ZEST Security
Agentic exposure management platform whose eight named agents turn scanner, CSPM and CNAPP findings into validated, code based resolution paths tested on a digital twin, delivered through Jira, Slack and code integrations with read only cloud access.
ZEST Security, founded in November 2023 with offices in New York and Tel Aviv, sells an agentic exposure management platform that moves security teams from flagging cloud risk to closing it. It unifies findings from cloud, application and VM scanners, removes false positives, deprioritizes what cannot be exploited, and builds validated resolution paths.
Eight named agents divide the work: a data fabric agent builds a graph of the organization's technical DNA (assets, services, DevOps deployments, tooling, controls and policies); root cause analysis traces each problem to its asset, lines of code, IaC tool and owner; risk prioritization ranks by exploitability, reachability, business criticality and effort; cloud policy analysis and security guardrails agents discount risks existing controls already mitigate; an impact simulator tests patches, package updates and IaC or code fixes on a digital twin of the environment, recursively validating outcomes before anything is suggested; a security as code agent writes replacement code; and a resolution builder combines their outputs into the best path.
ZEST holds read only access to the cloud and changes nothing directly. It delivers context and fixes through Jira, Slack and code integrations, including generated Terraform fixes, so teams act and stay in control. It shows a SOC 2 Type II badge and sells a free 14 day trial with a written risk exposure assessment, plus Security Teams and Enterprise plans by yearly subscription.
It fits cloud security and platform teams with large vulnerability and misconfiguration backlogs from CSPM and CNAPP tools who want validated, code level resolution paths without granting write access. ZEST runs as SaaS with its in house LLM inside its own AWS infrastructure, but it publishes no hosting region, names no access controls for its console and does not name its model.
Vendor details
Canonical URL
https://www.zestsecurity.io/
Category
Security / SOC agent
Funding status
$5M seed (July 2024) from Hanaco Ventures, Silvertech Ventures and angel investors. Founded November 2023.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Natively integrates with cloud providers AWS, Azure and GCP, cloud security solutions such as CNAPP and CSPM, and DevOps systems including Terraform, CloudFormation and Pulumi, plus ticketing and messaging platforms. ZEST is available on AWS Marketplace and holds read only access to the cloud environment.
In practice
A cloud team has thousands of findings across its CSPM and vulnerability scanners and cannot tell which to fix first. ZEST unifies them, drops false positives and ranks what is actually exploitable and reachable in that environment.
A critical vulnerability has no patch yet. ZEST's guardrails agent finds protections already available in the cloud security services the team runs, and sends that mitigation path to the owner in Jira or Slack.
Developers want fixes they can merge without guesswork. ZEST writes Terraform and code changes that fit the organization's policies, tests each one on a digital twin first, and delivers it through the team's code integration.
Sources & related URLs
Research sources
Agentic Index coverage score
7.0 / 14 capabilities · 50%
| Integrations & Tool Calling | Full |
|---|---|
|
ZEST reads AWS, Azure and GCP, CNAPP and CSPM findings and IaC tools, and natively integrates with CSPM, vulnerability management, SCA and ASPM solutions, with 50+ integrations supported. Named integrations include Aqua, Datadog, Azure Sentinel, Microsoft Teams and GitLab. It writes into Jira, Slack and code integrations (GitHub), updating tickets and workflows and generating Terraform fixes, while holding only read only access to the cloud itself. SourceZEST Security, zestsecurity.io/meet-the-productread 2026-10-06 |
|
| Workflow Orchestration | Full |
|
Eight named agents coordinate, and the resolution builder agent "leverages the outcomes of numerous agents to determine the best path for resolution". The others feed it, covering the data fabric, root cause analysis, risk prioritization, impact simulation, security as code, cloud policy analysis and security guardrails. Together they unify findings, drop false positives, deprioritize what cannot be exploited, map remediation and mitigation paths and validate the result. SourceZEST Security, zestsecurity.io/meet-the-product and zestsecurity.ioread 2026-10-06 |
|
| Knowledge Grounding & RAG | Full |
|
The data fabric agent "creates a graph and structure database that represents your technical DNA, including all assets and services, DevOps deployments, existing tooling, controls, and policies", which the other agents reason over. The cloud policy analysis agent checks findings against the organization's cloud policies to set aside risks already mitigated, and the guardrails agent finds the protections cloud security services already provide. SourceZEST Security, zestsecurity.io/meet-the-productread 2026-10-06 |
|
| Human Oversight & Guardrails | Partial |
|
"ZEST only has read-only access. We don't change anything in your cloud environment directly." Fixes reach people as tickets, messages and code changes, so the team decides what to apply and keeps complete control. ZEST names no approval step inside the product before it writes a ticket or a message. SourceZEST Security, zestsecurity.io/meet-the-productread 2026-10-06 |
|
| Security, Identity & Governance | Partial |
|
ZEST displays a SOC 2 Type II badge. It names no SSO, role model or audit log for its console. ZEST keeps read only access to the customer's cloud and sends no customer data to outside AI services, using its in house LLM instead. SourceZEST Security, zestsecurity.io and /meet-the-productread 2026-10-06 |
