Back to vendors
Z

ZEST Security

Visit site
Entry priceFree 14 day trial with a written risk exposure assessment; Security Teams and Enterprise plans by yearly subscription, prices on requestFull pricing detail

Agentic exposure management platform whose eight named agents turn scanner, CSPM and CNAPP findings into validated, code based resolution paths tested on a digital twin, delivered through Jira, Slack and code integrations with read only cloud access.

ZEST Security, founded in November 2023 with offices in New York and Tel Aviv, sells an agentic exposure management platform that moves security teams from flagging cloud risk to closing it. It unifies findings from cloud, application and VM scanners, removes false positives, deprioritizes what cannot be exploited, and builds validated resolution paths.

Eight named agents divide the work: a data fabric agent builds a graph of the organization's technical DNA (assets, services, DevOps deployments, tooling, controls and policies); root cause analysis traces each problem to its asset, lines of code, IaC tool and owner; risk prioritization ranks by exploitability, reachability, business criticality and effort; cloud policy analysis and security guardrails agents discount risks existing controls already mitigate; an impact simulator tests patches, package updates and IaC or code fixes on a digital twin of the environment, recursively validating outcomes before anything is suggested; a security as code agent writes replacement code; and a resolution builder combines their outputs into the best path.

ZEST holds read only access to the cloud and changes nothing directly. It delivers context and fixes through Jira, Slack and code integrations, including generated Terraform fixes, so teams act and stay in control. It shows a SOC 2 Type II badge and sells a free 14 day trial with a written risk exposure assessment, plus Security Teams and Enterprise plans by yearly subscription.

It fits cloud security and platform teams with large vulnerability and misconfiguration backlogs from CSPM and CNAPP tools who want validated, code level resolution paths without granting write access. ZEST runs as SaaS with its in house LLM inside its own AWS infrastructure, but it publishes no hosting region, names no access controls for its console and does not name its model.

Vendor details

Canonical URL

https://www.zestsecurity.io/

Category

Security / SOC agent

Funding status

$5M seed (July 2024) from Hanaco Ventures, Silvertech Ventures and angel investors. Founded November 2023.

Company status

independent

Use cases & customers

Primary use cases

Autonomous cloud risk remediationVulnerability and misconfiguration mitigationRoot cause analysis and prioritizationSecurity as code fixes

Target customers

Cloud security teamsDevOps and platform teamsEnterprises with large cloud risk backlogs

Deployment options

SaaSCloud connected read only

Integrations

Natively integrates with cloud providers AWS, Azure and GCP, cloud security solutions such as CNAPP and CSPM, and DevOps systems including Terraform, CloudFormation and Pulumi, plus ticketing and messaging platforms. ZEST is available on AWS Marketplace and holds read only access to the cloud environment.

In practice

A cloud team has thousands of findings across its CSPM and vulnerability scanners and cannot tell which to fix first. ZEST unifies them, drops false positives and ranks what is actually exploitable and reachable in that environment.

A critical vulnerability has no patch yet. ZEST's guardrails agent finds protections already available in the cloud security services the team runs, and sends that mitigation path to the owner in Jira or Slack.

Developers want fixes they can merge without guesswork. ZEST writes Terraform and code changes that fit the organization's policies, tests each one on a digital twin first, and delivers it through the team's code integration.

Agentic Index coverage score

7.0 / 14 capabilities · 50%

Integrations & Tool Calling Full

ZEST reads AWS, Azure and GCP, CNAPP and CSPM findings and IaC tools, and natively integrates with CSPM, vulnerability management, SCA and ASPM solutions, with 50+ integrations supported. Named integrations include Aqua, Datadog, Azure Sentinel, Microsoft Teams and GitLab. It writes into Jira, Slack and code integrations (GitHub), updating tickets and workflows and generating Terraform fixes, while holding only read only access to the cloud itself.

SourceZEST Security, zestsecurity.io/meet-the-productread 2026-10-06

Workflow Orchestration Full

Eight named agents coordinate, and the resolution builder agent "leverages the outcomes of numerous agents to determine the best path for resolution". The others feed it, covering the data fabric, root cause analysis, risk prioritization, impact simulation, security as code, cloud policy analysis and security guardrails. Together they unify findings, drop false positives, deprioritize what cannot be exploited, map remediation and mitigation paths and validate the result.

SourceZEST Security, zestsecurity.io/meet-the-product and zestsecurity.ioread 2026-10-06

Knowledge Grounding & RAG Full

The data fabric agent "creates a graph and structure database that represents your technical DNA, including all assets and services, DevOps deployments, existing tooling, controls, and policies", which the other agents reason over. The cloud policy analysis agent checks findings against the organization's cloud policies to set aside risks already mitigated, and the guardrails agent finds the protections cloud security services already provide.

SourceZEST Security, zestsecurity.io/meet-the-productread 2026-10-06

Human Oversight & Guardrails Partial

"ZEST only has read-only access. We don't change anything in your cloud environment directly." Fixes reach people as tickets, messages and code changes, so the team decides what to apply and keeps complete control. ZEST names no approval step inside the product before it writes a ticket or a message.

SourceZEST Security, zestsecurity.io/meet-the-productread 2026-10-06

Security, Identity & Governance Partial

ZEST displays a SOC 2 Type II badge. It names no SSO, role model or audit log for its console. ZEST keeps read only access to the customer's cloud and sends no customer data to outside AI services, using its in house LLM instead.

