
守护未知。
持续渗透测试
对网站、API、云资产和私有环境运行持续安全测试。在统一仪表板中查看发现、报告和实时 agent 活动。
与顶级团队共建
我们与塑造安全、云和 frontier AI 的团队合作,让你的防御领先于威胁。
工作方式
从设置到报告,平台会跟踪测试对象、映射 scope 边界,并实时推送发现。
连接要测试的目标
添加网站、API、代码仓库或私有目标。NullSquare 会映射 scope,并从干净的起点准备运行。
让 agent 完成工作
Agent 会探索目标,运行合适工具,跟踪证据,并在报告前验证支持的问题。
将发现转化为行动
查看已验证的发现,检查保留的证据,共享报告,并在修复后重新运行检查。
持续跟踪 readiness
运行 compliance assessment,审查 control、关联 evidence,并显示哪些通过、失败或需要更多 proof。
准备探索?
几秒钟内打开实时交互式平台演示。无需配置。
核心能力
面向安全和工程团队,提供清晰、可执行、低噪声的安全发现。
随处执行
在你的 VPC、on-prem 或全球云区域内部署 agents。
代码感知分析
针对每个 PR 和代码仓库传输持续评估可利用性。
Critical findings verified in PR #128.
Automated scan completed: 0 issues.
Unencrypted bucket detected in STAGE.
持续覆盖
安排周期性测试,监控 runner 健康,并随时间跟踪自动化活动。
全局连接
原生支持安全和工程团队日常使用的工具。
合规审计就绪
Null-Ai 持续将执行遥测和漏洞发现直接映射到当前合规控制。
SOC 2
Trust Services Criteria
Unauthenticated access was rejected on tested routes; cross-role depth improves with scoped test accounts.
Basis · Agent-tested access boundary
Fails cleanly when evidence shows missing HSTS, plaintext redirects, or weak transport posture.
Basis · HTTP/TLS proof package
Scanner findings, HTTP exchanges, and retained artifacts link to the exact control check.
Basis · Scanner and artifact evidence
The agent requests monitoring coverage evidence instead of silently marking a control reviewed.
Basis · Integration or uploaded evidence
NullSquare prepares the control evidence story. It does not certify, attest, provide legal advice, replace a DPO or QSA, or replace an independent auditor.
信任徽章
向客户展示你认真对待安全,并让他们亲自验证。
运行 NullSquare 的网站会显示徽章,表明安全状态正被持续监控。徽章链接到任何人都能打开并验证的公开页面 — 证明是公开的,findings 保持私密。
点击徽章 — 任何人都可以打开该网站的公开验证页面。
选择适合你 scope 的计划
立即开始测试公共边界,扩展测试周期,并在需要时部署安全的 Private Runner 网络。
Starter
基础边界扫描。
- 300 credits/月
- Low model access
- 1 organization user
- 1 个并发运行
- 1 个活动 scopes
Plus
适合快速增长的应用。
- 5,000 credits/月
- Low and medium model access
- 1 organization user
- 计划自动化
- 2 个并发运行
- 1 个活动 scopes
Pro
完整的 offensive 漏洞流程。
- 50,000 credits/月
- All model tiers
- Unlimited organization users
- 计划自动化
- Repository assignment for whitebox analysis
- Code review
- Compliance workspace
- Live terminal and activity details
- 内部节点执行
- 告警集成
- 3 个并发运行
- 5 个活动 scopes
Enterprise
定制 scope、私有 runner 与高容量。
- 定制 credit 池
- 定制运行容量
- 定制 scope 限制
- All model tiers
- Repository assignment for whitebox analysis
- Code review
- Compliance workspace
- Live terminal and activity details
- 告警集成
- 24 小时支持
申请 pentest scope 评审
提交你的信息后,我们会联系你确认 scope、排期和测试窗口。
博客最新内容
来自最新发布的安全思考。
阅读最新的 NullSquare 实战笔记,或打开完整博客,查看更多关于 AI Security、持续测试、release gates 和 attack surface 覆盖的文章。

AI security
AI vulnerability remediation: what Chrome’s 1,072 fixes reveal
AI vulnerability remediation: what Chrome’s 1,072 fixes reveal
Google’s Chrome security update shows why AI vulnerability remediation must measure validated fixes, deployment coverage, and exploit retesting.