyber Security Manager

The Novee Advantages

The Novee Advantage for Proprietary Model and Harness

The Problem with Horizon3:

Horizon3's strength is infrastructure and network testing, where NodeZero navigates autonomously and delivers deterministic, pre-validated exploit proof. But that same determinism is its ceiling on the application layer: it scopes third-party LLMs to specific exploit decisions and reliably finds known vulnerability classes, while the novel business logic flaws that chain into real breaches go undiscovered, run after run.

How Novee Goes Further:

Novee post-trained its own offensive reasoning model on real attacker tradecraft. It doesn't just execute pre-validated exploits, it reasons and chains vulnerabilities across your business logic the way a human attacker would. Orchestrated with best-in-class frontier models selected per task, and purpose-built for offensive application security, it finds the complex, chained attack paths that deterministic execution structurally can't reach on its own.

The Novee Advantage for Validation and False-Positive Triage

The Problem with Horizon3:

Horizon3 attaches deterministic exploit proof, but features no multi-agent validation for web apps, meaning fewer independent checks between a false positive and your team.

How Novee Improves Signal-to-Noise:

Every suspected vulnerability runs through three independent agents – a finder, a validator, and a blind re-validator with no context from the first two – backed by deterministic checks wherever exploitability can be confirmed by execution rather than inference. If any stage fails, the finding never surfaces. Every issue that reaches your team arrives proven, with a working exploit, replication steps, and a PoC script. No false positives by design, no manual triage.

The Novee Advantage for Closing the Loop

The Problem with Horizon3:

Horizon3 delivers exploit proof and reproduction, but its web application offering doesn't describe remediation tailored to your architecture, and there's no automatic retesting to confirm a fix worked or to catch regressions, so the work of reaching a verified fix lands back on your team, cycle after cycle.

How Novee Improves Remediation:

Because the Novee Asset Intelligence Model captures your architecture and tech stack, remediation guidance is specific to your WAF, backend, and codebase and, connected to CI/CD, drops to the code level. Once a fix ships, Novee automatically retests to confirm the vulnerability is resolved and checks for new risk the change introduced.