SourceZEST Security, zestsecurity.io and /meet-the-productread 2026-10-06

Observability & Auditability Partial

The root cause analysis agent traces each problem to the asset, lines of code, IaC tool and DevOps owner, and resolution paths explain the agents' conclusions. Once a fix lands, ZEST validates the remediation and updates the related workflows. ZEST names no run trace or audit log of the agents' own steps.

SourceZEST Security, zestsecurity.io/meet-the-product and zestsecurity.ioread 2026-10-06

Memory & State Persistence Not documented

The data fabric graph and the digital twin hold what the agents reason over. ZEST does not say whether its agents keep memory from one run to the next, or for how long.

SourceZEST Security, zestsecurity.io/meet-the-productread 2026-10-06

Deployment & Data Residency Not documented

ZEST is SaaS with read only connections into the customer's clouds, and its in house LLM runs inside ZEST's own infrastructure in AWS. No hosting region is published, and ZEST names no region choice and no way to run it in the customer's own environment. ZEST can also be bought through AWS Marketplace.

SourceZEST Security, zestsecurity.io/meet-the-product and zestsecurity.ioread 2026-10-06

Prebuilt Agents / Templates / Packs Full

Eight named agents ship, each with its own job, covering the data fabric, root cause analysis, risk prioritization, impact simulation, security as code, cloud policy analysis, security guardrails and resolution building. The security as code agent writes replacement code that fits the organization's infrastructure and policies, and the risk prioritization agent ranks findings by risk, exploitability, reachability, business criticality, remediation effort and impact.

SourceZEST Security, zestsecurity.io/meet-the-productread 2026-10-06

Triggers & Channel Coverage Partial

Findings from cloud, application and vulnerability management scanners flow into ZEST, which delivers resolutions into ticketing and messaging. ZEST names no event, schedule or webhook that starts the agents on a new finding. Validated fixes also update the existing workflows.

SourceZEST Security, zestsecurity.ioread 2026-10-06

Model Flexibility & Routing Not documented

An internal, in house LLM runs the agents inside ZEST's own AWS infrastructure, and no customer data goes to outside AI services. The model is not named and customers get no choice of model.

SourceZEST Security, zestsecurity.io/meet-the-product; zestsecurity.ioread 2026-10-06

APIs / SDKs / MCP Extensibility Not documented

The 50+ integrations pull findings in and push tickets, messages and code fixes out. ZEST names no API, SDK or MCP server for building on it.

SourceZEST Security, zestsecurity.io/meet-the-product; zestsecurity.ioread 2026-10-06

Testing, Debugging & Optimization Full

"Our agents simulate every fix on a digital twin of your environment, recursively validating the outcome before suggesting changes", so each proposed fix is checked before it reaches the team. The impact simulator agent tests patches, package updates, IaC and code fixes to find the paths that close the most vulnerabilities at once, and ZEST validates the remediation after a fix is applied.

SourceZEST Security, zestsecurity.io/meet-the-product and zestsecurity.ioread 2026-10-06

Browser / Computer-use Not documented

Through integrations, ZEST works on cloud, IaC and code artifacts and names no agent that operates a browser or desktop. It generates Terraform and code fixes rather than working through consoles.

SourceZEST Security, zestsecurity.io and /meet-the-productread 2026-10-06

The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Pricing

Free 14 day trial with a written risk exposure assessment; Security Teams and Enterprise plans by yearly subscription, prices on request

yearly plan tier, scoped by cloud projects and code integrations

Trial available

What is public

Plan names, the free trial and its written assessment, and per plan limits (cloud projects, code integrations, AI prioritization, support hours); no dollar figures.

Billing mechanics

Yearly subscriptions in two paid tiers keyed to cloud projects (100 or 300) and code integrations (one or unlimited), after a 14 day free trial.

Cost watchouts

The Security Teams plan allows one code integration; more code integrations require Enterprise.

Variable cost rationale

Tiers are keyed to cloud projects and code integrations, so growing past 100 projects or adding code integrations moves a team to Enterprise; no usage meter is published.

Sales call required

Yes, required for paid access

Free / trial

14 day free trial with a written risk exposure assessment

Lowest paid plan

None public; contact sales or AWS Marketplace

Key ambiguities

No public rates; a free trial and assessment exist but production pricing and its scaling axis are not disclosed.

Agentic Index verified 2026-09-28

Alternatives to ZEST Security

The closest documented capability profiles to ZEST Security among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • Noma Security7.0 / 14Fuller documented coverage on Observability & Auditability and Triggers & Channel Coverage
  • Quantro Security7.0 / 14Fuller documented coverage on Human Oversight & Guardrails and Triggers & Channel Coverage
  • Airrived8.5 / 14Adds documented Model Flexibility & Routing and APIs, SDKs & MCP Extensibility
  • Magnitude8.5 / 14Adds documented Memory & State Persistence and APIs, SDKs & MCP Extensibility
  • Terra Security6.5 / 14Fuller documented coverage on Observability & Auditability and Triggers & Channel Coverage
  • Token Security6.5 / 14Adds documented APIs, SDKs & MCP Extensibility

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.