Horizon3 alternative: NodeZero and the EU evidence gap
TL;DR
Horizon3.ai is one of the strongest autonomous pentest platforms in the market, and the funding confirms it. In August 2026 it raised a $250M Series E at a $2B valuation, co-led by NightDragon and NEA, after approaching $100 million in ARR with 120% year-on-year growth and 310,000 production security tests run with zero disruptions. Anyone shopping for a "Horizon3 alternative" should start by accepting that the product works.
So the comparison is not about whether the testing is real. For an EU regulated buyer it comes down to two narrower questions:
- Pick Horizon3.ai / NodeZero when the internal network is the risk, when the estate is large and mixed, and when continuous validation across everything matters more than the shape of the report.
- Pick Fleuret AI when the trigger is a regulatory deadline on an external web and API surface, and the deliverable has to survive a supervisor reading it.
- Neither is a scanner, so do not evaluate either one on CVE counts.
Why the query is being typed right now
Because of a date. On 7 July 2026 the ECB sent significant institutions a letter, signed by Supervisory Board chair Claudia Buch, requiring a board-level action plan by 31 October 2026 on AI-enabled cyber threats. It sets out six focus areas, from protecting attack surfaces and accelerating patch management at scale through to operational resilience and supply-chain assurance.
One correction worth making, because vendors are getting this wrong in both directions: the letter does not mandate threat-led penetration testing. A&O Shearman's reading finds no TLPT requirement in it. TLPT obligations arrive through DORA, where your competent authority designates you. What the ECB actually asks is whether your current testing capacity is sufficient at the new pace of attack. That is a question about throughput and evidence, not about buying a specific category of tool.
Horizon3.ai, described fairly
NodeZero runs real attack techniques against production environments and chains them to prove impact, rather than reporting theoretical findings. Its own launch announcement lists internal, external, Kubernetes, cloud, Active Directory and web application testing, and the ability to "instantly verify remediation" once a fix ships. Its architecture is deliberate about where AI sits: Horizon3's own description is graph-based reasoning for attack planning, classical machine learning for classification, scoped generative AI for tasks like high-value targeting, and deterministic logic for exploit execution, never generative AI. It does not train foundation models. That is a more disciplined design than most of the "AI pentest" category, and we would rather say so than pretend otherwise.
TechCrunch also reports offices opened in Amsterdam in June 2026, plus Australia and Singapore. If you have read a comparison page claiming Horizon3 cannot serve European customers, it is out of date.
The gap that is actually observable
Here is what an EU buyer can verify without a sales call.
Horizon3 publishes a factsheet on meeting the ECB's AI cybersecurity mandate with NodeZero. DORA and NIS2 appear in it once, inside a single line about producing "executive and regulatory-ready evidence supporting ECB, DORA, and NIS2 requirements". The page says nothing about where data is processed.
On the AI page, the residency sentence reads: "any GenAI tasks run only through secure clouds like Amazon Bedrock, with complete data residency and isolation." Read it closely. It claims completeness and names no region.
Neither of those is a scandal. Both are exactly the sentences a DORA Article 28 sub-processor review will send back with a question attached, and an October deadline is a bad time to be waiting on an answer.
A finding you cannot place in a jurisdiction is still a finding. It is just harder to file.
Where Fleuret AI is different, and where it is not
We cover external web applications, REST and GraphQL APIs, and external infrastructure. Every finding ships with a reproducible proof of concept, because a finding a developer cannot reproduce is a ticket nobody closes. Data stays in the EU, in the fra1 region, with serverless functions pinned to Europe, and our sub-processors are listed publicly so the Article 28 answer is a link rather than a meeting. The audit PDF is Ed25519-signed and maps to DORA Article 24 and NIS2 Annex I as shipped. Pentest is €4,000 per test, Advanced Pentest €8,000, delivered in hours rather than the two to four weeks a consulting firm takes.
What we do not cover in 2026: internal network, Active Directory, Kubernetes, and cloud configuration. NodeZero does cover those. If that is where your risk lives, Horizon3 is the better purchase and this page should not talk you out of it.
Two questions to take to either vendor
- Name the region. Not "EU residency" as a posture, the actual processing region for scan data, findings, and any model inference, plus the sub-processor list behind it.
- Show me the deliverable, not the dashboard. Ask for a sample report and check whether the mapping to DORA Article 24 or NIS2 Annex I is already in it, or whether your GRC team will be rebuilding it by hand in October.
Ask us both. If our answer is worse for your scope, buy the other one.
If your risk lives on an external web and API surface and your auditor wants evidence rather than a dashboard, request a demo.
Related reading
- XBOW alternative in Europe: the wider EU agentic-pentest shortlist.
- FireCompass alternative: breadth against depth, the same trade in a different shape.
- Pentera alternative: the internal-network comparison in detail.
- DORA Article 24 in live production: what the testing clause asks for.
- Sovereign EU AI pentest: the regime behind the residency question.
- Agentic AI pentesting explained: how multi-agent exploitation works.
Sources
- Horizon3 hits $2 billion valuation with $250M Series E as AI threats escalate, Kate Park, TechCrunch, 3 August 2026: the Series E, valuation, investors, ARR and growth, the 310,000 tests figure, and the Amsterdam, Australia and Singapore offices.
- Horizon3 Raises $250M Series E at $2B+ Valuation, Horizon3.ai: the primary anchor for the round being co-led by NightDragon and NEA, for the tested surfaces (internal, external, Kubernetes, cloud, Active Directory, web app), for "instantly verify remediation", and for "deepening presence across EMEA".
- NodeZero pricing, Horizon3.ai: four named tiers, Flex, Core, Pro and Elite, with no figure against any of them. Cited for what is absent, so no third-party contract estimate is repeated here.
- ECB requires significant institutions to address AI-enabled cybersecurity threats, Alexander Behrens, Catharina Glugla, Niklas Germayer and Chloe Barrowman, A&O Shearman, 9 July 2026: the 7 July 2026 letter, its author, the 31 October 2026 deadline, the six focus areas, and the absence of a TLPT mandate.
- Meeting the ECB's AI-Enabled Cybersecurity Mandate with NodeZero, Horizon3.ai: the vendor's own EU regulatory page, cited for how it frames DORA and NIS2 and for what it does not state about processing location.
- AI at Horizon3, Horizon3.ai: the architecture description and the data residency sentence, quoted verbatim.
- Regulation (EU) 2022/2554 (DORA), EUR-Lex: Article 24 on testing and Article 28 on sub-processor arrangements.