ZeroPath
ZeroPath is a Y Combinator-backed developer tool that autonomously detects, verifies, and submits pull-request fixes for code vulnerabilities directly from a GitHub app, aiming to close the gap between vulnerability discovery and actual remediation.
Visit Website ↗ + Add to CompareOverview
ZeroPath operates as a GitHub app that autonomously scans for security vulnerabilities, verifies that flagged issues are real rather than false positives, and generates pull requests with working patches — targeting the well-documented gap between vulnerabilities that scanners find and vulnerabilities that development teams actually fix.
Founded in 2024 by three co-founders with security backgrounds from Google and Tesla, ZeroPath went through Y Combinator’s Summer 2024 batch and is based in San Francisco.
Innovation Matrix Assessment
As a 2024-founded company that already shipped an autonomous verify-and-fix GitHub app with a 10-person team, ZeroPath shows a fast initial build pace typical of well-executed YC companies.
Autonomously verifying findings before generating a fix directly reduces both false-positive triage time and the manual patching work that consumes engineering capacity in most AppSec programs.
As a very early-stage company with no disclosed funding round beyond standard YC investment and no named enterprise customers found, independently verifiable market traction is currently limited.
Closing the loop from detection to verified, submitted fix is a meaningful workflow change from the detect-only model of most SAST and dependency-scanning tools.
No independent, third-party benchmark of fix accuracy or false-positive elimination rate was found; effectiveness is not independently verified beyond the company's own description.
The persistent gap between vulnerabilities found and vulnerabilities fixed is a long-standing, unresolved AppSec problem, giving autonomous remediation tools durable underlying relevance.
Why CISOs Should Care
Vulnerability backlogs routinely outpace engineering capacity to fix them; ZeroPath's autonomous verify-and-patch approach targets that specific operational bottleneck rather than adding another layer of unfixed findings to an AppSec team's queue.
What Makes It Different
Where most SAST and dependency scanners stop at detection and leave remediation to developers, ZeroPath closes the loop by autonomously verifying findings and submitting working fix pull requests directly into the development workflow.
The Matrix Verdict
47/100 — EMERGING / UNRANKED
A very early-stage but well-credentialed YC entrant addressing the persistent detect-vs-fix gap in application security; scores are appropriately conservative given its small team size and lack of disclosed funding or customer data.
Editorial Note: Claims vs. Verified Findings
YC batch, founding year, headquarters, and team size (10 people at YC profile time) are independently confirmed via ZeroPath's Y Combinator company page; specific funding amount and customer count are not disclosed.
Sources
Alternatives to ZeroPath
Wiz
Agentless, graph-based cloud security platform that maps multi-cloud risk end-to-end, now owned by Google after a record $32B…
Chainguard
Provides hardened, minimal, continuously-rebuilt container images and software packages to eliminate vulnerabilities before they reach production.
Microsoft Defender for Cloud
Microsoft's built-in cloud-native application protection platform, unifying CSPM, workload protection, and DevOps security natively across Azure, AWS, and…
Obsidian Security
Obsidian Security provides a SaaS security posture management (SSPM) platform that detects identity-centric threats and misconfigurations across enterprise…
Sysdig
The company behind Falco, the CNCF's runtime security standard, offering an eBPF/kernel-level CNAPP built on live syscall-based threat…
Upwind Security
Fast-growing, venture-backed CNAPP startup combining agentless scanning with eBPF runtime sensors for real-time cloud and AI workload risk…