NodeZero maker Horizon3.ai closed a $250 million Series E at a $2 billion-plus valuation, tripling in 14 months, as enterprises race to counter AI-powered attackers.
- Horizon3.ai raised $250M co-led by NightDragon and NEA, bringing total funding since founding to $428.5M.
- The $2B+ valuation is more than triple the $650M attached to the company's Series D just 14 months prior.
- NodeZero autonomously probes live enterprise networks for exploitable weaknesses, replacing annual manual pen tests.
Lead
Horizon3.ai, the San Francisco-based autonomous penetration testing company, announced on August 3, 2026 that it had closed a $250 million Series E round co-led by NightDragon and NEA, vaulting its valuation above $2 billion. The round was oversubscribed, drawing in seven new institutional investors alongside five returning backers. Fourteen months earlier, the company's Series D pegged it at $650 million. The implied valuation growth - more than 3x in little over a year - is a pointed statement about where enterprise security budgets are moving.
What Did Horizon3.ai Build?
The company's core product, NodeZero, runs real attacks against a customer's own production network, chains vulnerabilities across credentials, lateral movement paths, and cloud pivots, and then proves which weaknesses are actually exploitable rather than merely theoretically risky. Unlike vulnerability scanners that flag possibilities, NodeZero produces evidence of confirmed attack paths. It operates without taking systems offline and runs continuously rather than in the annual or semi-annual cadence that traditional penetration testing firms deliver. Days before the funding announcement, Horizon3.ai extended NodeZero to cover web application testing, adding exploit chaining from application-layer abuse through to sensitive data exposure.
The founders, CEO Snehal Antani and co-founder Anthony Pillitiere, met while serving at Joint Special Operations Command. That background is not incidental. NodeZero's design philosophy - think like an adversary, operate inside the target environment, chain small weaknesses into significant breaches - reflects how offensive military units approach target networks, not how compliance-driven security vendors approach checkbox audits.
Why Did Investors Move So Aggressively?
The round's size and structure both tell the story. Seven new investors joined - Acrew Capital, Blue Cloud Ventures, Demeter Group, EDBI (Singapore's state-linked economic development fund), PSG, SAIC, and Sapphire Ventures - while five prior backers returned: Craft Ventures, Prosperity7 Ventures, Qualcomm Ventures, Ridge Ventures, and SignalFire. An oversubscribed round with that breadth of participation suggests competitive pressure among LPs to get allocation, not a negotiated deal.
The underlying thesis is straightforward. AI tooling has lowered the cost of mounting sophisticated cyberattacks. Commodity attackers can now probe networks at scale, generate novel phishing campaigns, and adapt to defenses at a rate that human security teams cannot match manually. Autonomous defensive AI - systems that probe your own network continuously, at machine speed, before attackers do - is the logical counter-move. Horizon3.ai is betting that this dynamic drives enterprises toward always-on autonomous testing and away from point-in-time engagements.
The valuation math also merits scrutiny. A $650 million Series D followed by a $2 billion Series E implies the company's revenue trajectory was steep enough to justify the multiple expansion, or that investors are pricing in a market opportunity large enough to absorb a premium entry point. Horizon3.ai has not disclosed its revenue figures.
Who Is Dave DeWalt and Why Does the Board Appointment Matter?
NightDragon founder and CEO Dave DeWalt, who previously ran both FireEye and McAfee, will join Horizon3.ai's board of directors. NightDragon managing director Morgan Kyauk will sit alongside him. DeWalt's operational history spanning two of the most prominent enterprise security companies of the past decade carries credibility with the Fortune 500 buyers Horizon3.ai is targeting. Board appointments from lead investors are standard; appointments from someone with DeWalt's specific profile in the security market carry additional signal about the company's positioning for a potential public offering.
What Comes Next for Autonomous Penetration Testing?
Horizon3.ai faces a growing competitive set. Pentera, XM Cyber, and a collection of AI security startups are all addressing some version of the same problem - continuous automated attack simulation. What distinguishes NodeZero at this stage is its claim to production-safe continuous operation at enterprise scale and its recent expansion into web application coverage. The $250 million in fresh capital suggests the company will pursue customer acquisition aggressively, likely expanding internationally given EDBI's participation, and invest in extending the NodeZero platform to cover additional attack surfaces.
The inclusion of SAIC - a major U.S. defense and government IT contractor - among the new investors also raises the possibility of federal and public-sector pipeline development. That market, historically slow-moving on security procurement, has accelerated under pressure from high-profile intrusions against government networks.
Outlook
Horizon3.ai's $250 million raise at a $2 billion-plus valuation positions it as the best-funded pure-play in autonomous penetration testing. The tripling of valuation in 14 months reflects genuine product-market traction and a broader shift in enterprise security spending toward AI-driven offense simulation. Whether the company can maintain that trajectory as larger security platforms add autonomous testing capabilities to their own suites is the central question going forward. The board changes, the investor breadth, and the $428.5 million in cumulative funding all point toward the company preparing for a more significant liquidity event within the next two to three years.



