agent active

ZeroPath

Maker: ZeroPath

About

ZeroPath targets the failure mode of traditional SAST: a finding is reported, but producing an actual fix remains a human project. The platform scans repository fleets without requiring build configuration, using AI-driven analysis to catch business-logic flaws and auth bypasses that rule-based scanners miss. Its distinguishing step is agentic patching — for confirmed vulnerabilities an agent drafts a change that must compile, pass tests, and merge cleanly before it is proposed, turning scanner output into mergeable pull requests. Around that core sit complementary scanners: dependency analysis weighted by reachability, secrets detection across 40+ file types with validation, infrastructure-as-code scanning for Terraform and Kubernetes, container scanning, DAST with exploit proof, and continuous security review of pull requests. A versioned policy engine lets teams codify security requirements as testable rules, findings sync to Jira, Linear, or ServiceNow, and an AI inventory discovers models, agents, and MCP servers in customer codebases for AI-BOM compliance. A separate assistant agent, Zero, runs AppSec program tasks such as bug-bounty triage. Sold demo-first with cloud, hybrid, or on-prem deployment, it targets security engineering teams; the company was an RSAC 2026 Innovation Sandbox finalist and reports 300,000+ monthly scans.