Zeron
Also known as: Zeron ADK, Cyber Navigator
Cyber risk and security control plane whose ZAK agents (Conformity, Interno, Vendor Pulse, Cyber Navigator) act on the stack under DSL policies with Slack approvals and a tamper evident Action Ledger, plus an open source agent development kit and risk quantification.
Zeron is an India founded cyber risk company that now presents its platform as a control plane for security with governed AI agents. Cyber Navigator quantifies cyber risk in financial terms (CVaR and loss curves) over an asset graph that stitches normalized findings from more than 1,300 integrations across EDR, SIEM, cloud, identity, ITSM and vendor APIs, with coverage of more than 250 compliance frameworks.
ZAK is where agents act. Named prebuilt agents include Conformity, which collects control evidence for SOC 2, ISO 27001, RBI and SEBI CSCRF and answers auditors in natural language; Interno, which triages new CVEs and opens tickets and hunts threats across signals; Vendor Pulse, which reassesses third parties when their posture changes; and Cyber Navigator, which updates risk figures when telemetry changes.
Agents subscribe to normalized OCSF events and schedules, an Agent Builder lets teams compose triggers and actions visually, and Policy Studio defines in a DSL what agents may do, with hard guardrails, blast radius limits, approval steps such as a Slack approval before an action, and dry runs before changes ship. Every step is written to a tamper evident, SCF mapped Action Ledger. The ZAK agent development kit is open source on GitHub for Python, Node.js and Go, and agentctl, in early access, extends discovery, policy and audit to agents built on other frameworks.
Zeron lists ISO 27001:2022, ISO 42001, SOC 2 Type II and CSA STAR Level 1, offers SSO/SAML and RBAC with per tenant isolation, and deploys as SaaS on its cloud with in region hosting or on the customer's own servers. It fits CISOs in banking, insurance, healthcare and the public sector who want risk quantification and compliance evidence alongside governed agents that act only under policy; the models behind the agents are not named.
Vendor details
Canonical URL
https://zeron.one
Category
Security / SOC agent
Subcategory
Cyber risk intelligence and security agent development
Funding status
Private; India based (founders Sanket Sarkar, Snehanjan Chatterjee, Swarnali Singha); PCI Security Standards Council India-South Asia board; customers across BFSI, healthcare, and public sector
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
More than 1,300 integrations across EDR, SIEM, cloud, identity, ITSM and vendor APIs through REST, GraphQL and webhook connectors; agents act, for example patching an endpoint through the CrowdStrike API, updating Jira tickets and requesting approval in Slack; SSO/SAML and RBAC; the open source ZAK kit (pip and npm zin-adk, Go module) for building agents.
In practice
A CISO uses Cyber Navigator to convert technical findings into financial impact scores with the QBER model and prioritize remediation by business exposure.
A security engineer defines a red team agent in a single YAML file with ZAK, and every tool call passes through the six guardrail policy engine before executing.
Behavioral agents identify an insider threat with predicted impact and root cause while control auto tuning closes a misconfiguration gap in real time.
Sources & related URLs
Agentic Index coverage score
10.5 / 14 capabilities · 75%
| Integrations & Tool Calling | Full |
|---|---|
|
1,300+ integrations span EDR, SIEM, cloud, identity, ITSM and vendor APIs, with ZAK agents acting on the stack, for example patching an endpoint through the CrowdStrike API and updating a Jira ticket after a Slack approval. The live agents act on EDR, XDR, SIEM, CSPM, CNAPP, IAM, PAM, SOAR, GRC, vulnerability management and CMDB tools. The platform normalizes about 7.3 million events a day into the OCSF schema and removes 68% of duplicates across tools. SourceZeron, zeron.one and /platformread 2026-10-05 |
|
| Workflow Orchestration | Full |
|
Agent Builder is a visual workflow editor where teams drag triggers, compose actions and ship governed AI agents in minutes, and engineers can build agents in code with the open source ZAK kit. Either way, the customer designs the flow. Each agent runs a five step loop, observe, reason, decide, act and verify, with policy gates at every stage. In code, an engineer writes the agent's logic and tools, and the platform layer handles policy, audit and saving results to the graph. SourceZeron, zeron.one, /zak and securezeron.github.io ZAK docsread 2026-10-05 |
|
| Knowledge Grounding & RAG | Full |
|
The Security Intelligence Fabric is a graph database of assets, vulnerabilities, risks and vendors, kept separate for each tenant, that ZAK agents read and write to. Normalized findings are stitched to the asset graph, so the graph keeps up with the customer's estate. The fabric runs on Memgraph, and the platform covers more than 250 compliance frameworks. Cyber Navigator's QBER model blends industry, market cap, business line, locations and regulations with technical findings to estimate annual loss. SourceZeron, securezeron.github.io ZAK docs and zeron.one/platformread 2026-10-05 |
|
| Human Oversight & Guardrails | Full |
|
Policies written in Zeron's DSL can require approval before an action, for example "approve: slack('#sec-ops')", alongside hard guardrails and blast radius limits. The agent waits for that approval before it acts. A policy can set conditions on severity, internet exposure or the change in value at risk, and it can forbid an agent from touching assets with a given tag, such as production databases. Policies can be rolled back instantly, and the Action Ledger records the approvals people give. SourceZeron, zeron.one/zakread 2026-10-05 |
|
| Security, Identity & Governance | Full |
|
Zeron holds ISO/IEC 27001:2022, ISO/IEC 42001, SOC 2 Type II and CSA STAR Level 1, and the platform provides per tenant isolation, SSO/SAML and RBAC. It also holds ISO 9001:2015. Data is encrypted in transit and at rest, customer data is never used to train models, and the platform is aligned to DPDPA, GDPR and DORA. SourceZeron, zeron.one/platformread 2026-10-05 |
|
| Observability & Auditability | Full |
|
The Action Ledger is a tamper evident audit trail mapped to SCF, with every step written to it, so every agent decision can be proven after the fact. It is append only, maps each entry to the customer's control frameworks and includes the approvals people give. Every action on the platform also goes to a tamper evident audit log, and agentctl is built to discover, secure and audit agents across the organization, including agents built on other frameworks. SourceZeron, zeron.one, /zak and /platformread 2026-10-05 |
|
| Memory & State Persistence | Not documented |
|
The graph persistence ZAK handles is the Security Intelligence Fabric, the knowledge graph the agents retrieve from. Zeron describes no memory that agents keep for themselves from one run to the next. Each run names its tenant, and the graph keeps each tenant's nodes in their own namespace. SourceZeron, securezeron.github.io ZAK docsread 2026-10-05 |
|
| Deployment & Data Residency | Full |
|
Zeron deploys on premises, in the cloud or as a hybrid. The SaaS option runs on Zeron's cloud on AWS or Azure with in region hosting; Zeron handles setup, and customers work through a browser or the API. The on premises option installs on the customer's own servers, and the customer's IT team handles hardware, software and integration. SaaS can be running within hours or days, and on premises within weeks or months. Zeron does not list its regions, but says data is hosted, processed and stored inside the jurisdiction regulators require. SourceZeron, zeron.one/deployment and /platformread 2026-10-05 |
|
| Prebuilt Agents, Templates & Packs | Full |
|
