The one-glance read on who they are and how they grow. Each point is verifiable from the receipts above.
An AI-native platform that auto-detects, verifies, and PR-fixes code vulnerabilities (SAST, SCA, secrets, IaC) for engineering teams, YC S24-backed, citing 1,000+ organizations and 200,000+ monthly scans as of March 2026.
Organic-led, research-driven content, reinforced by always-on Google search ads rather than founder audience or paid social creative.
≈35,000 monthly visits (+32.1%) as of 2026-07-31, 6 of 12 Google ads active, and 3x claimed ARR growth (March 2026).
Real CVE disclosures in famous open-source projects double as HN posts, YouTube walkthroughs, ranking pages, and ad copy, a compounding trust-and-SEO engine rivals without real findings cannot replicate.
The order the channels came online. Sequence is strategy: what they did first, and what they layered on once demand existed.
Estimated demand, the channel split behind it, and the keywords and referrers doing the work. Directional modeling, not audited analytics.
ZeroPath draws an estimated ≈35,000 monthly visits, up 32.1% as of 2026-07-31. The evidence doesn't break out channel-by-channel share, referrers, or named competitors, so the read here leans on what the ranking data shows directly: ZeroPath already holds the #1 organic position for "sast tool," "sast solutions," and "best sast tools," the exact category-defining searches a security buyer types before ever hearing the brand name.
The specific pages earning their organic search traffic, and the pattern behind why they rank. Adapt the format, not the topic.
ZeroPath's top organic page is a best-sast-tools comparison listicle, which alone earns the large majority of its top-five pages' organic traffic, far ahead of any single CVE writeup. The rest of the pattern is long-tail: individual technical explainers on real disclosures like the Redis Lua use-after-free and the Cisco ASA buffer overflow, plus a category-definition page on OWASP, each pulling modest but real traffic. This works because the comparison page captures high commercial intent exactly when a buyer is choosing a vendor, while every CVE writeup is essentially free content, since the underlying research already happened for credibility reasons, giving the writeup its own indexed page and its own search term to rank for.
Not traffic share. How much weight the growth system actually puts on each channel, with a one-line read on the role it plays.
Open roles read like a roadmap: the functions they’re staffing show where the company is investing next and what stage it’s at.
For founder-led SaaS the breakdown shifts from ads to traction: where the first users came from, how the founder grows it in the open, and the compounding organic surface.
ZeroPath stacked its funding news, a Product Hunt launch, and matching Reddit posts into one visible window, then re-surfaced later through a competition placement rather than a second big-bang launch.
ZeroPath announced its public launch alongside the close of a seed round led by SurgePoint Capital, with Y Combinator and Paul Graham participating, on January 22, 2025. It followed with a Product Hunt launch that drew 230 upvotes and 29 comments and a same-day Reddit post on 2025-02-04 in r/InfoSecNews titled "ZeroPath is now in Public Access," with a companion r/Infosec post under a longer title.
RSA Conference named ZeroPath a Top 10 Innovation Sandbox finalist on February 10, 2026, a placement that came with a $5M SAFE investment from Crosspoint Capital Partners given to each finalist, then had the company present live in San Francisco on March 23, 2026, with a scans-and-ARR growth announcement landing in between on March 13, 2026.
Rather than one Show HN spike, ZeroPath keeps generating attention through roughly monthly Hacker News submissions tied to real disclosures like the better-auth account-takeover bug and 7 new FFmpeg vulnerabilities, a slow-drip relaunch instead of a single moment.
ZeroPath's build-in-public motion is thin on personal audience and heavy on research credibility instead, run through co-founder Etienne Lunetta rather than a big personal following.
Co-founder and COO Etienne Lunetta fronts ZeroPath's research and product content, presenting the July 2026 "Intro to ZeroPath Threat Modeling" YouTube video and appearing among the accounts posting the company's Hacker News CVE research, but his personal X account carries only 4 followers across 12 posts. ZeroPath's other three co-founders, CEO Dean Valentine, CTO Raphael Karger, and CIO Nathan Hrncirik, appear less often in the company's public content.
A founder account (posting as jddda) opened an r/InfoSecNews thread on 2025-02-04 titled "ZeroPath is now in Public Access," with a companion r/Infosec post, then returned to r/cybersecurity with a discussion-bait post asking "Opinions on AI SAST." r/Infosec was the best-performing of the three at a score of 2, modest numbers that show the tactic, post-then-discuss in practitioner subreddits, more than any viral pop.
With personal follower counts negligible, the credibility work happens through named CVE disclosures attributed to the company rather than a founder persona, a distribution model built on proof-of-work rather than a build-in-public narrative arc.
ZeroPath's SEO surface is built almost entirely from repurposing its own security research, not a broad blog calendar.
Each CVE disclosure, the Redis and Cisco ASA writeups covered above among them, becomes its own indexed page targeting that CVE's exact search term, so the company's ordinary research output does double duty as SEO at no separate production cost.
The best-sast-tools listicle covered above is the site's dominant organic asset, the kind of buyer-intent page worth owning early in a still-forming category.
The same Google ad account covered above splits between plain category-term hooks like "Security Vulnerability Scanner" and "AI-Native Security Platform" and a bold-claim ad reading "ZeroPath found 100+ issues in curl that traditional scanners missed," turning the curl research into paid-ad proof rather than funding pure demand generation elsewhere. One ad also points to a "Mythos: AI Attack Simulation" page, a second product surface being tested through the same account.
the evidence shows no referral or affiliate program, so distribution compounds only through content and paid search, not a recruited partner network.
This founder-led SaaS also runs paid acquisition. Here are the live ads doing the work, each with the X-ray and a play you can adapt.