|
| Observability & Auditability | Partial |
|
The root cause analysis agent traces each problem to the asset, lines of code, IaC tool and DevOps owner, and resolution paths explain the agents' conclusions. Once a fix lands, ZEST validates the remediation and updates the related workflows. ZEST names no run trace or audit log of the agents' own steps. SourceZEST Security, zestsecurity.io/meet-the-product and zestsecurity.ioread 2026-10-06 |
|
| Memory & State Persistence | Not documented |
|
The data fabric graph and the digital twin hold what the agents reason over. ZEST does not say whether its agents keep memory from one run to the next, or for how long. SourceZEST Security, zestsecurity.io/meet-the-productread 2026-10-06 |
|
| Deployment & Data Residency | Not documented |
|
ZEST is SaaS with read only connections into the customer's clouds, and its in house LLM runs inside ZEST's own infrastructure in AWS. No hosting region is published, and ZEST names no region choice and no way to run it in the customer's own environment. ZEST can also be bought through AWS Marketplace. SourceZEST Security, zestsecurity.io/meet-the-product and zestsecurity.ioread 2026-10-06 |
|
| Prebuilt Agents / Templates / Packs | Full |
|
Eight named agents ship, each with its own job, covering the data fabric, root cause analysis, risk prioritization, impact simulation, security as code, cloud policy analysis, security guardrails and resolution building. The security as code agent writes replacement code that fits the organization's infrastructure and policies, and the risk prioritization agent ranks findings by risk, exploitability, reachability, business criticality, remediation effort and impact. SourceZEST Security, zestsecurity.io/meet-the-productread 2026-10-06 |
|
| Triggers & Channel Coverage | Partial |
|
Findings from cloud, application and vulnerability management scanners flow into ZEST, which delivers resolutions into ticketing and messaging. ZEST names no event, schedule or webhook that starts the agents on a new finding. Validated fixes also update the existing workflows. SourceZEST Security, zestsecurity.ioread 2026-10-06 |
|
| Model Flexibility & Routing | Not documented |
|
An internal, in house LLM runs the agents inside ZEST's own AWS infrastructure, and no customer data goes to outside AI services. The model is not named and customers get no choice of model. SourceZEST Security, zestsecurity.io/meet-the-product; zestsecurity.ioread 2026-10-06 |
|
| APIs / SDKs / MCP Extensibility | Not documented |
|
The 50+ integrations pull findings in and push tickets, messages and code fixes out. ZEST names no API, SDK or MCP server for building on it. SourceZEST Security, zestsecurity.io/meet-the-product; zestsecurity.ioread 2026-10-06 |
|
| Testing, Debugging & Optimization | Full |
|
"Our agents simulate every fix on a digital twin of your environment, recursively validating the outcome before suggesting changes", so each proposed fix is checked before it reaches the team. The impact simulator agent tests patches, package updates, IaC and code fixes to find the paths that close the most vulnerabilities at once, and ZEST validates the remediation after a fix is applied. SourceZEST Security, zestsecurity.io/meet-the-product and zestsecurity.ioread 2026-10-06 |
|
| Browser / Computer-use | Not documented |
|
Through integrations, ZEST works on cloud, IaC and code artifacts and names no agent that operates a browser or desktop. It generates Terraform and code fixes rather than working through consoles. SourceZEST Security, zestsecurity.io and /meet-the-productread 2026-10-06 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Pricing
Free 14 day trial with a written risk exposure assessment; Security Teams and Enterprise plans by yearly subscription, prices on request
yearly plan tier, scoped by cloud projects and code integrations
What is public
Plan names, the free trial and its written assessment, and per plan limits (cloud projects, code integrations, AI prioritization, support hours); no dollar figures.
Billing mechanics
Yearly subscriptions in two paid tiers keyed to cloud projects (100 or 300) and code integrations (one or unlimited), after a 14 day free trial.
Cost watchouts
The Security Teams plan allows one code integration; more code integrations require Enterprise.
Variable cost rationale
Tiers are keyed to cloud projects and code integrations, so growing past 100 projects or adding code integrations moves a team to Enterprise; no usage meter is published.
Sales call required
Yes, required for paid access
Free / trial
14 day free trial with a written risk exposure assessment
Lowest paid plan
None public; contact sales or AWS Marketplace
Key ambiguities
No public rates; a free trial and assessment exist but production pricing and its scaling axis are not disclosed.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to ZEST Security
The closest documented capability profiles to ZEST Security among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Noma Security7.0 / 14Fuller documented coverage on Observability & Auditability and Triggers & Channel Coverage
- Quantro Security7.0 / 14Fuller documented coverage on Human Oversight & Guardrails and Triggers & Channel Coverage
- Airrived8.5 / 14Adds documented Model Flexibility & Routing and APIs, SDKs & MCP Extensibility
- Magnitude8.5 / 14Adds documented Memory & State Persistence and APIs, SDKs & MCP Extensibility
- Terra Security6.5 / 14Fuller documented coverage on Observability & Auditability and Triggers & Channel Coverage
- Token Security6.5 / 14Adds documented APIs, SDKs & MCP Extensibility
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded