Horizon3 says it has launched the general availability of its first Asia-Pacific “Sovereign Instance”, hosted in Sydney, aimed at Australian organisations seeking in-country data residency for autonomous penetration testing.
In a press release, the company said the new Australian point of presence keeps customer data resident in Australia and is designed to support continuous, production-safe autonomous security validation under local control.
Horizon3 positioned the move as a response to the growing use of AI by attackers to identify and exploit vulnerabilities more quickly, arguing that periodic assessments and theoretical findings are no longer sufficient for many organisations. The company said its NodeZero platform “continuously validates” attack paths across internal, external, cloud, identity and web application environments, and is intended to support a “hack–fix–verify” remediation cycle.
The company said the Sydney instance is targeted at “highest-trust” Australian environments including government, critical infrastructure, Defence Industrial Base organisations, banks and other regulated entities. Horizon3 said keeping data in-country and under local control can help organisations align with requirements under the Security of Critical Infrastructure (SOCI) Act, APRA CPS 234, the ASD Essential Eight and related frameworks.
“Australian organisations face the same AI-accelerated threat landscape as the rest of the world, but they rightly demand that the tools they use to defend themselves meet the highest standards of data residency and national control,” said Gareth Cox, Vice President of Sales, Asia Pacific and Japan at Horizon3. “With the Sydney Sovereign Instance, customers can now run the World’s Best AI Hacker continuously and safely, knowing their data never leaves Australia. This enables them to move beyond assumptions and continuously prove which exposures actually matter—and that remediation works.”
Horizon3 co-founder and chief executive Snehal Antani said data sovereignty had become a “strategic requirement” for platforms used in critical infrastructure and national security contexts. “As AI-powered attacks accelerate, countries will only allow continuous, autonomous security validation on their most sensitive networks if they know the data remains under their control and is accessed by cleared nationals,” he said.
Horizon3 said the Sydney deployment complements existing points of presence in the United States and Germany, and is the company’s first sovereign instance in the Asia-Pacific region. The company also referenced a recent US$250 million Series E funding round at a valuation exceeding US$2 billion, which it said would support international expansion including investment across Australia, New Zealand and the wider region.
In the release, Horizon3 said NodeZero has run more than 310,000 “production-safe autonomous security tests” for more than 7,500 organisations globally, and said it holds FedRAMP High authorisation.