Why it works. Directly address a critical pain point for AI developers and security professionals by offering a specific solution for AI model security testing.
Headline directly states the product's core function and benefit: 'Mythos: AI Attack Simulation - Attack-Test Your AI Models'. Ensure your ad headline clearly and concisely states the problem your product solves and how it solves it, using keywords your target audience would search for.

Why it works. Authority-building and problem-solution ad to attract professionals seeking advanced code security solutions.
Displaying 'Sponsored' at the top, followed by the domain 'www.zeropath.com/'. Clearly label your ad as 'Sponsored' and include your website URL prominently at the beginning of the creative.

Why it works. This creative uses a direct response approach to highlight a unique value proposition in cybersecurity, aiming to generate leads for product demonstrations.
Headline: "AI-Native Security Platform" Clearly state your core product's most innovative or differentiating feature in the main headline.

Why it works. Directly state the product's function and benefit to attract a specific B2B audience, aiming for immediate click-through.
Headline: "Security Vulnerability Scanner" Use a clear, benefit-driven headline that directly names the problem your product solves in the first line of text.

Why it works. Educational content marketing to attract users interested in AI and application security, aiming to drive clicks to learn about ZeroPath's platform.
Prominent, curiosity-driven headline: The ad features "Learn More About AI" as the largest text on the left side. Use a large, clear headline that asks a question or presents a broad, intriguing topic relevant to your product, leaving the specific solution for the landing page.

Why it works. This ad uses a direct response approach by clearly stating the product category and offering more information to a targeted audience interested in AI-driven application security.
Prominent headline stating the core offering: "AI-Native Security Platform" (on-screen text). Lead with a clear, concise headline that immediately communicates your product's core value proposition and key technology.
The channels are not separate. They are one system where each stage feeds the next. Here is the read, then the plays to run tomorrow.
The loop starts with real vulnerability research, not audience-building or paid brand spend, and it lacks a strong second-order sharing mechanic once a buyer lands.
CVE disclosures in well-known open-source projects (curl, FFmpeg, better-auth, Cisco ASA, Redis, Spinnaker) function as top of funnel, distributed through the company blog, YouTube, and modest Hacker News submissions, each generating its own indexed page and occasional press.
A usage-based entry tier funnels into the $1,000/month-plus-$60-per-developer Team plan or a custom Enterprise tier with on-prem and BYOK options. The hiring mix, split between an Account Executive and SDR pair and four product/design/research roles (Software Engineer, Security Researcher, Customer Engineer, Product Designer), shows a self-serve base now adding a direct-sales layer to close that price point.
The best-sast-tools page and the CVE-specific writeups are evergreen assets, each new disclosure adds a permanent indexed page rather than a one-time spike, so the library keeps growing between funding or press moments.
There is no visible referral, affiliate, or community layer, and the founder's own social reach is negligible, so nothing multiplies a single disclosure beyond the channels ZeroPath posts it to directly.
ZeroPath discloses scan volume and org counts but not an absolute ARR figure, a conversion rate from its entry tier, or a per-seat expansion rate on the $60/developer/month pricing, so the actual revenue scale behind its reported 3x ARR growth can't be sized.
The proofZeroPath's blog and Hacker News posts on real CVEs in curl and FFmpeg turn ordinary research output into press and search traffic without a separate content budget.
The adaptationIf your product analyzes, audits, or scans anything, pick one real and independently verifiable output each month, one specific named bug, error, or anomaly, not an aggregate stat, and write it up with the exact technical detail a practitioner would want, then submit it to the one community where that practitioner already hangs out. Start with whatever your product surfaced this past month that a stranger could verify themselves.
Cost: $0 · Time to signal: weeks · Works pre-PMF: yes, conditional on the finding being real, specific, and independently checkable.
The proofZeroPath's Google ads run on category phrases like "Security Vulnerability Scanner" and "AI-Native Security Platform," not just branded search, with several running months at a stretch.
The adaptationWrite down the 2-3 plain phrases a buyer types before they know any brand name in your category, then run a small always-on text ad against exactly those phrases with a $5-10/day cap. Let it run 30 days before touching spend; whichever phrase keeps converting past that mark is your signal to scale.
Cost: under $500 · Time to signal: weeks · Works pre-PMF: conditional, yes if a buyer-intent search term already exists for your category, no in categories driven by impulse or virality rather than search.
The proofA ZeroPath founder account posted into r/InfoSecNews, r/Infosec, and r/cybersecurity, mixing launch announcements with a discussion-style post titled "Opinions on AI SAST" to seed practitioner conversation.
The adaptationFind the 2-3 subreddits where your exact buyer already asks questions, then post a genuine question tied to a real pain point in your category, framed the way "Opinions on AI SAST" was, and reply to every comment that follows. Skip any subreddit whose rules ban self-promotion; this only works where discussion is welcome.
Cost: $0 · Time to signal: days · Works pre-PMF: yes.
The proofZeroPath's best-sast-tools listicle is its dominant organic page and holds the #1 ranking position for that exact search.
The adaptationWrite one honest "best [your category] tools" page that includes real competitors, not just your own product, targeting the precise phrase a prospect searches right before choosing a vendor, then update it every quarter to defend the ranking. One well-targeted comparison page like this can out-earn a dozen thin blog posts.
Cost: $0 in-house, or under $500 for a freelance writer · Time to signal: months · Works pre-PMF: yes.
The proofZeroPath's January 2025 seed announcement, its Product Hunt launch, and matching Reddit posts all landed within roughly two weeks of each other, concentrating attention instead of spreading it thin.
The adaptationPick one real news hook, a raise, a launch, or a milestone, and post it to your own channel, one relevant community, and any launch platform you're using, all on the same calendar day rather than staggered over weeks. This is a one-time or infrequent move tied to an actual event, not a weekly repeatable tactic, so save it for news that's genuinely new.
Cost: $0 · Time to signal: days · Works pre-PMF: yes, but only when there is a real event to hook it to. Not transferable at an earlier stage: ZeroPath's specific proof points, the RSA Conference Innovation Sandbox finalist slot and disclosures in globally-known projects like curl and FFmpeg, depend on a founding team with deep security-research credentials (CTO Raphael Karger, a former Google security engineer; CIO Nathan Hrncirik, a former Tesla red-teamer) and on already-famous targets. A reader without that specific technical depth should adapt the underlying mechanic, publishing real, verifiable output, at whatever scale and target their own product and expertise actually reach.
Every morning we take one company that is actually growing and break down where its customers come from: the ads still running after a year, the channel doing the real work, and the play you can run this week.
Systemaic · directional intelligence. Traffic, spend, and reach figures are SimilarWeb-style estimates and qualitative reads of public data, not audited numbers. Built on real public receipts.
Live ad libraries: google ad library
Launch archives: Hacker News: AI Autonomously Finds 7 FFmpeg Vulnerabilities · Hacker News: Better-auth account takeover (CVE-2025-61928) found via Zero · Hacker News: Two 10.0 severity Spinnaker vulns give attackers RCE and pro · Hacker News: How good is Opus 4.6 at vuln detection? · Hacker News: Malicious Websites Can Exploit OpenClaw to Steal Credentials · Hacker News: Next.js Middleware Exploit: Deep Dive into CVE-2025-29927 Au
Researched facts: Company mission/product description: ZeroPath is a Y Combinator (S24)-backed AI-native app · Founding team and roles: Founded 2024 in San Francisco by Dean Valentine (CEO), Nathan Hrn · Y Combinator batch: ZeroPath is a Y Combinator S24 (Summer 2024) batch company · Pre-seed funding: ZeroPath received roughly $500,000 in pre-seed/accelerator funding from · Additional seed funding (Feb 2026): ZeroPath raised a further $5M seed round around Feb 10 · v1 public launch traction (Jan 2025): At its v1 launch, ZeroPath was trusted by 750+ compa · Scale as of mid-2026: By 2026 ZeroPath's platform runs more than 200,000 scans per month a · RSAC 2026 Innovation Sandbox recognition: ZeroPath was named a Top 10 finalist in the RSAC · Product Hunt launch reception: ZeroPath launched on Product Hunt describing itself as an a · Zero AI agent product launch (May 2026): On May 12, 2026, ZeroPath launched "Zero," descri · Pricing: Free tier: ZeroPath offers a free tier covering 1 repository with unlimited PR sc · Vulnerability research: curl project: ZeroPath's AI static analyzer was used (via research
Milestone sources: 2025-01-22: ZeroPath publicly launched its LLM-driven code security platform alongside the · 2025-10: ZeroPath's AI scanner surfaced 170 verified bugs in the curl project, praised by · 2026-02-10: RSA Conference named ZeroPath a Top 10 finalist in the RSAC 2026 Innovation Sa · 2026-03-13: ZeroPath announced it was scaling its AI-native application security platform, · 2026-03-18: ZeroPath publicized that one of its sudo vulnerability discoveries was referen · 2026-05-11: ZeroPath published a benchmark post arguing its AI scanner outperformed Anthro
Traffic, spend, and revenue figures are estimates as noted in the report; the links above are the primary public artifacts.