Frequently Asked Questions
Get answers to common questions about ZeroPath's AI-native security platform
General
ZeroPath is the first AI-native application security platform, performing 300k+ code scans per month. It replaces your SAST, SCA, secrets detection, and IaC scanning products with one unified platform.
Beyond scanning, ZeroPath includes automated PR reviews, one-click autofix, a natural language policy engine, risk management, and compliance automation with framework mapping to SOC 2, PCI-DSS, ISO 27001, and NIST 800-53.
ZeroPath was selected as a Top 10 Finalist for the RSAC 2026 Innovation Sandbox Contest, one of the most prestigious recognitions in cybersecurity.
Almost all SAST offerings (including "AI-enabled" platforms) essentially detect bugs the same way: by tracing program inputs (from network events, filesystem) and seeing if they flow into vulnerable functions. This is accomplished by combining a large, user-maintained repository of 'rules' with an engine that statically analyzes control flows. For massive, diverse codebases, the simple "blacklist" nature of these rules results in both false positives and missed vulnerabilities.
ZeroPath is part of a new class of AppSec tools called "AI-native". Instead of scanning your code with static analysis tricks, we've built a platform from the ground up with LLMs. Our language models scan your code for problems like a pentester would, investigating each potential issue for exploitability in real-world conditions — catching business logic flaws, auth bypasses, and race conditions that rule-based tools simply cannot detect.
This approach has been validated in the real world: ZeroPath autonomously discovered 7 vulnerabilities in FFmpeg, 170+ valid bugs in curl, and critical auth bypasses in projects like Better Auth.
ZeroPath supports 30+ languages with deep analysis including:
Because ZeroPath's analysis is LLM-based rather than rule-based, adding new language support doesn't require building a separate rule set from scratch. Contact us if you have specific needs.
Integrations & Compatibility
ZeroPath includes official support and integrations (for both full scans and PR scans) with:
Zeropath can also scan uploaded code and code from credentialed git repositories.
ZeroPath supports:
ZeroPath can sync available issues with these platforms automatically.
ZeroPath can export findings as:
Export is available through both the API and the Web UI. ZeroPath can also integrate with and sync with the above issue trackers.
ZeroPath supports most of the single-sign-on options, including:
Both SAML and OAuth platforms are supported.
Yes! You can access almost all of the features of the ZeroPath web UI through our documented API.
API features include:
- Trigger scans programmatically
- Retrieve vulnerability reports
- Manage integrations
- Export findings in various formats
Product & Pricing
Most teams are scanning their first repository within 5 minutes. Connect your VCS (GitHub, GitLab, Bitbucket, or Azure DevOps) with one click, select which repos to add, and start a scan. There are no build scripts to configure, no agents to install, and no infrastructure to provision. ZeroPath automatically discovers your tech stack, maps your application architecture, and begins analysis. Enterprise SSO and team permissions can be configured in the same session.
ZeroPath's Team plan starts at $1,000/month base plus $60 per developer per month, with a 14-day free trial. We only count developers actively using the tool day-to-day, not everyone who has ever committed to a repo. All plans include unlimited repositories and scans.
The Enterprise plan offers custom pricing with on-prem/self-hosted deployment, BYOK (bring your own LLM keys), volume discounts, dedicated support with SLA, SCIM provisioning, the policy engine, and custom compliance reports.
A usage-based Credits plan (pay per scan, no monthly commitment) is coming soon. See full details on our pricing page.
PR scans typically complete in under 2 minutes. They're diff-focused meaning only changed files and their surrounding context are analyzed, with SAST, SCA, secrets, and IaC running in parallel. By comparison, tools like Checkmarx take 25–45 minutes on full codebases and can't be used as a practical PR gate.
Full repository scans take longer depending on codebase size, but subsequent scans are up to 10x faster because ZeroPath intelligently reuses results for unchanged files.
ZeroPath detects standard technical vulnerabilities like SQL injection, XSS, SSRF, command injection, path traversal, insecure deserialization, XXE, CORS misconfigurations, CSRF, and memory safety issues (buffer overflows, use-after-free). All findings are scored with CVSS 4.0.
What sets ZeroPath apart is its ability to find business logic vulnerabilities that rule-based tools miss entirely: broken authentication flows, authorization bypasses (IDOR), privilege escalation, race conditions, and workflow bypass. For example, ZeroPath found an unauthenticated API key creation flaw in Better Auth enabling complete account takeover, 7 memory safety flaws in FFmpeg including heap buffer overflows in protocol handlers, and a credential theft vulnerability in OpenClaw enabling unauthorized access to stored credentials.
ZeroPath also detects AI-specific vulnerabilities like prompt injection and training data exposure, secrets and hardcoded credentials, IaC misconfigurations, and vulnerable dependencies with reachability analysis.
Yes. ZeroPath integrates with Vanta, Drata, and ServiceNow for automated compliance evidence collection. Every scan generates fresh audit evidence that maps findings to exact control clauses across SOC 2, ISO 27001, PCI-DSS 4.0, and NIST 800-53.
You can schedule automated evidence exports with signed SBOMs and fix verification records, generate auditor-ready compliance reports on demand, and track MTTR and SLA breaches by business unit. This turns last-minute audit scrambles into continuous compliance. Learn more about compliance automation and our GRC team solutions.
ZeroPath's enterprise offering includes granular role-based access control (RBAC) with immutable audit logs, SSO/SAML via WorkOS (Okta, Azure AD, Google, Auth0, and more), and SCIM provisioning for automated user lifecycle management.
For organizations with complex structures, ZeroPath supports multi-tenant architecture with workspace isolation for subsidiaries and business units, making it suitable for MSPs and holding companies. A natural language policy engine lets you define and enforce organization-specific security rules without learning a DSL.
Deployment options include on-prem, self-hosted, and private cloud with BYOK (bring your own LLM keys) for organizations with strict data residency requirements. All enterprise plans include dedicated support with SLA and hands-on onboarding.
Still have questions?
Our team is here to help. Contact us for more information about ZeroPath.