Zeron ships named prebuilt ZAK agents with stated jobs, including Conformity (control evidence for SOC 2, ISO 27001, RBI and SEBI CSCRF; audit companion), Interno (CVE triage that opens tickets; threat hunting), Vendor Pulse (third party reassessment) and Cyber Navigator (CVaR and loss curves). In all, six agents run on the platform. Threat Hunting works on EDR and SIEM data, Vulnerability Triage on vulnerability management and Jira, Vendor Risk Watcher on GRC, Compliance Evidence on GRC and CMDB, Audit Companion on the Action Ledger and its evidence, and CRQ Refresh on SIEM data. Interno scores and ranks new CVEs before it opens tickets, and the Audit Companion answers auditors' questions in plain language. SourceZeron, zeron.one and /zakread 2026-10-05 |
|
| Triggers & Channel Coverage | Full |
|
Agents subscribe to normalized OCSF events, such as a critical CVE detected or a vendor risk spike, and to schedules, such as a compliance drift check, and they start when one of those arrives. A policy can also fire on a newly created finding, and Agent Builder lets teams drag triggers onto a workflow. Cyber Navigator refreshes value at risk and loss curves whenever telemetry changes. SourceZeron, zeron.one and /zakread 2026-10-05 |
|
| Model Flexibility & Routing | Not documented |
|
Zeron names no model behind the ZAK agents and offers no choice of provider. The agent definition has a reasoning mode field, which sets how the agent reasons, not which model it uses. Customer data is never used to train models. SourceZeron, securezeron.github.io ZAK docs and zeron.one/platformread 2026-10-05 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
ZAK is an open source agent development kit (github.com/securezeron/zeron-agent-development-kit) installable as zin-adk from pip and npm and as a Go module, with a CLI (zak init, validate, run) and developer docs, and the platform takes REST, GraphQL and webhook connectors. Engineers mark tool functions with a decorator, and the kit's platform layer supplies a policy engine, an audit logger and an agent executor. SaaS customers can also reach the platform through its API. SourceZeron, securezeron.github.io ZAK docs and zeron.one/deploymentread 2026-10-05 |
|
| Testing, Debugging & Optimization | Partial |
|
Policy Studio offers dry runs and version control before anything ships, and zak validate checks agent definitions. Both check policies and configuration. There is no way to test an agent's behavior against scored cases. The last step of each agent loop is a verify step, where the agent checks what its action did, and policies can be rolled back instantly. SourceZeron, zeron.one/zak and securezeron.github.io ZAK docsread 2026-10-05 |
|
| Browser & Computer Use | Not documented |
|
Agents act through API integrations, and none operates a browser or desktop. They work on EDR, SIEM, GRC, vulnerability management and ticketing tools through those tools' APIs, such as patching an endpoint through the CrowdStrike API. SourceZeron, zeron.one and /platformread 2026-10-05 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Pricing
Contact sales (ZAK ADK is free and open source)
modular products (CRPM, Vendor Pulse, Insure Pulse); ZAK open source
What is public
That ZAK ADK is free and open source under Apache 2.0 and the deployment options (SaaS vs on prem) are public; platform dollar figures are not.
Billing mechanics
The ZAK Agent Development Kit is open source (Apache 2.0, free). The commercial CRPM platform, Vendor Pulse, and Insure Pulse are sold via a sales led motion, SaaS subscription (Zeron cloud) or self hosted on prem.
Cost watchouts
Inference, not stated by the vendor: the open source ZAK kit is free, but the platform and its agents are commercial; on premises deployment shifts infrastructure cost to the customer.
Variable cost rationale
Inference, not stated by the vendor: the commercial platform likely scales with assets, modules or agents in scope; no public metering exists.
Additional watchouts
The free ADK does not include the commercial risk platform; self hosted deployment carries infrastructure cost.
Sales call required
Yes, required for paid access
Free / trial
ZAK agent development kit is open source; platform by demo; agentctl in early access
Key ambiguities
Platform pricing is unpublished; the split between the free open source ADK and the commercial platform is clear but platform figures are not.
Missing data
Commercial platform pricing figures, billing axis, contract terms.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to Zeron
The closest documented capability profiles to Zeron among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Drata10.5 / 14Matches Zeron across all 14 documented capabilities
- Cyware10.0 / 14A lighter documented profile than Zeron
- BlinkOps10.5 / 14Adds documented Memory & State Persistence
- SentinelOne10.5 / 14Adds documented Model Flexibility & Routing
- Vanta9.5 / 14A lighter documented profile than Zeron
- ContraForce11.0 / 14Adds documented Model Flexibility & Routing
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded