# Horizon3.ai

**Canonical:** https://apis.io/providers/horizon3ai/  
**Website:** https://horizon3.ai  
**APIs profiled:** 1

Horizon3.ai is a cybersecurity company whose NodeZero platform delivers autonomous penetration testing and continuous security posture management. NodeZero safely attacks your internal, external, cloud, and hybrid environments the way a real adversary would, proving exploitable attack paths, prioritizing the fixes that matter, and verifying that remediations actually work. Horizon3.ai exposes a publicly documented GraphQL API (the NodeZero API) plus an h3-cli command-line tool and a hosted Model Context Protocol (MCP) server, letting teams schedule pentests, retrieve findings, weaknesses, attack paths, credentials, and host inventory, and wire results into CI/CD, ticketing (Jira, ServiceNow), and agentic workflows. NodeZero Federal is FedRAMP High authorized for public-sector use.

## Kin Score — 45.3 / 100 (developing)

Scored 2026-08-30 under rubric 0.17.2. Trend: flat (+0.0 from 45.3).

| Facet | Score |
|---|---|
| Discoverability | 75.9 |
| Contract Quality | 42.7 |
| Governance | 18.2 |
| Contract Governance | 18.2 |
| Operational Transparency | 42.1 |
| Developer Ergonomics | 49.4 |
| Commercial Clarity | 47.4 |
| Access Clarity | 47.4 |

## Agent readiness — 43.2 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | documented |
| Auth Clarity | served |
| Idempotency | no |
| Error Semantics | documented |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | yes |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | served |
| Protected Resource Metadata | verified |
| Dynamic Client Registration | yes |
| Agentic Commerce | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (1)

- **NodeZero GraphQL API** — The NodeZero API is a publicly accessible GraphQL API that exposes a subset of the Horizon3.ai Portal: schedule and control autonomous pentest operations, and read pentests, ops...

## MCP servers (1)

- **Horizon3.ai MCP Server** — Horizon3.ai-hosted Model Context Protocol server exposing NodeZero data and actions to MCP-compliant agents. Backs onto the same NodeZero platform as the GraphQL API. Secured wi...

## Security (4)

- **Horizon3Ai Authentication** — apiKey/http-bearer/oauth2 · 3 schemes
- **Horizon3Ai Domain Security** — TLSv1.3 · HSTS · DMARC
- **Horizon3Ai Vulnerability Disclosure** — contact published
- **Horizon3Ai Trust Center** — FedRAMP High, SOC 2, CMMC 2.0, NIST SP 800-53 Rev. 5

## Tags

Company, Security, Cybersecurity, Penetration Testing, Autonomous Pentesting, Attack Surface Management, Exposure Management, Vulnerability Management, GraphQL, Offensive Security

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/horizon3ai/). Scores are computed from the provider's own public artifacts under a published rubric.
