NightVision
NightVision is an application security startup providing AI-assisted dynamic testing that discovers and exploits API and web vulnerabilities before they reach production.
Visit Website ↗ + Add to Compare Claim This CompanyOverview
NightVision builds a dynamic application security testing (DAST) platform that combines real-browser web application scanning with automated API discovery. Founded in 2022, the Los Angeles-based startup targets a specific pain point in modern AppSec programs: most DAST tools struggle with authenticated flows, multi-factor authentication, and the sprawling, undocumented APIs that AI coding assistants now generate at high speed.
The platform uses large language models to navigate web application forms and login flows during scanning, and generates OpenAPI specifications directly from source code to find “shadow” APIs that were never formally documented. It supports authenticated scanning with MFA/TOTP, and integrates with CI/CD pipelines and, more recently, with AI coding agents via open-source Model Context Protocol (MCP) servers, letting a coding agent verify its own fix against NightVision’s findings before merging.
NightVision has raised roughly $6.9 million in seed funding to date. Its differentiator against legacy DAST vendors is speed and automation of the discovery step, which the company says removes the manual setup that keeps many DAST tools from running as continuous checks rather than periodic scans.
Innovation Matrix Assessment
Applies LLM-driven browser navigation and deterministic source-code API discovery to DAST, and shipped MCP integration so AI coding agents can verify their own fixes, a fast-moving response to AI-generated code sprawl.
Authenticated, MFA-aware scanning that plugs into CI/CD reduces the manual setup that keeps many DAST tools from running continuously, a real workflow improvement for AppSec teams.
Roughly $6.9M raised to date and only informal customer endorsements (a BeyondTrust engineer's quote) rather than named enterprise deployments; still early commercially.
DAST is a mature, crowded category; NightVision's automation is a genuine but incremental improvement on discovery speed and false-positive rates rather than a new approach to application testing.
The only efficacy evidence found is a vendor-reported evaluation claiming 51% faster scans than an incumbent scanner in a Fortune 500 healthcare trial; no independent benchmark was located.
AI-assisted software development is expanding attack surface faster than manual AppSec review can cover, which sustains demand for automated, continuous discovery tools like this one.
Why CISOs Should Care
Cuts the manual configuration overhead that keeps most DAST tools running only periodically, and catches undocumented "shadow" APIs created by AI coding tools before they ship.
What Makes It Different
Uses LLMs to navigate authenticated web flows during scanning and derives API specs directly from source code rather than relying on traffic capture or manual documentation.
The Matrix Verdict
53/100 — INCREMENTAL INNOVATOR
NightVision lands as an Incremental Innovator: a technically sound, fast-moving improvement on DAST automation, but still seed-stage with no independently verified efficacy data or named enterprise customers.
Editorial Note: Claims vs. Verified Findings
The 51%-faster and reduced-false-positive claims come from a single vendor-described evaluation; no independent testing or named customer case study was found to corroborate them.
Sources
- SecurityWeek — https://www.securityweek.com/nightvision-raises-5-4-million-for-application-security-testing/
- NightVision funding announcement — https://www.nightvision.net/blog/nightvision-raises-5-4-million-in-seed-funding-to-develop-fast-and-easy-to-use-application-security-testing
- Company site — https://nightviz.ai/
Alternatives to NightVision
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…